Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Microsoft

Windows 11 KB5124008 update breaks domain trust for some users

Microsoft is investigating reports that the Windows 11 KB5124008 security update breaks domain trust relationships on some enterprise systems, preventing users from logging in with valid domain credentials.

Administrators said affected computers lose their secure channel with Active Directory after the update is installed and the devices reboot. Cached credentials may continue to work offline, indicating that the problem concerns domain authentication rather than users’ passwords.

Alex Turner, a Windows administrator who reported the issue on Microsoft’s Q&A forums, said Windows 11 25H2 workstations worked normally before KB5124008 was installed. He said uninstalling the update and repairing the domain relationship restored access, while reinstalling it caused the failure to return. Another administrator reported that 11 Windows 11 25H2 Enterprise devices out of approximately 256 lost domain trust after the update.

Reports point to Windows Machine Identity Isolation, particularly when enabled in audit or enforcement mode, but Microsoft has not confirmed it as the root cause. Administrators have reported Kerberos failures followed by NTLM and Netlogon fallbacks. Microsoft has not published an official workaround and said it will share guidance as it becomes available. BleepingComputer said it will update the report when more information is provided.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.