UK’s trusted IT infrastructure partner since 2003
Servnet
FinanceToolsConfiguratorGet in Touch
Cyber security

Windows AD Logins Can Fail After Sept 2026 Patch: Fix It

London · Servnet News Desk · IT infrastructure analysis4 min read
Share

Microsoft has confirmed that its September 2026 security update can, for some Credential Guard-protected machine accounts, sever the secure channel between domain-joined PCs and on-premises Active Directory, preventing interactive domain sign-in and producing trust-relationship errors. For estates below Windows Server 2025 DFL, this is a configuration/prerequisite issue on clients, not a generic Windows logon bug — and Microsoft has published a mitigation.

Microsoft Patch Tuesday vulnerability counts, 2026
9667254832420Jul 2026Aug 2026Sep 2026MonthFlaws fixedVulnerabilities patched
View the data behind this chart
Microsoft Patch Tuesday vulnerability counts, 2026
Flaws fixedJul 2026Aug 2026Sep 2026
Vulnerabilities patched622398966

What's actually broken

On 16 September 2026, Microsoft added a new known issue affecting Windows 11 24H2 and 25H2 via KB5124008, and 26H1 via its corresponding September security update. The cause is a change to a feature called Machine Identity Isolation, which is designed to let Credential Guard protect machine account secrets rather than storing them in the registry.

The practical effect: Credential Guard-protected machine accounts can lose their secure channel to an on-premises Active Directory domain. Users then see a trust-relationship error and can't sign in with valid domain credentials — even though nothing is wrong with their password or account.

Why the domain functional level matters

The update doesn't flip enforcement on by itself. Instead, it makes Windows start honouring existing or policy-configured Machine Identity Isolation settings. The catch, as Microsoft put it, is that the feature "is supported only in environments connected to domain controllers running at Windows Server 2025 Domain Functional Level (DFL) and above."

Any device previously configured for Machine Identity Isolation — via Intune, Group Policy or registry — that talks to domain controllers below that DFL threshold may experience this issue after patching. Crucially, Microsoft says AD replication and AD services on the domain controllers themselves are unaffected; this is a client-side authentication failure, not a directory outage.

Who in the UK is exposed

This won't hit every domain-joined fleet. It targets organisations that had already enabled Machine Identity Isolation, whether deliberately for hardened endpoint security or as an inherited policy default, while their domain controller estate still sits below Server 2025 DFL. Many UK public sector and mid-market environments running mixed Server 2019/2022 domain controllers alongside newer Windows 11 clients fall squarely into that gap.

Teams that haven't upgraded domain controller functional levels, or are mid-migration, should treat this as a prompt to check exposure now rather than wait for a helpdesk flood. Anyone weighing the broader case for migrating to Windows Server 2025 gets a fresh, concrete reason: DFL alignment isn't just about lifecycle support, it now gates whether a mainstream security feature works at all.

Illustration: Windows AD Logins Can Fail After Sept 2026 Patch: Fix It

The fix: disable, restart, repair

Microsoft's guidance is blunt: disable Machine Identity Isolation using the same channel it was enabled through — Intune, Group Policy, or the Windows Registry. Registry changes carry the usual warning to back up first and know how to roll back before touching anything.

After disabling the feature, restart the affected device, then repair its secure channel with the Test-ComputerSecureChannel PowerShell command. Microsoft notes that offline sign-in using previously cached credentials might continue to work in the meantime, which buys some breathing room for triage rather than an all-hands panic. Longer term, Microsoft says it plans to resolve the issue in a future Windows update by temporarily preventing Machine Identity Isolation enforcement while it improves the feature — but there's no fixed date attached to that yet.

  • Identify devices with Machine Identity Isolation enabled via policy or registry
  • Check domain controller functional level against Server 2025 DFL
  • Disable the feature through the same mechanism used to enable it
  • Restart, then run Test-ComputerSecureChannel to repair trust
  • Watch for Microsoft's future permanent fix before re-enabling

A mega Patch Tuesday, and why triage discipline matters

This isn't happening in isolation. Reporting on the same September 2026 Patch Tuesday puts the total vulnerability count at 966 fixes, including zero-days, alongside a separate Active Directory Domain Services denial-of-service pair (CVE-2026-62762 and CVE-2026-69809) patched in the same release. That volume is exactly the environment where a config-dependent regression like this one hides in plain sight until helpdesks start ringing.

For estates without a rigorous staged rollout, this is a reminder of why patch management discipline — pilot rings, DFL and domain-controller prerequisite checks, and rollback playboons — pays for itself the moment a mainstream security feature interacts badly with an unready back end.

What Servnet-managed estates should do now

If you manage domain-joined fleets directly, the immediate job is inventory: which devices have Machine Identity Isolation configured, and which domain controllers they authenticate against. That's also a good moment to revisit wider machine identity security posture, since Credential Guard-protected machine accounts sit at the centre of this failure mode.

Teams without a current, tested Active Directory forest recovery plan should treat this incident as a live-fire drill for one. And if domain controller hardware or specification is part of the underlying problem, it's worth revisiting guidance on specifying Active Directory domain controllers alongside hardware maintenance and break-fix support to keep DFL upgrades from stalling on ageing kit. Broader identity and endpoint resilience — including zero trust controls and managed detection & response — reduces the blast radius when the next Patch Tuesday regression lands.

Share
Key takeaways
  • KB5124008 (September 2026) can break the secure channel between domain-joined Windows 11 PCs and on-prem AD via Machine Identity Isolation changes
  • Affected versions: Windows 11 24H2, 25H2 and 26H1; known issue confirmed by Microsoft on 16 September 2026
  • Root cause: Machine Identity Isolation requires domain controllers at Windows Server 2025 DFL or later — estates below that break
  • Fix now: disable the feature via Intune/GPO/registry, restart, then run Test-ComputerSecureChannel; a permanent Microsoft fix is planned but undated
Frequently asked

FAQs — Windows AD Logins Can Fail After Sept 2026 Patch

What is causing domain login failures after the September 2026 Windows patch?

Microsoft says changes to Machine Identity Isolation in the KB5124008 update can cause Credential Guard-protected machine accounts to lose their secure channel with on-premises Active Directory, producing trust-relationship errors at sign-in.

Which Windows versions are affected?

Windows 11 versions 24H2, 25H2 and 26H1 are named in Microsoft's known-issue entry, added on 16 September 2026.

How do I fix it right now?

Disable Machine Identity Isolation using the same method used to enable it (Intune, Group Policy or Registry), restart the device, then repair the secure channel with the Test-ComputerSecureChannel PowerShell command.

Will Microsoft release a permanent fix?

Microsoft says it plans to resolve the issue in a future Windows update by temporarily preventing Machine Identity Isolation enforcement while it improves the feature, though no date has been given.

Related

Turning this into a buying decision?

One conversation with an engineer who's specced this before. No sales script.

Talk to Servnet →

Talk to a UK specialist

Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.

or call 0800 987 4111