Microsoft Patch Update Brings Trust Issues for Domain-Joined Windows PCs
Microsoft's September patch update has introduced a trust issue for Windows PCs that are domain-joined. The problem affects Windows 11 versions 24H2, 25H2, and 26H1.
The issue stems from changes to Machine Identity Isolation in the September 2026 security update (KB5124008). Credential Guard-protected machine accounts might lose their secure channel with an on-premises Active Directory domain.
As a result, users may not be able to sign in with valid domain credentials and may see a message complaining about the trust relationship between the device and domain. Microsoft has confirmed that this issue is related to the Machine Identity Isolation feature being enabled without properly checking the domain controller's functional level.
The company has provided a workaround, which involves disabling the Machine Identity Isolation feature using Intune, Group Policy, or the Windows Registry. Administrators must back up the registry before making changes and restart the device after disabling the feature to repair its secure channel using the Test-ComputerSecureChannel PowerShell command.