Microsoft confirms that after installing the September 8, 2026 security update (KB5124008 for Windows 11 24H2/25H2, KB5124012 for 26H1) or later, some Credential Guard–protected machine accounts can lose their secure channel with an on-premises Active Directory domain. Affected users may be unable to sign in interactively with valid domain credentials and may see a trust-relationship error, though offline sign-in with cached credentials, AD replication, and domain controller services are unaffected. Microsoft attributes the cause to the update enabling enforcement of Machine Identity Isolation settings that were already configured but previously inactive.
