Microsoft confirms that after installing the September 8, 2026 security update (KB5124008 for Windows 11 24H2/25H2, KB5124012 for 26H1) or later, some Credential Guard–protected machine accounts can lose their secure channel with an on-premises Active Directory domain. Affected users may be unable to sign in interactively with valid domain credentials and may see a trust-relationship error, though offline sign-in with cached credentials, AD replication, and domain controller services are unaffected. Microsoft attributes the cause to the update enabling enforcement of Machine Identity Isolation settings that were already configured but previously inactive.
Source note No permanent fix is documented yet as of this writing — Microsoft's advisory describes a workaround (disabling Machine Identity Isolation and repairing the secure channel), not a resolution. Third-party coverage of this issue varies in reliability; this item reflects only what Microsoft's own advisory states.
CVE-2026-85880 (Windows ALPC heap overflow) and CVE-2026-81963 (Windows Update Stack) were added to CISA's Known Exploited Vulnerabilities catalog after confirmed active exploitation. Both allow an already-authenticated local attacker to escalate to SYSTEM privileges. The federal remediation deadline for both is today, and fixes have been available since Microsoft's September Patch Tuesday.
Source note Both CVEs were actually added to KEV on 2026-09-08 — today is the compliance deadline, not the disclosure date. Some early aggregator coverage mislabeled CVE-2026-85880 as a "Windows Codecs Library" flaw; CISA's own catalog and Microsoft's advisory both identify it as Windows ALPC.
Microsoft's Entra Agent ID what's-new page has expanded past the three Conditional Access templates already covered on the site. Entra ID Governance now extends access packages to agent identities for both on-behalf-of and autonomous scenarios, two new sponsor lifecycle-workflow templates address orphaned agents when a sponsor leaves, and agent registry experiences are converging under Microsoft Agent 365, with documented migration paths off plain app registrations and off Copilot Studio agents.
Source note Page's footer says "last updated 2026-05-01" but its metadata says 2026-08-13 — the two disagree, and neither is within the last seven days, so this likely isn't brand-new.