Microsoft has acknowledged another serious problem linked to the September 2026 Windows 11 security update, and this one is particularly important for business and enterprise PCs.

The KB5124008 update can cause domain-joined Windows 11 PCs to lose their secure connection with Active Directory, resulting in users being unable to sign in with valid domain credentials.

Microsoft has now provided administrators with a manual workaround involving Machine Identity Isolation while a more permanent solution is being prepared.

The issue affects Windows 11 24H2 and 25H2 systems, with reports also involving newer supported client configurations. Microsoft’s KB5124008 documentation confirms the update applies to Windows 11 24H2 and 25H2.

Windows 11 KB5124008 can break domain logins

KB5124008 was released on September 8, 2026, as part of Microsoft’s September security updates.

The update delivers important security improvements, but administrators have reported a separate problem affecting PCs connected to on-premises Active Directory environments.

After installing the update and restarting the computer, affected machines can lose their domain secure channel.

That can produce errors indicating that the trust relationship between the computer and the domain has failed.

In some cases, users may also see their valid domain username and password rejected.

Microsoft’s update documentation currently lists several known issues associated with KB5124008, although the domain-authentication problem is being handled separately from issues such as Remote Desktop and Hyper-V folder sharing.

What is causing the domain trust problem?

The issue appears to be connected to a Windows security feature called Machine Identity Isolation.

This feature works alongside security technologies such as Credential Guard and is designed to better protect machine-account credentials used when a Windows computer communicates with an Active Directory domain.

Reports from administrators indicate that KB5124008 can cause Windows to begin enforcing previously configured Machine Identity Isolation settings.

The problem becomes particularly relevant in environments where domain controllers don’t meet the required Windows Server 2025 Domain Functional Level baseline for the enforcement behavior.

In those environments, the workstation can lose its secure channel with the domain controller.

The result can be surprisingly disruptive: the PC may still boot normally, but users relying on domain authentication can suddenly find themselves locked out.

Which Windows 11 versions are affected?

The reports primarily concern enterprise and domain-connected Windows 11 machines rather than typical home PCs.

The affected Windows client versions reported include:

  • Windows 11 24H2
  • Windows 11 25H2
  • Windows 11 26H1 in some reports

The issue requires a particular combination of domain authentication, security configuration and Machine Identity Isolation settings, so not every Windows 11 PC running KB5124008 will be affected.

That’s an important distinction for consumers.

If you’re using a normal personal Windows 11 PC that isn’t joined to an on-premises Active Directory domain, this particular bug is unlikely to affect you.

What happens when the bug hits?

The most obvious symptom is a broken domain trust relationship.

Affected users can encounter messages indicating that the computer’s trust relationship with the domain has failed.

Another reported symptom is Windows rejecting correct domain credentials with an error suggesting that the username or password is incorrect.

Interestingly, cached credentials may continue to work while the PC is offline, which can help administrators regain access to an affected machine and troubleshoot the problem.

Administrators have also reported that removing KB5124008 can restore normal behavior, although uninstalling a security update should not be treated as the first choice because it removes important security fixes.

Microsoft provides a manual workaround

Microsoft’s current workaround is to disable Machine Identity Isolation using the same management mechanism that enabled it.

That means organizations should first determine whether the setting was configured through:

  • Microsoft Intune
  • Group Policy
  • Windows Registry

Microsoft’s guidance says administrators should disable Machine Identity Isolation through the corresponding management method.

Intune-managed PCs

If Machine Identity Isolation was configured through Intune, administrators should disable the relevant policy through Intune.

Group Policy-managed PCs

If the feature was enabled using Group Policy, administrators should disable the setting through the applicable Group Policy configuration.

Registry-configured PCs

For machines where the setting was configured directly in the Registry, Microsoft provides specific registry locations.

On affected Windows 11 systems, administrators should check:

HKLM\SYSTEM\CurrentControlSet\Control\Lsa\MachineIdentityIsolation

and

HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard\MachineIdentityIsolation

If the relevant MachineIdentityIsolation value is set to 2, Microsoft says to change it to 0 as part of the workaround.

