Microsoft’s September 2026 security update KB5124008 is knocking some Windows 11 enterprise clients off Always On VPN after the Patch Tuesday package landed on September 8.
Administrators who can reproduce the failure say certificate-based tunnels that worked immediately before the patch stop connecting afterward, then recover as soon as the cumulative update is removed and the device is rebooted.
The first detailed account appeared on Microsoft Q&A on September 9, 2026, from an administrator running Windows 11 24H2 and 25H2 clients with Always On VPN, certificate-based authentication, Routing and Remote Access Service plus Network Policy Server on Windows Server 2019, and a VPN profile deployed through Microsoft Intune.
Windows 11 Security Update KB5124008
After KB5124008 is installed, Always On VPN no longer connects. Uninstalling the update and rebooting restores the tunnel on multiple machines, which is why the reporter halted the rollout. That working-broken-working cycle is the classic signature of a client-side regression rather than a bad Intune profile or a failing NPS server.
Independent advisor Domic Vo told the original poster the pattern lines up with a change in the Windows networking stack or IPsec certificate handling, not a local configuration mistake.
Vo advised collecting rasphone.pbk data, RasClient events under Applications and Services Logs, and NPS logs if a Microsoft support case is opened. A suggestion to retarget affected Intune profiles toward EAP-TLS should be treated only as an unproven stopgap, not official Microsoft guidance.
KB5124008 is the September 8 cumulative security update for Windows 11 24H2, which moves to build 26100.9445, and 25H2, which moves to build 26200.9445.
Microsoft’s support article still says the company is not currently aware of any issues with this update, even as some IT teams pause deployment on remote-access fleets.
The same release is a mandatory Patch Tuesday package covering a record volume of vulnerabilities, including two elevation-of-privilege zero-days already exploited in the wild: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows Advanced Local Procedure Call.
Holding the client update therefore trades tunnel availability against a large security backlog, which is why many shops will freeze only Always On VPN cohorts in WSUS or Intune rather than blocking the entire estate.
The timing is especially awkward because the same cumulative update also advertised better resiliency for VPN-related background processes that could stop responding.
A security patch that claims VPN hardening while breaking certificate-based Always On VPN is exactly the kind of regression enterprise networking teams watch for after Patch Tuesday.
Until Microsoft documents the failure or ships a hotfix, the conservative path is the one the original environment already took. Pause KB5124008 on Always On VPN endpoints, keep RRAS and NPS servers current, and escalate with RasClient and NPS evidence so the case can be clustered with other reports.
Organizations that must keep the patch for compliance should pilot any authentication change in a small ring and treat uninstall-and-reboot as the only currently proven recovery. Home users without Always On VPN are unaffected.
This is an enterprise remote-access regression sitting on top of an otherwise high-priority Windows 11 security release, and it deserves a known-issue entry before the next servicing wave.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
The post Windows 11 Security Update KB5124008 Breaks Always-On VPN Connections appeared first on Cyber Security News.
