Microsoft acknowledges possible domain‑trust breakage in KB5124008
Microsoft confirmed it is aware of reports that the Windows 11 KB5124008 security update may break domain trust relationships and is actively investigating the issue.
The problem appears to surface after the update is applied and the system is rebooted. Administrators have observed that the secure channel between the workstation and Active Directory disappears, leading to Kerberos authentication failures and a fallback to NTLM or Netlogon.
Technical clues
Microsoft documentation states that disabling Machine Identity Isolation when it was previously enabled in enforcement mode can break domain authentication and may require the device to be unjoined and rejoined to the domain. This aligns with several unconfirmed reports linking the KB5124008 failures to the Machine Identity Isolation feature.
Unconfirmed observations (reported on Reddit and Microsoft Q&A):
- Devices lose their secure channel after installing KB5124008 and rebooting.
- One admin saw 11 out of ~256 Windows 11 25H2 Enterprise PCs lose domain trust.
- Kerberos failures followed by NTLM/Netlogon fallbacks.
- The registry key
MachineIdentityIsolationset to2(enforcement mode) after the update. - Disabling Machine Identity Isolation reportedly stops the issue without removing the update.
- Running
Test-ComputerSecureChannel -Repair -Credential (Get-Credential)after disabling the feature restored the secure channel for some admins.
Who is affected?
The reports focus on Windows 11 25H2 (Enterprise) devices that have the KB5124008 update applied. No CVE has been assigned, and the impact appears limited to environments that rely on domain authentication.
Immediate defensive steps
- Delay deployment of KB5124008 in production until Microsoft releases guidance.
- If the update is already installed, verify whether
MachineIdentityIsolationis enabled (registry pathHKLM\SYSTEM\CurrentControlSet\Control\Lsa\MachineIdentityIsolation). - Consider disabling Machine Identity Isolation (set the value to
0) on affected machines, then reboot. - Run
Test-ComputerSecureChannel -Repair -Credential (Get-Credential)to re‑establish the secure channel. - Monitor event logs for Kerberos errors (ID 4768, 4769) and Netlogon failures.
- Maintain a rollback plan: keep the update package handy so you can uninstall KB5124008 if the issue persists.
Keep an eye on Microsoft’s security advisory channels for any official fix or further clarification.
