Microsoft is investigating reports that the Windows 11 KB5124008 security update is causing Active Directory domain trust issues on some enterprise computers, preventing users from signing in with valid credentials. Released on September 8, 2026, KB5124008 is a cumulative security update for Windows 11 versions 25H2 and 24H2, advancing them to builds 26200.9445 and 26100.9445, respectively. Microsoft’s release notes currently document USB audio, Hyper-V Plan9 folder-sharing, and Remote Desktop Services issues, but do not mention domain-trust failures among the update’s known problems.

The administrator encountered issues on six systems: KB5124008 installation and restart broke the secure channel, which was resolved by uninstalling the update and rebuilding domain membership. PowerShell's Test-ComputerSecureChannel returned False, and nltest /sc_query: produced ERROR_NO_TRUST_LSA_SECRET, error 1786.

Administrators ruled out DNS discovery, Active Directory replication, time synchronization, account lockouts, duplicate machine SIDs, and general domain-controller health. Enabling Machine Identity Isolation compromises virtualization-based security for machine-account credentials, while uninstalling KB5124008 removes the security patches included with the September cumulative update. Organizations should pause the broad deployment, test policy changes on a limited device group, maintain local administrator or LAPS access, and verify recovery with nltest before returning endpoints to production.

The September 14 out-of-band update KB5129195 addresses documented RDS, Hyper-V Plan9, and multichannel USB audio issues, but its release notes do not mention domain trust or Machine Identity Isolation.