Windows 11 KB5124008 turned one September update into several different problems
Microsoft released KB5124008 on September 8 for Windows 11 versions 24H2 and 25H2, taking them to builds 26100.9445 and 26200.9445. Its subsequent issue records cover remote sessions, Linux virtual-machine folder sharing, certain USB audio devices, domain sign-in, and File History backups. Those are separate faults with different affected configurations and different fixes; treating them as one problem obscures what an administrator needs to deploy.
In some organizations, Remote Desktop Services became unstable: connections could fail after several minutes, sign-ins could fail, and servers could hang during Remote Desktop configuration. Related management tools and File Explorer could also stop responding. Microsoft says Windows 365 and Azure Virtual Desktop were unaffected by this September RDS incident. Its September 14 out-of-band update, KB5129195, resolved the documented RDS problem on the affected Windows 11 versions.
The Linux-related failure had a narrower mechanism. Applications using Host Compute Service-managed virtual machines and Plan9 host-folder sharing could start a Linux guest normally but fail to make Windows folders accessible inside it. Microsoft named Windows Subsystem for Linux and Claude Cowork among affected applications; standard Hyper-V virtual machines that do not use Plan9 sharing were outside that particular failure. KB5129195 resolved it. Administrators who had applied Microsoft’s temporary Group Policy mitigation were instructed to re-enable that policy, install the out-of-band update, and restart.
KB5129195 did not clear the entire September list. Microsoft says it fixed the reported 8-channel and 3D-mode symptoms on some USB Audio Class 1.0 devices, but other symptoms—including devices showing Code 10 or producing no sound—remained under investigation. Some users of multichannel devices reported that switching to two-channel audio restored sound; Microsoft presents that as a limited workaround, not a remedy for every affected device.
File History followed yet another schedule. After KB5124008, some backups stopped advancing even when the destination drive was connected; users could see an incorrect “Reconnect your drive” prompt or an unchanged “Last Backup” time. Microsoft says Windows 11 updates released on or after September 22, including the optional preview KB5124010, address the problem. Anyone relying on File History should confirm a new backup completes rather than take the presence of a connected drive as proof that files are protected.
KB5124008’s domain-trust issue calls for a configuration check
The domain sign-in issue is especially important because its trigger is specific. Microsoft says KB5124008 caused Windows to honor existing or policy-provisioned Machine Identity Isolation enforcement settings. That enforcement is supported only in environments whose domain controllers run at Windows Server 2025 Domain Functional Level or higher. On affected Credential Guard-protected machines outside that boundary, the secure channel to an on-premises Active Directory domain can fail, preventing interactive sign-in with valid domain credentials; cached credentials may still permit offline sign-in. Microsoft says domain-controller services and AD replication are unaffected.
The supported response is to determine whether Machine Identity Isolation enforcement was enabled and how it was managed. Microsoft instructs administrators in affected, unsupported configurations to disable it using the same route that enabled it—Intune, Group Policy, or the registry—then restart the device and repair the secure channel. Registry changes carry their own recovery risk, so they should not be substituted for an Intune or Group Policy change on a managed machine. Microsoft still described this issue as mitigated, with a future Windows update planned, after the September 14 emergency release.
The January-to-September record is uneven, but it is not a failure-rate study
September was not an isolated reason for Windows Latest’s comparison. In January, Windows 11 KB5074109 caused credential-prompt failures for some connections made through Windows App to Azure Virtual Desktop and Windows 365. Microsoft also documented applications hanging or erroring while opening or saving cloud-backed files, including certain Outlook configurations with PST files on OneDrive. These January cloud-desktop failures should not be confused with the separate September RDS incident, for which Microsoft explicitly excluded Azure Virtual Desktop and Windows 365.
Windows Latest’s month-by-month account also identifies a March Microsoft-account sign-in failure, installation and BitLocker troubles in later months, and June and July problems involving business PCs and drivers. Its useful warning is that an update appearing shortly before a crash does not automatically establish causation. For August’s reported game crashes, Microsoft concluded its Windows update was not the cause; its investigation connected the issue to components associated with RGB-equipped peripherals and took action against a specific driver. Counting those crashes as a confirmed Windows regression would make the comparison less accurate.
There is a plausible reason Windows 10’s record looks quieter: it receives security servicing without Windows 11’s continuing stream of feature changes. Windows Latest advances that explanation, but the records here do not isolate feature development as the cause of the difference. They also do not supply the number of affected PCs, a comparable crash rate, or a consistent way to count an incident that spans both versions of Windows. For a deployment decision, the documented symptom and affected configuration are more useful than a nine-month score.
Windows 10 KB5122878 complicates September’s clean comparison
Windows 10’s September 8 security update was KB5122878 for eligible version 22H2 devices and specified version 21H2 editions. Microsoft’s own KB page documents the same class of September Remote Desktop Services failure for Windows 10 and points to its September 14 out-of-band update, KB5129236, as a resolution. A business running Remote Desktop workloads therefore cannot treat remaining on Windows 10 as protection from that particular regression.
Microsoft’s Windows 10 KB page also lists a File History known issue, but its description names KB5124008—the Windows 11 update. The Windows 11 record names a September 22 fix; the Windows 10 page, as reviewed, does not give the same Windows 10-specific resolution. That identifier mismatch limits how precisely a reader can assign the File History fault or its fix to KB5122878. A Windows 10 user seeing stalled backups should verify the installed update and whether File History is actually completing backups, without assuming that Windows 11’s KB5124010 applies to their PC.
There is also a longer-term cost to choosing the quieter platform. Ordinary support for Windows 10 version 22H2 ended on October 14, 2025. Microsoft says eligible devices enrolled in its consumer Extended Security Updates program can receive protection through October 12, 2027. That date describes the consumer ESU route, not a universal support deadline for every enterprise or LTSC installation, and ESU is a security-update bridge rather than a return to Windows 10 feature development.
What this means for you
Judge the update against the job the PC performs. A Windows 11 developer dependent on shared folders in WSL, an administrator responsible for RDS hosts, and a user relying on File History faced different September risks and received fixes on different dates. A Windows 10 organization also needs to account for shared faults and its own servicing eligibility, rather than using the operating-system name as a stand-in for reliability.
- Check the installed Windows version and KB number before matching a symptom to a known issue; KB5124008 and KB5122878 have different follow-up updates.
- For the documented September RDS failure, Microsoft identifies KB5129195 or later for the affected Windows 11 versions and KB5129236 or later for the affected Windows 10 versions.
- For Plan9 host-folder failures on affected Windows 11 systems, install the September 14 fix or later; if an administrator used the temporary Group Policy mitigation, follow Microsoft’s instruction to re-enable it and restart.
- For Windows 11 File History failures, Microsoft identifies September 22’s KB5124010 or later; confirm the backup timestamp advances after updating.
- For domain trust failures, check Machine Identity Isolation enforcement and the domain functional-level requirement before changing policy; do not expect the September 14 out-of-band update alone to resolve that configuration issue.
Windows 10’s smaller set of reported 2026 disruptions gives cautious administrators a reason to value its predictability while they plan a move, provided their machines remain eligible for security updates. September shows the limit of the slogan: Windows 11 had several distinct confirmed regressions, but a major RDS fault crossed the version boundary. The sound operational choice is to keep security servicing in place and make rollout decisions against the workloads, configurations, and fixes Microsoft actually names.