Urgent.News

What's breaking now, across thousands of outlets.

Tech

Microsoft patch gives domain-joined Windows PCs trust issues

Machine Identity Isolation policies can reject valid credentials unless controllers meet the Server 2025 functional level

Microsoft patch gives domain-joined Windows PCs trust issues

Microsoft's September software rollout has brought about yet another set of issues with its Active Directory domain logins. The problem, discovered on September 16, impacts Windows 11 versions 24H2, 25H2, and 26H1. It is attributed to alterations in Machine Identity Isolation introduced with the September 2026 security update (KB5124008).

The issue lies in Credential Guard-protected machine accounts potentially losing their secure connection with an on-premises Active Directory domain, resulting in users being unable to log in with valid domain credentials and encountering messages about trust relationship problems between the device and domain.

The September update enables Machine Identity Isolation but does not activate enforcement directly. Instead, Windows starts respecting existing or policy-configured enforcement settings. This becomes problematic because the feature is only supported in environments connected to domain controllers with a Windows Server 2025 Domain Functional Level (DFL) or later.

Devices that were previously configured to use Machine Identity Isolation but are not connected to Windows Server 2025 domain controllers will face this issue and must disable the feature, according to Microsoft.

Offline sign-in using cached credentials may still function. Active Directory replication and services on the domain controllers remain unaffected. Microsoft has offered a workaround, which involves disabling Machine Identity Isolation using the same method that was used to enable it: Intune, Group Policy, or the Windows Registry.

Administrators are advised to back up the registry and understand how to restore it before making changes. After disabling the feature, a restart of the device and repair of the secure channel using the Test-ComputerSecureChannel PowerShell command is necessary.

Microsoft has expressed its plans to resolve the issue in a future Windows update by temporarily disabling Machine Identity Isolation enforcement while enhancements to the feature are made. The feature's usefulness lies in the protection of machine account secrets by Credential Guard instead of storing them in the registry. However, its implementation has proven more complex than anticipated. This revelation comes on the heels of Microsoft's out-of-band update to address other problems introduced in the September update.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Tech

More from Thursday 17 September →