Has anyone seen domain trust or machine secure-channel problems after installing KB5124008 on a Windows 11 25H2 client? In my environment, the domain controllers are running Windows Server 2019 and have not been patched yet. After installing the update and rebooting, I could still sign in with domain credentials, but Test-ComputerSecureChannel returned false and reported that the secure channel was broken. However, nltest /sc_query:domain reported a successful connection to the domain controller. Running Test-ComputerSecureChannel -Repair restored the secure channel, and later checks returned True. I'm trying to determine whether this is a real update-related issue or an isolated false alarm before rolling the update out to more clients.
1 Answer
I saw something similar after installing KB5124008 on a Windows 11 25H2 workstation while the domain controllers were still on Server 2019. Test-ComputerSecureChannel reported a broken trust, even though nltest /sc_query:domain showed a healthy Netlogon connection and successful communication with the DC. Running Test-ComputerSecureChannel -Repair fixed it. I’m continuing to test other machines to see whether the problem is reproducible or just a misleading status result.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures