Microsoft acknowledged a significant issue affecting Windows 11 versions 24H2, 25H2, and 26H1 related to Active Directory domain logins as of September 16. This issue stems from changes made to Machine Identity Isolation in the September 2026 security update (KB5124008), which may cause Credential Guard-protected machine accounts to lose their secure channel with an on-premises Active Directory domain, preventing users from signing in with valid domain credentials. The update activates Machine Identity Isolation but does not enforce it immediately, and it is only compatible with environments linked to domain controllers operating at the Windows Server 2025 Domain Functional Level (DFL) or higher. Microsoft advised that devices not connected to Windows Server 2025 domain controllers will need to disable Machine Identity Isolation. A workaround involves disabling the feature through Intune, Group Policy, or the Windows Registry, followed by a device restart and repairing the secure channel using the Test-ComputerSecureChannel PowerShell command. Microsoft plans to address this issue in a future update by temporarily halting Machine Identity Isolation enforcement while enhancements are made.