All news
Connectivity
17 September 2026

Windows security update causes log-in failures on domain-joined PCs

A recent Microsoft update has introduced new identity isolation policies that may block users from logging into their work computers. The issue occurs when the central server managing the network has not been updated to the latest functional standards.

What this means for your business

Businesses using Windows Server to manage office PCs may find staff unable to access their devices or network resources. If you encounter 'trust relationship' errors, your server configuration or operating system version likely needs adjustment to meet new security requirements.

The nature of the authentication error

Recent updates to Windows have introduced a feature called Machine Identity Isolation. This is designed to improve security by strictly verifying the identity of a computer before it is allowed to access a business network. However, this change has caused some Windows PCs to lose their connection to the 'domain'—the central system that manages user accounts and security settings.

When this happens, staff may see an error message stating that the trust relationship between the workstation and the primary domain has failed. This prevents the user from logging in with their standard business credentials.

Why this is happening now

For many years, older versions of Windows Server have been able to manage newer Windows 10 and 11 computers without difficulty. This update changes that requirement. The new security policy expects the domain controller—the server in charge of the network—to be running at a 'functional level' equivalent to Windows Server 2025.

Many UK small businesses currently operate on Windows Server 2016, 2019, or 2022. Because these older versions do not support the specific identity isolation protocols Microsoft is now enforcing, the server and the PC cannot verify each other's identity, resulting in a lockout.

Action for small business owners

If your business relies on an on-site server or a private cloud server to manage your office computers, your IT setup may be affected. This does not generally affect businesses that are 'cloud-only' and use Microsoft Entra ID (formerly Azure AD) without a local server.

To resolve the issue, the Machine Identity Isolation policy may need to be disabled via Group Policy—a tool used to manage settings across all office computers—until your server infrastructure can be updated. We are currently monitoring official Microsoft documentation for a permanent patch that allows older servers to remain compatible with this new security layer. If you are planning a server refresh, this change makes the transition to Windows Server 2025 more urgent for maintaining network stability.

Not sure how exposed you are?

Twenty minutes on a call is usually enough to tell you.