Microsoft shares workaround for Windows 11 domain login issues caused by KB5124012
After the September KB5124012 security update for Windows 11, some machines under Credential Guard lose trust with the local Active Directory domain and reject domain credentials. The cause is Machine Identity Isolation, which requires Windows Server 2025-level controllers. Microsoft suggests disabling the feature via Intune, Group Policy or the registry and rebooting.
- Issue affects Credential Guard machines in AD domains
- Cause is Machine Identity Isolation, needs Windows Server 2025 DFL
- Workaround: disable the feature and restart the device
- Fix promised in a future Windows update
Read next
Software