Microsoft and security news

News

Microsoft Support — KB5124008 Known Issuessource dated 16 Sep 2026

Known Issue: KB5124008 Can Break AD Domain Trust on Credential Guard–Protected Devices

Microsoft confirms that after installing the September 8, 2026 security update (KB5124008 for Windows 11 24H2/25H2, KB5124012 for 26H1) or later, some Credential Guard–protected machine accounts can lose their secure channel with an on-premises Active Directory domain. Affected users may be unable to sign in interactively with valid domain credentials and may see a trust-relationship error, though offline sign-in with cached credentials, AD replication, and domain controller services are unaffected. Microsoft attributes the cause to the update enabling enforcement of Machine Identity Isolation settings that were already configured but previously inactive.

Source note No permanent fix is documented yet as of this writing — Microsoft's advisory describes a workaround (disabling Machine Identity Isolation and repairing the secure channel), not a resolution. Third-party coverage of this issue varies in reliability; this item reflects only what Microsoft's own advisory states.

CISA Known Exploited Vulnerabilities Catalog

CISA Deadline Today: Patch Two Actively-Exploited Windows Zero-Days

CVE-2026-85880 (Windows ALPC heap overflow) and CVE-2026-81963 (Windows Update Stack) were added to CISA's Known Exploited Vulnerabilities catalog after confirmed active exploitation. Both allow an already-authenticated local attacker to escalate to SYSTEM privileges. The federal remediation deadline for both is today, and fixes have been available since Microsoft's September Patch Tuesday.

Source note Both CVEs were actually added to KEV on 2026-09-08 — today is the compliance deadline, not the disclosure date. Some early aggregator coverage mislabeled CVE-2026-85880 as a "Windows Codecs Library" flaw; CISA's own catalog and Microsoft's advisory both identify it as Windows ALPC.

Microsoft Learnsource dated 13 Aug 2026

Entra Agent ID Reaches Full GA — Governance, Lifecycle, and Agent 365 Convergence

Microsoft's Entra Agent ID what's-new page has expanded past the three Conditional Access templates already covered on the site. Entra ID Governance now extends access packages to agent identities for both on-behalf-of and autonomous scenarios, two new sponsor lifecycle-workflow templates address orphaned agents when a sponsor leaves, and agent registry experiences are converging under Microsoft Agent 365, with documented migration paths off plain app registrations and off Copilot Studio agents.

Source note Page's footer says "last updated 2026-05-01" but its metadata says 2026-08-13 — the two disagree, and neither is within the last seven days, so this likely isn't brand-new.

Join the waitlist

Tell me which exam you're sitting and I'll let you know the moment your guide is ready. People on the list get early access and launch pricing.

← Back

You're on the list

Thanks. I'll email you when your guide is ready, and I'll reply if you told me your background.
Which exams(required)

The Lowdown, by email

New posts on Microsoft security and Azure, exam changes as they happen, and first word when the guides launch.

You'll get a confirmation email first. Unsubscribe any time from the link in every email.