Microsoft is investigating reports that the Windows 11 KB5124008 security update may cause some domain-joined enterprise devices to lose their trust relationship with Active Directory after restarting.
Administrators posting on Microsoft Q&A and Reddit said affected Windows 11 25H2 systems rejected valid domain credentials following installation of the update. In several reports, users could still sign in with cached credentials while disconnected from the network, suggesting the issue involved domain authentication rather than user password changes.
Secure channel failures reported
Domain-joined PCs maintain a secure channel with domain controllers through machine account credentials. When the credentials stored on a device no longer align with the corresponding Active Directory machine account, Windows may display domain trust errors or deny domain logins.
Some administrators said they confirmed that the secure channel had failed on affected systems. They reported that removing KB5124008 and repairing the computer's domain relationship restored access, while reinstalling the update caused the issue to recur. The number of impacted devices appears to vary by environment, with reports ranging from a subset of workstations to all updated Windows 11 systems in an organization.
Machine Identity Isolation under review
Community investigations have pointed to the Windows Machine Identity Isolation setting as a possible factor. The feature is associated with Virtualization-Based Security and Credential Guard, and is intended to protect machine account secrets used for Active Directory authentication.
Administrators observed that some affected endpoints had the MachineIdentityIsolation configuration set to enforcement mode after the update. In that mode, Windows can place the machine account secret under Credential Guard protections and remove the prior copy maintained by the Local Security Authority.
Several administrators said disabling the setting and repairing the secure channel resolved their immediate problem. However, changing the setting can itself disrupt authentication. Microsoft documentation warns that devices previously using enforcement mode may need to be removed from and rejoined to a domain if the feature is disabled.
- Microsoft has acknowledged the reports and said it is investigating.
- The company has not confirmed the root cause.
- No official workaround has been published.
Organizations experiencing the issue should validate changes in a controlled environment and follow Microsoft guidance when it becomes available.
