KB5124008 leaves Remote Desktop Services hanging on Windows 11 (September 11, 2026)

Chapters
What Microsoft confirmed
The entry is headed "Remote Desktop Services might stop responding after Sept. 2026 security update". Microsoft opened it at 11:19 PT on September 11, 2026 and last updated it at 19:20 PT the same day, with the status Mitigated. Its own description: RDS might become unstable, resulting in RDP connections failing after several minutes, sign-in issues, or servers hanging at the message "Please wait for the Remote Desktop Configuration".
The knock-on effects are in the entry too: related tools, including Microsoft Management Console, the RDS Licensing Diagnoser and File Explorer, might also become unresponsive. The 26H1 release health page adds that the Windows Update page might stop responding and continuously display a loading indicator, and traces the 26H1 side of it to OS Build 28000.2954, KB5124012, from September 8, 2026.
Mitigated is not fixed. It means Microsoft has reduced the impact for some customers while the underlying defect stands, and the entry says the company is working to release a resolution in a future Windows update.
TL;DR
Remote Desktop Services became unstable on Windows 11 and on supported Windows Server releases after September's security update, and Microsoft confirmed it on September 11, 2026, opening a known issue on its Windows release health dashboard at 11:19 PT and moving it to Mitigated at 19:20 PT the same evening. RDP connections fail after several minutes, sign-in fails, or a server hangs at the message about waiting for the Remote Desktop Configuration. There is no fix: Microsoft says it is working to release a resolution in a future Windows update.
- Microsoft's wording is that RDS might become unstable, resulting in RDP connections failing after several minutes, sign-in issues, or servers hanging at the Remote Desktop Configuration message.
- The damage spreads past RDP. Microsoft Management Console, the RDS Licensing Diagnoser and File Explorer might also become unresponsive, and on 26H1 the Windows Update page might keep showing a loading indicator.
- Affected clients run from Windows 11 26H1, OS build 28000.2954 from KB5124012, down to Windows 10 Enterprise LTSC 2016. Servers run from Windows Server 2012 to Windows Server 2025.
- The only Microsoft workaround is stopping, meaning deallocating, an unreachable virtual machine and starting it again, which ends every session on it and does not hold.
- Two further KB5124008 issues were opened the same day: Hyper-V Plan9 host folder shares at 02:22 PT and USB audio at 18:36 PT.
How far it reaches
This is the broadest platform list of the month. On the client side it runs from Windows 11 26H1 through Windows 10 Enterprise LTSC 2016, and on the server side from Windows Server 2012 to Windows Server 2025. If your remote access story involves a session host, a jump box or an RDS licensing server, you are in scope.
September 11 was a heavy day for this one update in general. The dashboard shows two more KB5124008 issues opened the same day, host folder shares in Hyper-V based Linux virtual machines at 02:22 PT and USB audio at 18:36 PT.
| Scope | What the dashboard lists |
|---|---|
| Updates | KB5124008 for 25H2 and 24H2; KB5124012 for 26H1, OS Build 28000.2954, September 8, 2026 |
| Status | Mitigated, opened September 11, 2026 at 11:19 PT, last updated 19:20 PT |
| Clients | Windows 11 26H1 through Windows 10 Enterprise LTSC 2016 |
| Servers | Windows Server 2012 through Windows Server 2025 |
| Also unresponsive | Microsoft Management Console, RDS Licensing Diagnoser, File Explorer, and on 26H1 the Windows Update page |
| Workaround | Stop, meaning deallocate, an affected virtual machine and start it again |
The workaround, and what it costs
Microsoft's published workaround is narrow. If a virtual machine is unreachable over RDP, customers may be able to temporarily restore connectivity by stopping, meaning deallocating, the affected virtual machine and starting it again.
Read the words carefully. Temporarily restore connectivity is a way back into a box, not a remedy. Deallocating a virtual machine ends every session on it, so anyone working through that host loses their work in progress, and nothing prevents the instability returning afterwards. There is no client-side setting, no registry value and no service restart in the entry.
A second report the same day: domain logons
Separately, Endpoint Weekly reported on September 11, 2026 that KB5124008, which brings Windows 11 25H2 to OS Build 26200.9445, breaks machine identity authentication against some domain controllers through stricter Netlogon secure channel negotiation. The controllers it names are Windows Server 2019 and some Windows Server 2022.
The indicators it gives are specific enough to test: Event ID 4625 with Status 0xC000006D on the domain controller, Test-ComputerSecureChannel returning False on the client, and nltest returning ERROR_NO_TRUST_LSA_SECRET (1786). Its workaround is to change the MachineIdentityIsolation registry value from 0x00000002 to 0x00000000 and then run Test-ComputerSecureChannel with the Repair switch, with no restart required, and its guidance is to pause KB5124008 on 25H2 devices that authenticate against Server 2019 or 2022 domain controllers.
One caution. This is a single outlet's report, and unlike the RDS problem it has no Microsoft release health entry behind it as of September 11, 2026. Relaxing a machine identity isolation setting to fix a logon failure is exactly the kind of change to test on one machine and to document, not to push out broadly on a Friday.
What you can do today
1. List the machines that matter: session hosts, jump boxes, RDS licensing servers and any virtual machine you reach only over RDP. Check which of them took KB5124008 or, on 26H1, KB5124012.
2. Hold the update on those roles in WSUS or Intune until Microsoft ships the resolution, and accept the stated cost, which is that those machines stay at August's patch level.
3. If a virtual machine is already unreachable, warn the users, then stop, meaning deallocate, it and start it again. Their sessions will not survive it.
4. When MMC, the RDS Licensing Diagnoser or File Explorer hangs on a patched host, stop troubleshooting it as a separate fault. Microsoft lists all three as part of this one.
5. For the domain logon reports, run Test-ComputerSecureChannel on one affected client and check the domain controller for Event ID 4625 with Status 0xC000006D before you touch any registry value. Confirm the symptom first.
6. Re-read the release health entry before you conclude anything is over. It said Mitigated at 19:20 PT on September 11, 2026, and mitigated is not the same as fixed.
Frequently asked questions
Does Mitigated mean the Remote Desktop problem is fixed?
No. As of September 11, 2026 the entry says Microsoft is working to release a resolution in a future Windows update. Mitigated means the impact has been reduced for some customers while the defect stands.