Microsoft says it is investigating widespread reports that the Windows 11 KB5124008 security update is breaking domain trust relationships on enterprise machines, causing valid domain credentials to be rejected after a reboot.

Administrators posting on Reddit and Microsoft’s Q&A forums report that affected devices lose their secure channel with Active Directory once the update is installed. Users are told their username or password is incorrect even though the credentials are valid, and cached credentials continue to work offline, pointing to a domain authentication failure rather than an actual password issue.

“Microsoft is aware of these reports and is investigating. We will share guidance as it becomes available,” the company told BleepingComputer. No official workaround has been published yet.

Machine Identity Isolation implicated

While Microsoft has not confirmed a root cause, multiple administrators have linked the failures to Windows’ Machine Identity Isolation feature, part of Virtualization-Based Security and Credential Guard. In enforcement mode, this feature moves the machine account secret into Credential Guard and removes the copy normally stored in LSA. Several admins found the registry value MachineIdentityIsolation under HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa set to ‘2’ (enforcement) after installing KB5124008.

One administrator reported 11 out of roughly 256 Windows 11 25H2 Enterprise devices losing domain trust post-update, alongside Kerberos authentication failures that fell back to NTLM and Netlogon. Another said every Windows 11 25H2 workstation on their network began rejecting valid domain credentials after the update.

Fixes and risks

Uninstalling KB5124008 and repairing the domain relationship has restored access for some admins, though reinstalling the update brings the failure back. Others have resolved the issue by setting MachineIdentityIsolation to ‘0’, rebooting, and then repairing the secure channel with a PowerShell command such as Test-ComputerSecureChannel -Repair -Credential(Get-Credential).

However, disabling the feature carries its own risk. One administrator reported that switching MachineIdentityIsolation from audit or enforcement mode to disabled caused domain trust failures across their environment, even on systems that never had KB5124008 installed. Microsoft’s own documentation warns that disabling the feature after it has run in enforcement mode can break domain authentication entirely, requiring affected devices to be unjoined and rejoined to the domain.

Security teams managing Windows 11 25H2 fleets should hold off on broad changes to Machine Identity Isolation settings until Microsoft confirms the root cause and issues formal guidance.