Microsoft has confirmed that its September 2026 security update can, for some Credential Guard-protected machine accounts, sever the secure channel between domain-joined PCs and on-premises Active Directory, preventing interactive domain sign-in and producing trust-relationship errors. For estates below Windows Server 2025 DFL, this is a configuration/prerequisite issue on clients, not a generic Windows logon bug — and Microsoft has published a mitigation.
View the data behind this chart
| Flaws fixed | Jul 2026 | Aug 2026 | Sep 2026 |
|---|---|---|---|
| Vulnerabilities patched | 622 | 398 | 966 |
What's actually broken
On 16 September 2026, Microsoft added a new known issue affecting Windows 11 24H2 and 25H2 via KB5124008, and 26H1 via its corresponding September security update. The cause is a change to a feature called Machine Identity Isolation, which is designed to let Credential Guard protect machine account secrets rather than storing them in the registry.
The practical effect: Credential Guard-protected machine accounts can lose their secure channel to an on-premises Active Directory domain. Users then see a trust-relationship error and can't sign in with valid domain credentials — even though nothing is wrong with their password or account.
Why the domain functional level matters
The update doesn't flip enforcement on by itself. Instead, it makes Windows start honouring existing or policy-configured Machine Identity Isolation settings. The catch, as Microsoft put it, is that the feature "is supported only in environments connected to domain controllers running at Windows Server 2025 Domain Functional Level (DFL) and above."
Any device previously configured for Machine Identity Isolation — via Intune, Group Policy or registry — that talks to domain controllers below that DFL threshold may experience this issue after patching. Crucially, Microsoft says AD replication and AD services on the domain controllers themselves are unaffected; this is a client-side authentication failure, not a directory outage.
Who in the UK is exposed
This won't hit every domain-joined fleet. It targets organisations that had already enabled Machine Identity Isolation, whether deliberately for hardened endpoint security or as an inherited policy default, while their domain controller estate still sits below Server 2025 DFL. Many UK public sector and mid-market environments running mixed Server 2019/2022 domain controllers alongside newer Windows 11 clients fall squarely into that gap.
Teams that haven't upgraded domain controller functional levels, or are mid-migration, should treat this as a prompt to check exposure now rather than wait for a helpdesk flood. Anyone weighing the broader case for migrating to Windows Server 2025 gets a fresh, concrete reason: DFL alignment isn't just about lifecycle support, it now gates whether a mainstream security feature works at all.

The fix: disable, restart, repair
Microsoft's guidance is blunt: disable Machine Identity Isolation using the same channel it was enabled through — Intune, Group Policy, or the Windows Registry. Registry changes carry the usual warning to back up first and know how to roll back before touching anything.
After disabling the feature, restart the affected device, then repair its secure channel with the Test-ComputerSecureChannel PowerShell command. Microsoft notes that offline sign-in using previously cached credentials might continue to work in the meantime, which buys some breathing room for triage rather than an all-hands panic. Longer term, Microsoft says it plans to resolve the issue in a future Windows update by temporarily preventing Machine Identity Isolation enforcement while it improves the feature — but there's no fixed date attached to that yet.
- •Identify devices with Machine Identity Isolation enabled via policy or registry
- •Check domain controller functional level against Server 2025 DFL
- •Disable the feature through the same mechanism used to enable it
- •Restart, then run Test-ComputerSecureChannel to repair trust
- •Watch for Microsoft's future permanent fix before re-enabling
A mega Patch Tuesday, and why triage discipline matters
This isn't happening in isolation. Reporting on the same September 2026 Patch Tuesday puts the total vulnerability count at 966 fixes, including zero-days, alongside a separate Active Directory Domain Services denial-of-service pair (CVE-2026-62762 and CVE-2026-69809) patched in the same release. That volume is exactly the environment where a config-dependent regression like this one hides in plain sight until helpdesks start ringing.
For estates without a rigorous staged rollout, this is a reminder of why patch management discipline — pilot rings, DFL and domain-controller prerequisite checks, and rollback playboons — pays for itself the moment a mainstream security feature interacts badly with an unready back end.
What Servnet-managed estates should do now
If you manage domain-joined fleets directly, the immediate job is inventory: which devices have Machine Identity Isolation configured, and which domain controllers they authenticate against. That's also a good moment to revisit wider machine identity security posture, since Credential Guard-protected machine accounts sit at the centre of this failure mode.
Teams without a current, tested Active Directory forest recovery plan should treat this incident as a live-fire drill for one. And if domain controller hardware or specification is part of the underlying problem, it's worth revisiting guidance on specifying Active Directory domain controllers alongside hardware maintenance and break-fix support to keep DFL upgrades from stalling on ageing kit. Broader identity and endpoint resilience — including zero trust controls and managed detection & response — reduces the blast radius when the next Patch Tuesday regression lands.
- 01The Register — Microsoft patch gives domain-joined Windows PCs trust issues · 17 September 2026
- 02BleepingComputer — Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days · 9 September 2026
- 03Computer Weekly — Patch Tuesday: Microsoft updates address almost 1000 flaws · 9 September 2026
- 04TechRadar Pro — Microsoft just released its biggest Patch Tuesday ever with 622 fixes · 8 July 2026
- 05The Hacker News — Microsoft patches 398 flaws · 12 August 2026
- 06thehackernews.com
- 07bleepingcomputer.com
- 08bleepingcomputer.com
