Windows 11 September 2026 Update Breaks Domain Logins: Microsoft Issues Temporary Fix
Microsoft has published a temporary fix for a known Windows 11 issue that prevents users from signing in with valid domain credentials after installing the September 2026 security update.
Reports from users and IT administrators on the Microsoft Q&A forum, Reddit, and other online platforms indicate that the bug breaks domain trust relationships on some corporate systems. Affected users may see domain trust and credential errors even when their usernames and passwords are valid.
Why Windows 11 domain logins are failing
Administrators investigating the issue have linked it to Machine Identity Isolation, a Windows security mechanism that is being set to forced mode starting this month.
The issue affects systems that install KB5124008 on Windows 11 24H2 or 25H2, or KB5124012 on Windows 11 26H1.
Microsoft’s documentation warns that enabling and then disabling Machine Identity Isolation in enforced mode can break domain authentication. In that situation, the device must be unjoined and then rejoined to the Windows domain.
Microsoft confirmed Wednesday that the authentication problems are caused by the September 2026 security update. The update enables Windows to respect existing settings or policies that enforce Machine Identity Isolation, which can result in domain trust failures and sign-in problems with valid credentials.
“Although this update does not directly enable machine identity isolation enforcement, Windows will begin respecting settings provisioned in existing settings or policies that enable machine identity isolation enforcement,” Microsoft said in its release health dashboard.
Microsoft added that the feature is supported only in environments connected to domain controllers running at the Windows Server 2025 domain functional level (DFL) or higher. It must be disabled in other environments.
Administrators should disable Machine Identity Isolation on devices that were previously configured to use it but are not connected to a Windows Server 2025 domain controller.
How to fix Windows 11 domain trust errors
Microsoft is working on a permanent solution that will temporarily disable Machine Identity Isolation enforcement in a future Windows update. In the meantime, administrators can disable the feature using the same administrative method used to enable it.
For example, administrators must disable Machine Identity Isolation in Intune if it was enabled through an Intune policy. If it was enabled through Group Policy, administrators should use the corresponding Group Policy setting.
Disable Machine Identity Isolation through the registry
If Machine Identity Isolation was enabled directly in the Windows registry, follow these steps:
1. On a Windows 11 version 24H2 or 25H2 device, locate these registry paths:
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\MachineIdentityIsolation
HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard\MachineIdentityIsolation
2. For either registry key, if MachineIdentityIsolation is set to 2, change it to 0.
3. Restart the device after disabling Machine Identity Isolation.
4. Reset the secure channel by running:
Test-ComputerSecureChannel -Repair -Credential (Get-Credential)
Other Windows 11 update issues remain
On Monday, Microsoft also released an out-of-band Windows update to address a Remote Desktop Services failure, Hyper-V issues, and USB audio problems caused by this month’s security updates.
However, the emergency updates did not resolve all audio issues introduced by the September 2026 update. Microsoft is continuing to work on fixes for the remaining problems.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



