Windows update locks some workers out of domain accounts
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Friday, September 18th, 2026.
Some Windows 11 users are being locked out of their domain accounts even though their credentials are still valid. Microsoft is investigating reports that update KB5124008 can break the secure channel between certain enterprise computers and Active Directory after the devices restart. Administrators have linked the failures to Machine Identity Isolation settings, but Microsoft hasn’t confirmed the cause or published an official workaround. In one reported environment, 11 of approximately 256 updated devices lost domain trust.
For affected organizations, the result can be failed logins, rising helpdesk demand, and hands-on recovery across managed fleets. Cached credentials may continue working while a computer is offline, which can make the incident look like a password problem even though domain authentication is the real issue. Leaders should balance the update’s security value against the operational risk of broad deployment before testing is complete. Defenders should preserve local administrator access and verify secure-channel health after pilot updates. For now, pause broad deployment, test representative devices, and make sure local recovery access works while Microsoft continues its investigation.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.