Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Microsoft

Microsoft: September 2026 Windows updates break Always On VPN connections

Microsoft has warned IT administrators that users may experience Always On VPN connection problems after installing the September 2026 security updates for Windows 11.

Always On VPN is a remote-access system that replaces DirectAccess. It supports domain-joined, non-domain-joined, and Microsoft Entra ID–joined devices running Windows 10, Windows 11, and Windows Server. The service can establish a secure tunnel to a corporate network when a device connects to the internet, while allowing administrators to control which apps and services use the connection. It supports IKEv2 and SSTP, as well as multi-factor authentication (MFA).

In a service alert seen by BleepingComputer and shared by Microsoft MVP Susan Bradley, Microsoft said affected systems may fail to connect to an organization's enterprise network. The issue can occur when the VPN automatically tries another connection method after an initial failure, such as automatic protocol selection with IKEv2 and SSTP.

Affected connections may remain in a “Connecting” state, repeatedly retry, or show the error, “The specified port is already in use.” Microsoft is working on a permanent solution. As a temporary workaround, IT administrators can change the Always On VPN profile from automatic protocol selection to one of two protocols: SSTP only or IKEv2 only. Microsoft said organizations should choose based on their environment, security, and deployment requirements.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.