< Back to all clusters
[TECHNOLOGY] · United States · 10 sources

started · updated

Microsoft Windows 11 update breaks Active Directory domain trust

Microsoft is investigating a critical issue where the Windows 11 KB5124008 security update disrupts Active Directory domain trust. This failure prevents users from signing in with valid credentials on enterprise computers, often resulting in an error message stating that the username or password is incorrect.

The problem is linked to a feature called ‘Machine Identity Isolation’ enabled by the September security updates. This feature can cause computer accounts protected by Credential Guard to lose their secure channel with a local Active Directory if the environment is not running Windows Server 2025 Domain Functional Level or higher. Affected versions include Windows 11 24H2, 25H2, and 26H1.

As a temporary workaround, Microsoft advises administrators to disable Machine Identity Isolation via Intune, Group Policy, or direct registry modifications. While interactive logins may fail, users can still sign in using cached credentials while the device is offline.

Entities

Active Directory · Microsoft · Windows 11