Microsoft patch gives domain-joined Windows PCs trust issues

← Back to the feed

Microsoft patch gives domain-joined Windows PCs trust issues

The Register · 2 weeks ago

Microsoft's September 2026 security update has introduced a significant problem affecting Active Directory domain logins on Windows 11, preventing users from signing into domain-joined PCs with valid credentials. The issue, present in Windows 11 versions 24H2, 25H2, and 26H1, stems from changes to the Machine Identity Isolation feature in update KB5124008, which can cause Credential Guard-protected machine accounts to lose their secure channel with on-premises Active Directory domains. This represents another setback in Microsoft's troubled September update cycle.

The feature is only supported on systems connected to Windows Server 2025 Domain Functional Level controllers or later. Affected administrators must disable Machine Identity Isolation through Intune, Group Policy, or the Windows Registry (with appropriate backups), then restart devices and repair the secure channel using PowerShell commands. Microsoft has confirmed it will address the issue in a future update by temporarily preventing Machine Identity Isolation enforcement whilst the feature receives further refinement.

  • September patch breaks domain login for some Windows 11 PCs
  • Workaround requires registry changes and PowerShell commands
  • Microsoft promises permanent fix in future update

Business Markets

Read the full article at the source →