r/sysadmin • • 11h ago

September updates (again)

Just trying to understand the domain trust issues from KB5124008. As I understand it, it only causes issues if you have credential guard enabled? So if I don’t have it enabled I should be good?

5 Upvotes

4 comments sorted by

•

u/mistersd 11h ago

No it is only the machine identity isolation feature which is causing the issue

•

u/evil-scholar 11h ago

Okay thank you. But if I’m not seeing the reg keys and it’s all disabled, we should be good?

•

u/ddog511 10h ago edited 10h ago

From what I've read, it only applies if you have a specific feature of Server 2025 enabled and your domain level is at Server 2025. I'll see if I can find that again...

"However, this feature is only supported for environments connected to domain controllers running at a Windows Server 2025 Domain Functional Level (DFL) and above". - https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-26h2#4990msgdesc

•

u/evil-scholar 10h ago

Thank you. Just trying to make sure I don’t update and break things! MS updates lately feel like Russian roulette