A recent security update from Microsoft, KB5124008, has caused disruptions for organizations using on-premises Active Directory, particularly affecting domain-joined Windows 11 devices with Credential Guard. After installing this update, some devices lost their secure trust relationship with the domain, preventing users from logging in with valid credentials. The issue is linked to Machine Identity Isolation, a security feature that enhances machine account credential protection but requires domain controllers to operate at the Windows Server 2025 Domain Functional Level. Organizations that enabled this feature without meeting the prerequisite may experience trust relationship failures. Microsoft has suggested a workaround to disable Machine Identity Isolation and plans to suspend its enforcement in an upcoming update while improvements are made.