Important: Registry modifications should only be performed by qualified administrators. Microsoft recommends backing up the Registry before making changes.

Restart the PC after changing the setting

After disabling Machine Identity Isolation, the affected PC needs to be restarted.

Once Windows has restarted, administrators can repair the computer’s secure channel with the domain.

Microsoft’s documented workaround uses PowerShell:

Test-ComputerSecureChannel -Repair -Credential (Get-Credential)

The command attempts to repair the secure channel between the Windows PC and the Active Directory domain.

Administrators will be prompted to provide appropriate domain credentials.

Don’t rush to uninstall KB5124008

Uninstalling KB5124008 may appear to be the simplest solution, especially if a machine becomes inaccessible after the update.

However, that approach has an important downside.

KB5124008 is a security update, so removing it also removes the security protections included in that update.

The better approach, where possible, is to use Microsoft’s mitigation and repair the domain relationship rather than broadly rolling back the security update.

Microsoft has already released KB5129195, an out-of-band update addressing several other problems caused by the September updates, including Remote Desktop and some USB audio issues. However, reports indicate that KB5129195 does not resolve the KB5124008 domain-trust problem.

This isn’t the only KB5124008 problem

The domain-authentication issue arrives alongside several other problems associated with Microsoft’s September 2026 update cycle.

Microsoft has already documented issues involving Hyper-V-based Linux virtual machines, where host folder shares using Plan9 may become unavailable.

That issue affected applications and environments including WSL and Claude Cowork and was resolved through updates released on and after September 14, including KB5129195.

Remote Desktop Services also experienced problems after the September security update, including failed connections, sign-in problems and systems becoming stuck during Remote Desktop configuration.

Microsoft says those problems were resolved by updates such as KB5129195.

The domain trust problem is therefore particularly notable because the emergency update does not appear to address it.

Microsoft is preparing a longer-term solution

The manual workaround isn’t necessarily the final answer.

Microsoft says it plans to temporarily prevent Machine Identity Isolation enforcement in a future update while it works through the compatibility problem.

That should reduce the immediate risk for affected environments, but administrators still need to be careful about changing security settings across large fleets.

The Microsoft Q&A discussion around the issue also shows why this isn’t a simple one-size-fits-all fix: administrators have reported different Machine Identity Isolation configurations and different domain environments.

Should you be worried about KB5124008?

For most home Windows 11 users, probably not.

The problem is primarily relevant to organizations using Windows 11 devices joined to on-premises Active Directory environments with particular Machine Identity Isolation configurations.

If you’re managing a business Windows environment, however, this is something worth checking before deploying KB5124008 broadly.

IT administrators should specifically look at:

  1. Which Windows 11 versions are deployed.
  2. Whether devices are joined to an on-premises Active Directory domain.
  3. Whether Machine Identity Isolation is enabled.
  4. How the policy is being managed.
  5. Whether affected PCs are experiencing secure-channel or domain-login failures.

Final thoughts

Microsoft’s September 2026 Windows 11 update cycle has turned into a complicated one for IT administrators.

KB5124008 is an important security update, but it can also trigger domain-trust problems in certain enterprise environments.

The newly documented workaround gives administrators a way to disable Machine Identity Isolation and repair the affected computer’s secure channel without immediately removing the security update.

The bigger fix is still expected from Microsoft.

For now, organizations running domain-joined Windows 11 PCs should test KB5124008 carefully and pay particular attention to Machine Identity Isolation, Credential Guard and Active Directory authentication before pushing the update across a large fleet.

Microsoft’s official KB5124008 documentation remains the best place to monitor the status of the update and its known issues.

For the latest rollout updates and troubleshooting guides, follow our Windows 11 coverage as more details emerge.

Add WinCentral as a preferred source on Google News
Add WinCentral as a preferred source on Google News