Windows 11 KB5124008 update breaks Active Directory domain trust, blocking logins for some users
Microsoft is investigating reports that the September 8, 2026 cumulative update KB5124008 for Windows 11 24H2/25H2 breaks the secure channel between domain-joined machines and Active Directory, causing 'The user name or password is incorrect' errors despite…
Administrators report that KB5124008, Microsoft's September 8, 2026 cumulative update for Windows 11 24H2/25H2 (builds 26100.9445/26200.9445), breaks the Active Directory secure channel on domain-joined machines, causing interactive logon failures after reboot. BleepingComputer reports the failures on Windows 11 25H2 systems, while the update itself targets 24H2/25H2. The suspected cause is Machine Identity Isolation, a Credential Guard capability that in enforcement mode moves machine-account secrets into virtualization-based security and removes the LSA copy; the MachineIdentityIsolation registry value was observed set to '2' (enforcement mode) after installing the update. Observed diagnostics include nltest error 1786 (ERROR_NO_TRUST_LSA_SECRET), domain controller Event 4625 with status 0xC000006D over NTLM, and Kerberos failures followed by NTLM and Netlogon fallbacks; cached credentials still worked offline, confirming a domain authentication issue rather than a password problem. Scale appears limited but real: one admin saw 11 of roughly 256 devices affected. Workarounds include disabling Machine Identity Isolation (setting MachineIdentityIsolation to 0 via registry, Group Policy, or Intune baseline), resetting the machine password, running Test-ComputerSecureChannel -Repair, or rejoining the domain. Uninstalling the update and repairing the domain relationship restores access, but reinstalling re-triggers the failure. Microsoft has confirmed no root cause or official fix, does not list the issue as a known problem in its release notes, and warns that disabling the feature can itself break domain authentication. The September 14 out-of-band update KB5129195 fixes other issues but not the domain trust failures.
- KB5124008 was released September 8, 2026 as the cumulative update for Windows 11 24H2/25H2 (builds 26100.9445/26200.9445); BleepingComputer reports login failures on Windows 11 25H2 systems after reboot, while the update targets both 24H2…
- Suspected cause: Machine Identity Isolation in enforcement mode moves machine-account secrets into Credential Guard / virtualization-based security and removes the LSA copy; the MachineIdentityIsolation registry value was set to '2' after…
- Observed errors: nltest error 1786 (ERROR_NO_TRUST_LSA_SECRET), domain controller Event 4625 with status 0xC000006D over NTLM, Kerberos failures followed by NTLM and Netlogon fallbacks; cached credentials still worked offline.
- Impact scale per one administrator: 11 of roughly 256 devices affected.
- Workarounds: set MachineIdentityIsolation to 0 (via registry, Group Policy, or Intune baseline), reset the machine password, run Test-ComputerSecureChannel -Repair, or rejoin the domain; uninstalling the update and repairing the domain…
- Microsoft position: no confirmed root cause or official fix, the issue is not listed as a known problem in release notes, and the company warns that disabling Machine Identity Isolation can also break domain authentication.
- The September 14, 2026 out-of-band update KB5129195 addresses other issues but does not fix the domain trust failures.
Coverage timelineoldest first · each row is one article
- · 7h agoWindows 11 KB5124008 update breaks domain trust for some users
BleepingComputer· 60
Microsoft is investigating Windows 11 KB5124008 breaking Active Directory domain trust, leaving some users unable to log in with valid credentials.
- · 3h agoWindows 11 KB5124008 Update Breaks Active Directory Domain Trust and Blocks User Logins
Cyber Security News· 58
Microsoft's September Windows 11 cumulative update KB5124008 breaks Active Directory domain trust on domain-joined machines, blocking logins despite valid credentials.