Microsoft is investigating reports that the Windows 11 cumulative security update KB5124008 can break Active Directory domain trust relationships after affected enterprise endpoints restart. On Windows 11 24H2 and 25H2 systems, the issue reportedly disrupts the machine-account secure channel with domain controllers, preventing valid domain users from signing in; cached offline credentials may remain usable.
Administrator reports link the failures to Machine Identity Isolation operating in enforcement mode, although Microsoft has not confirmed the root cause, added the problem to its known-issues documentation, or released an official workaround. Organizations should limit deployment, preserve local administrator or LAPS recovery access, and test remediation carefully; reported options include uninstalling the update, repairing or resetting the machine-account password, or rejoining systems to the domain, while disabling Machine Identity Isolation may reduce security protections or itself affect authentication.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Microsoft released out-of-band update KB5129195 to address documented Remote Desktop Services, Hyper-V Plan9 folder-sharing, and multichannel USB audio issues. The update did not mention Active Directory domain-trust failures or Machine Identity Isolation.
Microsoft released cumulative security update KB5124008 for Windows 11 versions 25H2 and 24H2, advancing them to builds 26200.9445 and 26100.9445, respectively.
Microsoft began investigating community reports that KB5124008 breaks Active Directory domain trust on some enterprise devices. Microsoft had not confirmed the update as the cause, identified a root cause, or issued an official workaround.
Administrators associated the affected systems with Machine Identity Isolation set to enforcement mode, where machine-account secrets are isolated in Credential Guard. Reported recovery measures included disabling the setting and repairing the secure channel or rejoining devices, though disabling it reduces credential protections and can itself require a domain rejoin.
Administrators reported that installing KB5124008 and rebooting domain-joined Windows 11 25H2 devices broke their computer secure channels, preventing interactive domain logons with valid credentials. Uninstalling the update and repairing or rebuilding domain membership restored access in reported tests, while reinstalling the update reproduced the failure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.