Skip to content

WindowsPublished 7 min read

KB5124008 breaks domain trust on Windows 11 PCs with Machine Identity Isolation (September 16, 2026)

Illustration for the article “KB5124008 breaks domain trust on Windows 11 PCs with Machine Identity Isolation (September 16, 2026)”
Listen to this article · 11:36 · AI-generated narration
0:00 / 11:36
Chapters

What administrators have been seeing

A Microsoft Q&A thread opened on September 9, 2026, the day after KB5124008 shipped, has the most detailed account. Its author, Alex Turner, reported domain-joined machines on build 26200.9445 that lost their secure channel, and wrote in the thread on September 10, 2026 that the count was up to six. IT-Connect reported on September 15, 2026 that those six machines sat in an environment with Windows Server 2019 domain controllers, and BleepingComputer reported on September 16, 2026 that Turner's workstations were Windows 11 25H2. Users saw "The user name or password is incorrect" with valid credentials. Test-ComputerSecureChannel returned False, nltest /sc_query returned ERROR_NO_TRUST_LSA_SECRET (1786), and the domain controller logged Event 4625 for the computer account with status 0xC000006D and sub-status 0xC000006A. Recovery in that thread took a full leave and rejoin after the uninstall; Reset-ComputerMachinePassword and Test-ComputerSecureChannel -Repair on their own did not hold.

BleepingComputer's report adds scale. An administrator on Reddit reported 11 of about 256 Windows 11 25H2 Enterprise devices losing domain trust after the update, with Kerberos failures followed by NTLM and Netlogon fallbacks. Another said every 25H2 workstation on their network began rejecting valid domain credentials. BleepingComputer says Microsoft told it the previous week that it was aware of the reports and investigating, and when the report was published Microsoft had not confirmed a cause or published a workaround.

IT-Connect reported that other administrators saw the same failure with Windows Server 2022 domain controllers, patched or not. It also reported that the out-of-band update KB5129195, the subject of my September 15 post, does not fix it.

TL;DR

Domain-joined Windows 11 PCs are rejecting valid passwords after the September security update KB5124008, BleepingComputer reported on September 16, 2026, because the machines lose their secure channel with Active Directory. Microsoft opened a known issue for it on its Windows release health dashboard at 14:15 PT on September 16, 2026, with the status Mitigated. The cause is Machine Identity Isolation, a Credential Guard feature whose enforcement setting Windows now honors after KB5124008, although the feature is only supported with domain controllers at the Windows Server 2025 domain functional level. The workaround is to turn the feature off and repair the secure channel. No fix has shipped.

  • Microsoft's symptom: users cannot sign in with valid domain credentials and might see a message that the trust relationship between the device and the domain failed. Offline sign-in with cached credentials might still work.
  • Affected: Credential Guard protected machine accounts on Windows 11 26H1, 25H2 and 24H2. No server release is listed, and AD replication and AD services on the domain controllers are not affected.
  • Microsoft says the update does not switch enforcement on by itself, and that it makes Windows start honoring an enforcement setting that a registry value or policy already asked for. Administrators quoted by BleepingComputer and IT-Connect say they never configured it.
  • The workaround is to disable Machine Identity Isolation by the method that enabled it, restart, and repair the secure channel with Test-ComputerSecureChannel. Turning enforcement off can itself force a domain rejoin.
  • The September 14 emergency update KB5129195 did not fix it. Microsoft plans a future update that temporarily prevents enforcement, with no date.

What Microsoft confirmed

The release health entry is titled Domain-joined devices might lose their secure trust relationship with the domain. It says that after the September 8, 2026 security update KB5124008, or later updates, some Credential Guard protected machine accounts might lose their secure channel with an on-premises Active Directory domain. Users then cannot sign in interactively with valid domain credentials. Offline sign-in with cached credentials might continue to work, and AD replication and AD services on the domain controllers are not affected.

The cause is stated plainly. KB5124008 does not directly enable Machine Identity Isolation enforcement, but it makes Windows begin honoring any existing or policy-provisioned setting that enabled it. The feature is only supported with domain controllers running at the Windows Server 2025 domain functional level and above, and Microsoft says it should be disabled everywhere else. Any device previously configured for Machine Identity Isolation that is not connected to Windows Server 2025 domain controllers will hit the problem, according to the entry.

Administrators quoted by BleepingComputer and IT-Connect say the value read 2 on machines where they had never configured the feature, one of them with the Group Policy setting left Not configured. Microsoft's entry does not address those reports, so how the value came to be 2 on those machines is unresolved.

ItemDetail
Known issueDomain-joined devices might lose their secure trust relationship with the domain
StatusMitigated, opened September 16, 2026 at 14:15 PT
Originating updateKB5124008, OS Build 26200.9445, September 8, 2026
ScopeCredential Guard protected machine accounts; Windows 11 26H1, 25H2 and 24H2; no server release
SymptomValid domain credentials refused; trust relationship failure message; cached sign-in may still work
CauseWindows now honors Machine Identity Isolation enforcement, supported only at the Windows Server 2025 domain functional level
WorkaroundDisable Machine Identity Isolation, restart, repair the secure channel
FixNone as of September 16, 2026; planned for a future Windows update

The workaround, and what it costs

Microsoft's workaround is to disable Machine Identity Isolation with the same management method that enabled it: Intune policy, Group Policy, or the registry. For the registry, it names two values, HKLM\SYSTEM\CurrentControlSet\Control\Lsa\MachineIdentityIsolation and HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard\MachineIdentityIsolation. If either is 2, set it to 0. Microsoft's registry steps speak of the Windows 11 version 24H2 or 25H2 device, although the same entry's affected list also names 26H1. Then restart the device and reset the secure channel in PowerShell with Test-ComputerSecureChannel -Repair -Credential (Get-Credential).

The cost sits in the warnings. BleepingComputer cites Microsoft's documentation: if Machine Identity Isolation was previously enabled in enforcement mode, disabling it will break domain authentication and the device has to be unjoined and rejoined to the domain. An administrator quoted by BleepingComputer warned that switching the setting from audit or enforcement mode to disabled broke domain trust across their environment, including on systems that had never installed KB5124008. That makes this a change to plan across a fleet, not a quick registry edit on one PC.

Removing KB5124008 is the other route, and it is not cheaper. In the Q&A reproduction, the machines needed a full leave and rejoin even after the update was uninstalled, and Reset-ComputerMachinePassword and Test-ComputerSecureChannel -Repair were not enough. Uninstalling also takes September's security fixes off the machine.

Who is affected, and who is not

The entry is about devices joined to an on-premises Active Directory domain whose machine accounts are protected by Credential Guard. A home PC, or a work laptop that is not joined to such a domain, is outside the scope Microsoft describes. Networks whose domain controllers already run at the Windows Server 2025 domain functional level are the ones Microsoft says support the feature.

Microsoft's next step is a future Windows update that temporarily prevents Machine Identity Isolation enforcement while it improves the feature. The entry gives no date for it. Microsoft also gives no count of affected devices, so I cannot say how common enforcement is outside the reports above. Until the fix ships, the workaround is the only remedy Microsoft offers.

What you can do today

1. If a work PC refuses a password you know is right, or says the trust relationship with the domain failed, tell whoever runs your domain. Microsoft has confirmed this fault, and it is not a forgotten password.

2. Do not reset your own password to fix it. The machine's secure channel with the domain is what failed, and a cached sign-in might still work while the PC is off the network.

3. Administrators: read the MachineIdentityIsolation value under HKLM\SYSTEM\CurrentControlSet\Control\Lsa on an affected PC before changing anything. A value of 2 is the enforcement setting Microsoft's entry describes, and administrators in these reports found it on machines they say they never configured.

4. Disable the feature by the method that enabled it, restart, then run Test-ComputerSecureChannel -Repair -Credential (Get-Credential). Try it on a few machines first, because turning off enforcement can itself break trust and force a rejoin.

5. Do not count on uninstalling KB5124008. In the Q&A reproduction it did not restore trust without a full leave and rejoin, and it removes September's security fixes.

6. If your domain controllers are not at the Windows Server 2025 domain functional level, keep Machine Identity Isolation disabled in new policies until Microsoft ships its fix. Microsoft says the feature should be disabled in those environments.

Get XLAnt

Frequently asked questions

Which PCs are affected by the KB5124008 domain trust bug?

Microsoft says Credential Guard protected machine accounts on Windows 11 26H1, 25H2 and 24H2 that were configured for Machine Identity Isolation and are not connected to Windows Server 2025 domain controllers. No server release is listed.

Has Microsoft fixed the domain trust failure?

No. The release health entry opened at 14:15 PT on September 16, 2026 with the status Mitigated, and Microsoft plans to resolve it in a future update by temporarily preventing enforcement. Until then, the workaround is to disable Machine Identity Isolation and repair the secure channel.

All articles