KB5124008 breaking domain trust?
Update KB5124008 breaks domain trust and causes connection status to flip unpredictably between true and false even after rebooting, repairing trust, and disabling machine identity isolation. Because remediation remains inconsistent, administrators cannot confirm whether the fix is actually working for end users to log in.
What people tried
Every workaround mentioned in the threads below. We haven’t tested any of them — and nobody here is claiming they worked.
- 1Manually running Test-ComputerSecureChannel -repair after trust breaks
- 2Disabling machine identity isolation via group policy or registry settings
- 3Checking domain controller replication health and configuring DNS forwarding zones
In their words
Unedited, grouped by where they were said, most upvoted first within each place, each linked to the thread it came from.
“KB5124008 - Breaking Domain Trust for anyone else?”source ↗
“It still returns false half the time after remediation.”source ↗
“It flips back and forth true and false even after disabling machine identity isolation, rebooting, and repairing trust.”source ↗
“What I don’t know, is if the mitigation is actually working for end users to log in.”source ↗
Where this came up
People with this problem also raised
- 2Why did DNS break after promoting a domain controller?
- 5Why are websites and APIs suddenly unreachable?
- 8How to clean up a hacked website and fix malware
- 13How to test if a software integration actually works
- 3How to remotely patch an air-gapped network without USB drives
- 10Sync agent stops with Error 5 Access Denied after internet outage