Windows 11 KB5124008 Update Linked to Domain Trust Failures


Microsoft is investigating reports that the Windows 11 KB5124008 security update is breaking domain trust relationships on enterprise systems, preventing users from logging in with valid domain credentials. Administrators report that affected computers lose their secure channel with Active Directory after the update is installed and devices reboot, with cached credentials continuing to work offline.

Reports indicate the failures are tied to the Windows Machine Identity Isolation security feature, particularly when enabled in audit or enforcement mode. One administrator confirmed that uninstalling KB5124008 and repairing the domain relationship restored access, while reinstalling the update caused the failure to return. Another reported that 11 out of approximately 256 Windows 11 25H2 Enterprise devices lost domain trust after updating.

Administrators observed Kerberos authentication failures followed by NTLM and Netlogon fallbacks on affected systems. Some restored access by setting the MachineIdentityIsolation registry value to 0, rebooting, and repairing the secure channel using PowerShell. However, Microsoft documentation warns that disabling the feature after it was previously enforced will break domain authentication and require devices to be unjoined and rejoined to the domain.

Microsoft has not yet confirmed Machine Identity Isolation as the root cause and has not published an official workaround. The company stated it is aware of the reports and will share guidance as it becomes available.

Read more...

Read More

Got Something To Say?

Your email address will not be published.