Keeping this short because people dealing with this right now don't need a long read.
Microsoft confirmed Wednesday that installing the September 2026 Patch Tuesday security updates on Windows 11 devices joined to a domain can break domain credential authentication entirely. Users enter valid credentials and get rejected. The machine is fine, the credentials are fine, the domain is fine. The update broke the handshake between them.
This is specifically hitting Windows 11 devices. Windows 10 and Server are not affected.
The irony is not lost on anyone. Security teams that moved fast to patch in response to the wormable DNS bug, the actively exploited zero-days, and the Cisco ISE situation this week are now fielding lockout calls from users who can't get into their machines.
Microsoft has published a temporary fix through the Known Issue Rollback mechanism. IT admins can deploy a Group Policy to roll back the specific change causing the authentication failure without uninstalling the full security update. The fix requires a restart to take effect after the policy applies.
The steps are on Microsoft's support page under the September 2026 Windows 11 known issues section. Search "KB5124008 domain login" and it should come up directly.
This is listed as a known issue with a fix in progress. A permanent resolution is expected in a future update. In the meantime, the Group Policy rollback is the recommended path rather than uninstalling the security update entirely, since that would undo the other fixes from this cycle.
Sources: BleepingComputer, Microsoft Support known issues page
Source: r/PureVPNforTeams · by /u/PureVPNforTeams