Windows 11 KB5124008 update breaks domain trust for some users

Windows 11 Update Causes Domain Trust Issues for Some Enterprise Users

A growing number of Windows administrators have reported a critical issue with Microsoft’s latest security update, KB5124008, which is causing domain trust relationships to break on some enterprise systems. This has resulted in users being unable to log in with valid domain credentials, even though their passwords and usernames are correct.

The problem appears to be linked to the “Machine Identity Isolation” feature in Windows 11’s Virtualization-Based Security and Credential Guard configuration. When this feature is enabled in audit or enforcement mode, it isolates machine account credentials used for domain authentication. However, after installing KB5124008, some users have reported that their systems lose secure channel with Active Directory, causing login failures.

Administrators who have been affected by the issue report that they were able to reproduce the problem consistently and that uninstalling KB5124008 resolved the issue. In fact, reinstalling the update caused the failure to return. This suggests that there is a direct connection between the Windows 11 security update and the domain trust issues.

One administrator who reported the issue on Microsoft’s Q&A forums noted that his Windows 11 workstations functioned normally before installing KB5124008 but began experiencing domain login failures after rebooting. He observed that cached credentials continued to work while the systems were offline, indicating that the problem was related to domain authentication rather than user passwords.

The affected administrators have discovered that disabling Machine Identity Isolation temporarily resolves the issue. However, they caution against making this change, as it could also cause similar problems in the future. Some administrators have reported that changing the setting from audit or enforcement mode to disabled caused domain trust failures across their environment, including on systems that had never installed KB5124008.

To resolve the issue, administrators can try disabling Machine Identity Isolation by modifying the relevant registry value and then repairing the machine’s secure channel using PowerShell. However, this is a temporary solution, and users are advised to wait for Microsoft’s official guidance on addressing the problem.

As the situation unfolds, it’s essential for Windows 11 administrators to be aware of this potential issue and take necessary precautions to mitigate its impact. If you’re experiencing domain trust issues after installing KB5124008, try disabling Machine Identity Isolation and repairing the secure channel as a temporary fix. However, keep in mind that making such changes may have unforeseen consequences, so it’s crucial to monitor your systems closely and revert any modifications once Microsoft releases an official solution.


Source: Bleeping Computer — 2026-09-16