VYPR
patchPublished Sep 17, 2026· 1 source

Windows 11 KB5124008 Update Causes Active Directory Domain Trust Failures

Microsoft is investigating an issue where the Windows 11 KB5124008 update breaks Active Directory domain trust, preventing user logins due to a conflict with Machine Identity Isolation.

Microsoft is currently investigating a critical issue impacting Windows 11 enterprise environments following the deployment of the KB5124008 security update. Reports indicate that the update, released on September 8, 2026, is causing Active Directory domain trust relationships to fail, resulting in user login failures. This widespread problem prevents users from signing into their machines with valid credentials, disrupting business operations.

The root cause appears to be related to Machine Identity Isolation, a feature of Credential Guard designed to protect machine account secrets. In enforcement mode, this feature moves machine secrets into Credential Guard and removes them from the standard Local Security Authority environment. If Credential Guard fails to authenticate the machine after a restart, the secure channel to the domain can be broken, leading to authentication issues. Administrators have observed that the Test-ComputerSecureChannel cmdlet returns False, and domain controllers log authentication failures for the affected computer accounts.

Initial troubleshooting by affected administrators ruled out common domain issues such as DNS problems, replication errors, time synchronization, account lockouts, and duplicate machine Security Identifiers (SIDs). The focus shifted to Machine Identity Isolation after observing that disabling this feature or resetting machine passwords could restore domain connectivity. One administrator successfully reproduced the failure by installing KB5124008 and then resolved it by disabling Machine Identity Isolation via Group Policy and Intune, followed by a registry modification. Other workarounds involved resetting the machine password and repairing the secure channel, or in some cases, removing and rejoining the machine to the domain.

While these workarounds can restore functionality, they come with security trade-offs. Disabling Machine Identity Isolation reduces the protection for machine-account credentials, and uninstalling the KB5124008 update removes the security fixes it provided. Enterprises are therefore advised to proceed with caution, treating these as temporary measures until Microsoft releases an official fix or guidance.

Microsoft's official release notes for KB5124008 do not currently list domain trust failures as a known issue, although they do mention problems with USB audio, Hyper-V folder sharing, and Remote Desktop Services. A subsequent out-of-band update, KB5129195, released on September 14, addresses some of these other documented issues but also does not mention the domain trust problem.

Given the severity of the impact on user logins and domain connectivity, organizations are strongly recommended to pause the broad deployment of KB5124008. It is crucial to test any policy changes related to Machine Identity Isolation on a limited group of devices before wider implementation. Maintaining access to local administrator accounts or using tools like Local Administrator Password Solution (LAPS) is also advised to facilitate recovery efforts.

Until Microsoft provides definitive guidance, IT departments should actively monitor the official KB page for updates and audit their Windows 11 environments for the status of Machine Identity Isolation settings. Proactive verification of recovery procedures, such as using nltest to check secure channel status, is essential to ensure business continuity in the event of similar issues.

Synthesized by Vypr AI
Windows 11 KB5124008 Update Causes Active Directory Domain Trust Failures · VYPR