Microsoft's record patch took Remote Desktop down with it. The fixes landed on 14 September.
Microsoft & Cloud

Microsoft's record patch took Remote Desktop down with it. The fixes landed on 14 September.

September's 974 CVE update left some servers refusing RDP connections. Out of band updates have cleared that, and one of them carries a known issue that can lock staff out of a domain joined PC.

21 September 20264 min read

Microsoft released out of band cumulative updates on 14 September 2026 to clear up damage from its 8 September security release, the one that fixed a record 974 CVEs. KB5129195 covers Windows 11 24H2 and 25H2. KB5129235 covers Windows Server 2025. Infosecurity Magazine reported on 15 September that Microsoft had by then issued six emergency patches to fix failures stemming from September's Patch Tuesday.

What broke

Both update pages describe the fault in the same words: "In affected environments, RDS might become unstable, causing RDP connection and sign-in failures or servers to become unresponsive during Remote Desktop configuration." Microsoft adds that "Related tools, including Microsoft Management Console (MMC), RDS Licensing Diagnoser, File Explorer, and the Windows Update page, might also stop responding."

If you run a terminal server, or any machine staff connect into over RDP, that is a working day gone. The fix is to install the out of band update. Microsoft describes the Windows Server 2025 release as a non-security cumulative update that carries the quality improvements from the 8 September package, so it is one install rather than two.

The known issue to read before you deploy

KB5129195 carries a known issue headed "Domain-joined devices might lose their secure trust relationship with the domain". Microsoft's description is that after installing the 8 September update or later, "some Credential Guard protected machine accounts might lose their secure channel with an on-premises Active Directory (AD) domain". Staff then cannot sign in with valid domain credentials and see a message saying the trust relationship between the device and the domain failed. Microsoft says offline sign in using previously cached credentials might still work, and that "AD replication and AD services on the domain controllers are not affected".

The cause is a feature called Machine Identity Isolation. Microsoft says the September update does not switch enforcement on by itself, but it does make Windows start honouring settings that were already in place. The feature is only supported where domain controllers run at Windows Server 2025 Domain Functional Level or above, so any device configured to use it without those domain controllers will hit the fault. The workaround is to disable Machine Identity Isolation using whichever method turned it on, Intune, Group Policy or the registry, restart the device, then repair the secure channel. Microsoft says it plans to resolve the issue in a future Windows update by temporarily preventing enforcement while the feature is improved.

One more thing if your staff wear headsets

A second known issue on both pages covers USB Audio Class 1.0 devices, which after the 8 September update might fail to start or produce no audio. Symptoms include "This device cannot start (Code 10)" in Device Manager, unresponsive volume controls, and sound settings that do not respond. The out of band update fixed one variant of this, affecting multichannel audio, and Microsoft is explicit that other audio symptoms are not resolved by it. If your team runs a softphone through a USB headset, that is a support call waiting to happen.

KB5129195 also carries a security fix of its own. Microsoft says the update "includes protections documented in CVE-2026-62721", which it describes as a Windows User-Mode Power Service elevation of privilege vulnerability.

What this means for your business

If you have a server anyone remotes into, install the out of band update. That is the short version. Before you push it across a domain, check two things: whether Machine Identity Isolation has been set anywhere in your Intune or Group Policy configuration, and whether your domain controllers are at Windows Server 2025 functional level. If the answer is set and no, your staff will start seeing trust relationship failures and somebody will spend the morning resetting secure channels. Microsoft has published the workaround and says a fuller fix is coming in a later update. The wider lesson from this month is that a patch window and a restart window are two different bookings, and September needed both.

#WEARECOBALT

Ready when you are.

Tell us what's slowing your business down. We'll tell you exactly how we'd fix it — plainly, with no obligation.