Microsoft is investigating reports that the Windows 11 KB5124008 and KB5124012 security updates are causing domain trust relationships to break on some enterprise systems. This issue prevents users from logging in with valid domain credentials after installing the updates.
Administrators have reported on platforms like Reddit and Microsoft's Q&A forums that affected computers lose their secure channel with Active Directory after the updates are installed and devices reboot. Users encounter domain trust errors and credential errors despite using correct usernames and passwords.
The failures are linked to the Machine Identity Isolation Windows security mechanism. After the KB5124008 (Windows 11 24H2/25H2) or KB5124012 (Windows 11 26H1) updates are installed, this feature is being set to enforcement mode.
Microsoft's documentation indicates that enabling Machine Identity Isolation in enforcement mode and then disabling it can break domain authentication, requiring a device to be unjoined and rejoined to the Windows domain.
In Windows Active Directory, domain-joined computers rely on machine account credentials to maintain a secure channel with domain controllers. If these locally stored credentials do not match what Active Directory expects, the secure channel can fail. This issue specifically affects systems not connected to Windows Server 2025 domain controllers.
Microsoft has shared a temporary fix for the domain login problems. The workaround involves disabling Machine Identity Isolation on affected devices. This guidance was provided after Microsoft confirmed awareness of the reports and initiated an investigation.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Microsoft released a temporary fix for Windows 11 domain login problems occurring after the September 2026 security updates. The issue stems from Machine Identity Isolation being set to enforcement mode, breaking domain trust relationships on systems not connected to Windows Server 2025 domain controllers. The workaround involves disabling Machine Identity Isolation on affected devices.
Microsoft is investigating reports that the Windows 11 KB5124008 security update is causing domain trust relationships to break on some enterprise systems, preventing users from logging in with valid domain credentials. This issue impacts organizations using Active Directory, as affected computers lose their secure channel with domain controllers after the update and a reboot.