Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Windows 11 Update Affects Domain Trust and User Logins

Windows 11 Update Affects Domain Trust and User Logins

Posted on September 17, 2026 By CWS

Microsoft is currently addressing concerns regarding the Windows 11 KB5124008 security update, which has reportedly disrupted Active Directory domain trust on certain enterprise computers. This issue has left some users unable to log in with their valid credentials.

Impact of the Update on Domain Trust

The incident seems to be associated with Machine Identity Isolation, though Microsoft has yet to confirm the exact cause or offer an official solution. Released on September 8, 2026, the KB5124008 update is designed for Windows 11 versions 25H2 and 24H2, upgrading them to builds 26200.9445 and 26100.9445, respectively. While the release notes mention issues with USB audio, Hyper-V Plan9 folder-sharing, and Remote Desktop Services, they do not currently acknowledge domain trust problems.

Reports from Administrators

An administrator managing workstations running Windows 11 25H2 in a domain with two Windows Server 2019 controllers first reported the problem. The administrator found that installing KB5124008 and rebooting disrupted the secure channel, while uninstalling the update and rejoining the domain temporarily resolved the issue. Unfortunately, reinstalling the update caused the problem to recur.

Users affected by this were met with error messages indicating incorrect usernames or passwords during logins, despite using valid credentials. While cached sign-ins worked offline, network authentication remained functional, suggesting that user credentials were not inherently invalid.

Technical Investigation and Mitigation Efforts

Technical tools such as PowerShell’s Test-ComputerSecureChannel returned False, and nltest /sc_query: generated ERROR_NO_TRUST_LSA_SECRET (error 1786). The domain controller logged Security Event 4625, indicating authentication failure for computer accounts with NTLM Logon Type 3. Investigations ruled out DNS discovery, Active Directory replication, and other potential causes before focusing on Machine Identity Isolation.

Machine Identity Isolation, part of Credential Guard, safeguards machine-account secrets through virtualization-based security. In some cases, setting MachineIdentityIsolation to Disabled through Group Policy and resetting registry values helped mitigate the problem.

Recommendations for Enterprises

Administrators have found that resetting machine passwords and using Test-ComputerSecureChannel with the -Repair option, after disabling isolation, restored domain trust in many instances. However, some systems still required removal from and rejoining to the domain. These measures should be viewed as community-provided temporary solutions rather than official fixes from Microsoft.

Organizations are advised to pause widespread deployment, test changes on a subset of devices, maintain local administrator access, and verify recovery before full implementation. The out-of-band update KB5129195 released on September 14 addresses other issues but does not mention domain trust or Machine Identity Isolation specifically.

Until Microsoft provides a definitive solution, enterprises should continue to monitor updates on Microsoft’s KB page and review Machine Identity Isolation configurations across their Windows 11 systems.

Cyber Security News Tags:Active Directory, Credential Guard, domain trust, enterprise IT, Machine Identity Isolation, Microsoft, security update, update issues, user logins, Windows 11

Post navigation

Previous Post: VectraRAT: Rentable Malware Threatens Windows Security

Related Posts

Microsoft Launches Project Zenith for Local AI Model Execution Microsoft Launches Project Zenith for Local AI Model Execution Cyber Security News
Dutch Authorities Confiscate Windscribe VPN Server Dutch Authorities Confiscate Windscribe VPN Server Cyber Security News
How to Use Threat Intelligence to Enhance Cybersecurity Operations How to Use Threat Intelligence to Enhance Cybersecurity Operations Cyber Security News
How to Implement Zero Trust Architecture in Enterprise Networks How to Implement Zero Trust Architecture in Enterprise Networks Cyber Security News
Cloudflare Unveils MCP Server Portals to Secure AI Revolution Cloudflare Unveils MCP Server Portals to Secure AI Revolution Cyber Security News
FortiClient Exploitation Leads to EKZ Malware Deployment FortiClient Exploitation Leads to EKZ Malware Deployment Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Windows 11 Update Affects Domain Trust and User Logins
  • VectraRAT: Rentable Malware Threatens Windows Security
  • Microsoft 365 Faces Global Access Issues with Errors
  • GhostCode Phishing Kit Evades Microsoft MFA to Hijack Accounts
  • Major WSO2 Flaw Risks Full Admin Control by Hackers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Windows 11 Update Affects Domain Trust and User Logins
  • VectraRAT: Rentable Malware Threatens Windows Security
  • Microsoft 365 Faces Global Access Issues with Errors
  • GhostCode Phishing Kit Evades Microsoft MFA to Hijack Accounts
  • Major WSO2 Flaw Risks Full Admin Control by Hackers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark