Microsoft confirms that update KB5124008 may break domain trust in Windows 11
Microsoft confirms that KB5124008 may break the trust relationship with Active Directory domains on certain Windows 11 devices with Credential Guard. We explain the scope, symptoms, and documented recovery.

News summary
Microsoft has acknowledged, in its Windows release health advisory, that the KB5124008 security update —published on 8 September 2026 for Windows 11 24H2 and 25H2— can cause some computer accounts protected by Credential Guard to lose the secure channel with an on-premises Active Directory domain. The visible result is a domain login failure even when credentials are correct.
This is not a universal issue. The behaviour has been observed in specific configurations related to Machine Identity Isolation, a feature associated with Credential Guard that protects machine account secrets. Microsoft indicates that the update does not necessarily enable the feature itself: what it does is begin enforcing a configuration that already existed on the device or had been applied via policies.
On affected devices, logging in with cached credentials may continue to work, creating a false sense of normality: the user enters Windows, but the device can no longer authenticate against the domain or normally access resources that depend on it.
Documented recovery does not involve editing the registry as a first step or hastily uninstalling a security update. It requires identifying how the configuration was applied, reverting it through the same management channel, restarting the device, and repairing the secure channel with the domain, subsequently validating authentication and resource access.
Source: Microsoft Learn — 18 September 2026
Which devices may be affected
The conditions described by Microsoft are Windows 11 24H2 (build 26100.9445) or 25H2 (build 26200.9445), KB5124008 or later updates, Credential Guard enabled, Machine Identity Isolation in audit or enforcement mode, and membership of a local Active Directory domain. The potential impact is the loss of the secure channel and domain authentication failures. Meeting these conditions does not in itself confirm that the machine is affected: the installed version and the specific configuration of each domain must be verified.
Microsoft has also linked this behaviour to certain more recent client configurations, including Windows 11 26H1. Official documentation applicable to each build should be consulted before taking action.
What is the Windows 11 KB5124008 update
KB5124008 is the cumulative security update released by Microsoft on 8 September 2026 for Windows 11 24H2 and 25H2. It brings systems to builds 26100.9445 (24H2) and 26200.9445 (25H2), and forms part of the standard monthly patching cycle.
Days after its distribution, Microsoft added an issue to the known issues list that may affect systems protected by Credential Guard and with Machine Identity Isolation configurations. The update remains a security update: the recommendation is not to avoid it, but to check the security configuration of the fleet before and after applying it.
What problem does KB5124008 cause in Active Directory
In an Active Directory domain, each joined machine has its own computer account, with a password that the system renews automatically. This credential maintains the secure channel between the machine and the domain controller, and is what subsequently allows user logins to be validated, group policies to be applied, and shared resources to be accessed.
When the computer account secrets no longer match what Active Directory expects, the secure channel breaks. Credential Guard isolates these secrets in a protected environment, and Machine Identity Isolation reinforces that isolation. If protection begins to be applied in a scenario that does not meet the expected requirements, the machine may lose the ability to prove its identity to the domain.
Therefore, the symptom should not be interpreted as a simple user password error: what is failing is the trust relationship between the machine and the domain. Resetting the password of the person unable to log in resolves nothing, as the problem lies with the computer account itself.
Symptoms that may appear on affected systems
Symptoms typically appear following the installation of the update and a subsequent system reboot. These are the most common behaviours reported by administrators and documented by Microsoft:
- The message “The trust relationship between this workstation and the primary domain failed”.
- Users being unable to log in with their domain credentials, even when they are correct.
- Windows access granted only via previously cached credentials.
- Inability to access domain shared folders and resources.
- Failures in login scripts and issues when applying group policies.
- Errors in applications that rely on Active Directory authentication.
- Systems that appear to work offline but fail when authenticating against the domain.
- The need to re-establish the secure channel with the domain controller.
What is Machine Identity Isolation
Machine Identity Isolation is a Windows security feature that protects secrets associated with the machine account within a Credential Guard environment. Its objective is to make it harder for an attacker with access to the computer to reuse that machine's identity within the domain.
Microsoft describes three configuration modes: 0 (disabled), 1 (audit), and 2 (enforcement). The transition from audit to enforcement is precisely the critical point, as it changes the system's actual behaviour regarding the machine identity.
The feature has compatibility requirements related to the domain functional level and domain controllers: Microsoft associates it with environments featuring a Windows Server 2025 functional level or higher. In domains that do not meet this requirement, forcing enforcement can lead to the described authentication failures.
This does not make Machine Identity Isolation a feature that should be disabled across the board. It is a legitimate security control: the correct decision is to align its configuration with the actual capacity of the domain, rather than giving up on protection by default.
How to recover an affected machine
The procedure documented by Microsoft is a temporary mitigation while a definitive fix is prepared. It must be executed with discretion and by documenting every step, especially in companies with many machines:
- Identify whether the machine is actually affected and not facing another network, DNS, or profile incident.
- Confirm the Windows version and build, and whether KB5124008 is installed.
- Check if Credential Guard is active on the machine.
- Review how Machine Identity Isolation was configured: Intune, group policy, registry, or management tool.
- Disable policy enforcement using exactly the same channel that enabled it.
- Restart the computer, repair the secure channel using the appropriate credentials, and validate login, policies, and shared resources.
- Re-evaluate the security configuration and plan its reactivation once the environment meets the requirements.
Diagnostic and repair commands
Microsoft documents the repair of the secure channel via PowerShell, executed with local administrator privileges and domain credentials with sufficient permissions: Test-ComputerSecureChannel -Repair -Credential (Get-Credential).
For preliminary diagnosis, nltest utilities can be used, specifying the actual domain name or domain controller: nltest /sc_query:DOMINIO and nltest /sc_verify:DOMINIO. None of these commands should be executed automatically across the fleet without first understanding the status of each machine.
Important notice: do not disable Credential Guard, Machine Identity Isolation, or modify the registry without previously verifying how the policy was applied and what impact it may have on authentication and domain membership.
Why a quick registry modification is not advisable
The configuration may be reflected in HKLM\SYSTEM\CurrentControlSet\Control\Lsa\MachineIdentityIsolation and HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard\MachineIdentityIsolation. If the value is applied by a group policy or Intune, it will be overwritten in the next cycle and the manual change will be temporary.
- Breaking the authentication of machines that were functioning until that moment.
- The issue persists after restarting because the policy is reapplied.
- Forcing the equipment to be removed from the domain and rejoined.
- Reducing the protection of machine account secrets.
- Turning an isolated incident into a widespread issue.
The procedure applied by Seintec
In managed environments, the review was conducted in an orderly and documented manner, without mass changes or improvised uninstalls of security updates. This is the itinerary followed, adapted in each case to the specific configuration of each domain:
- Inventory of versions, builds, and equipment with KB5124008 installed.
- Review of Credential Guard, Machine Identity Isolation, group policies, and Intune.
- Testing of the secure channel with the domain controller.
- Validation of login, shared resources, and dependent applications.
- Review of security and authentication events.
- Documentation of changes and subsequent monitoring.
What businesses should do now
If your fleet includes Windows 11 devices joined to a local domain, this is a reasonable workflow to mitigate the risk without causing a major incident:
- Inventory Windows 11 devices and verify version, build, and domain membership.
- Identify where KB5124008 is installed and whether Credential Guard is active.
- Analyse the configuration and Machine Identity Isolation mode.
- Consult Group Policy and Intune to locate the configuration source.
- Review trust and authentication errors and verify the secure channel.
- Perform a backup and document any changes before application.
- Apply the remediation recommended by Microsoft and validate with real users.
- Register the equipment that has had to rejoin the domain.
Impact for companies with Active Directory
A domain trust failure is not an aesthetic issue: it disrupts user workflows from the very first minute of the day. Sound patch management includes inventory, pilot group pre-testing, backups, documentation, monitoring, and a rollback plan defined before touching production.
- Users unable to log in and downtime at workstations or departments.
- Loss of access to shared folders, ERP, printers, and file servers.
- Security policies that are no longer applied correctly.
- Increase in the volume of calls to internal support.
- Risk of applying urgent changes without control or documentation.
How Seintec can help you with Active Directory and Windows
Seintec manages Windows infrastructures for businesses with local domains, cloud, or hybrid environments. In incidents such as this, the value lies in having a team that understands the environment’s previous configuration and can act without improvisation.
- Active Directory administration and Windows domain management.
- Windows 11 and Windows Server support.
- Professional patch management with windows, testing, and rollback plans.
- Credential Guard, security policies, group policies, and Microsoft Intune.
- Migration and maintenance of domain controllers.
- Resolution of trust relationship and secure channel errors.
- Monitoring, managed maintenance, cybersecurity, backup, and recovery.
- Remote desktop and virtual desktops.
Sources and documentation consulted
Official Microsoft documentation is the primary technical reference and may be updated with new guidance. The information was consulted on 18 September 2026.
- Microsoft: Status of Windows 11 24H2 and known issues
- Microsoft: Windows 11 25H2 status and known issues
- Microsoft Learn: Credential Guard documentation
- Microsoft Learn: Secure channel repair
- Microsoft Q&A: Secure channel failure technical report
- BleepingComputer: Domain trust issue coverage
- NeoTeo: Context on Microsoft confirmation
Frequently Asked Questions
- What is KB5124008?
- It is a Windows 11 security update, published on 8 September 2026 for versions 24H2 and 25H2, which may affect certain machines protected with Credential Guard and Machine Identity Isolation configurations.
- Does KB5124008 affect all Windows 11 machines?
- No. The impact depends on the installed version, the machine’s security configuration, whether Credential Guard is active, the applied policies and the relationship with an on-premises Active Directory domain.
- What does it mean that the trust relationship has failed?
- It means that the device can no longer correctly establish the secure channel with the domain controller to validate its machine account; therefore, user authentication against the domain ceases to function.
- Can I fix this by changing a registry key?
- It should not be done in an improvised manner. First, you must identify how Machine Identity Isolation was configured and apply the recovery via the original management channel, as a group policy or Intune may re-apply the previous value.
- Which command can repair the secure channel?
- Microsoft documents the use of Test-ComputerSecureChannel -Repair -Credential (Get-Credential). It must be executed with appropriate domain credentials and after verifying the actual status of the device.
- Will I have to rejoin the device to the domain?
- In some cases, it may be necessary, especially if a Machine Identity Isolation configuration that was in enforcement mode is modified and the secure channel repair proves insufficient.
- Can Seintec review these issues?
- Yes. Seintec can review Active Directory, Credential Guard, group policies, Intune, secure channels, domain controllers, and Windows 11 devices, and apply a controlled and documented recovery.
Trust relationship errors must not be resolved by applying isolated registry changes. Within a corporate infrastructure, it is essential to identify the policy that triggered the behaviour, repair the secure channel, and validate that security and authentication continue to function correctly. Speak with a Seintec specialist.
Contact SeintecRelated service
Managed IT Services
We keep your systems operational and failure-free.