
Microsoft is investigating reports that the Windows 11 update KB5124008 disrupts domain trust relationships on corporate systems, preventing logins with valid credentials. Microsoft confirmed to BleepingComputer: "We are aware and are investigating, and will provide guidance as it becomes available."
Administrators report on Reddit and Microsoft forums: after installing the update and rebooting, the secure channel with Active Directory disappears. Administrator Alex Turner stated that Windows 11 25H2 workstations were functioning normally until KB5124008, after which they began showing domain login errors. Cached credentials continued to work, indicating a domain authentication issue rather than password problems. Removing the update and restoring the domain connection helped; reinstalling brought back the error. Another administrator reported that out of ~256 devices running Windows 11 25H2 Enterprise, 11 lost domain trust, and there were also Kerberos failures with fallback to NTLM and Netlogon.
Turner linked the issues to the MachineIdentityIsolation setting, which after the update was set to "2" – enforcement mode. The feature is part of the VBS and Credential Guard configuration: it isolates machine credentials for AD authentication, moves the account secret to Credential Guard, and removes the copy from LSA. Some administrators restored systems by setting the parameter to "0", rebooting, and restoring the channel via PowerShell. "After rebooting, I had to restore the channel with this command. Since then, the computer has been working without losing the channel," explained Marcel Zender.
Disabling the feature should be done cautiously: one administrator warned that changing the mode to "disabled" caused domain trust issues even on systems without KB5124008. Microsoft's documentation warns: if the feature was in enforcement mode, disabling it will disrupt authentication and require the device to be rejoined to the domain.





