Subscribe Sign in

Microsoft patch gives domain-joined Windows PCs trust issues

1 min read Rewritten in plain language

Os Platforms

Show what we removed Rules applied: A3 A6 D2×4 D3×2 F2×5 all 30 rules
  • Machine Identity Isolation policies can reject valid credentials unless controllers meet the Server 2025 functional level.
  • The issue 25H2, and 26H1, was added to Microsoft's ever-lengthening list of known problems on September 16.
  • As a result, users might not be able to sign in with valid domain credentials and may see a message complaining about the trust relationship between the device and domain.
  • Windows begins honoring existing or policy-configured enforcement settings – a problem because the feature is supported only in environments connected to domain controllers running at Windows Server 2025 Domain Functional Level or later.

4 sentences from our version of the report, chosen to cover it. Nothing here is written; every line is in the article below. How

The issue 25H2, and 26H1, was added to Microsoft's ever-lengthening list of known problems on September 16. Administrators must disable Machine Identity Isolation using the same method by which it was enabled: Intune, Group Policy, or the Windows Registry.

Headline check

The one thing this headline claims did not turn up in the report.

  • “PCs” is named in the headline. We could not find it in the report.

Figures, names and quoted words in the headline, looked for in the report itself — not in the summary above. Names are matched as they are spelled, so a report that says “New South Wales” where the headline says “NSW” is queried here when it should not be. How this is checked

Machine Identity Isolation policies can reject valid credentials unless controllers meet the Server 2025 functional level.

Microsoft's September cavalcade of cockups continued with confirmation that something is amiss with Active Directory domain logins.

The issue 25H2, and 26H1, was added to Microsoft's ever-lengthening list of known problems on September 16.

The problem is that Credential Guard-protected machine accounts might lose their secure channel with an on-premises Active Directory domain. As a result, users might not be able to sign in with valid domain credentials and may see a message complaining about the trust relationship between the device and domain.

The update enables Machine Identity Isolation but does not switch on enforcement directly. Windows begins honoring existing or policy-configured enforcement settings – a problem because the feature is supported only in environments connected to domain controllers running at Windows Server 2025 Domain Functional Level or later.

AD replication and AD services on the domain controllers are not affected.

Shortened to 1 minute of reading, this version reads 9 on the Niral Score.

You are reading our version, not theirs. This is The Register's report shortened to its most important sentences, in plainer words, with verdicts and loaded words taken out. Plain description stays, and so do adjectives that carry a fact, such as "former" or "federal". The reporting, the facts and the quotations are theirs — quotations are never edited — and the indicators beside it measure this version. Hover or tap Adjectives to see every one left in the text.

How this outlet filed it, and how we rewrote it

No other newsroom we read has filed on this event, so there is nothing to compare it with yet.

Outlet Niral ScoreAdjectivesSourcingSentimentHappiness
The Registeras they published this story 10.8 5 32 0.1 72.5
Mundane Readneutralized from The Register 10.1 5 32 0.1 72.5

Sign in to react.

Comments

Nothing here yet.

Sign in to comment.

Questions

Readers can ask a question about this story here. Questions and answers are for subscribers. Sign in to read them.

Comments are read before they appear where anything in them needs a person to look. Nothing posted here is ever deleted; a comment taken down keeps its text and the reason, so the decision can be looked at again. How this works