Windows 11 administrators are facing a frustrating situation: Microsoft’s emergency patch was meant to repair broken authentication, but it didn’t. According to reports, the KB5129195 update fails to fix secure domain logins that were broken by the earlier KB5124008 update.
Before diving into the details, here’s the current status of the issue:
- Status: Confirmed. Administrators have reported that the emergency fix does not resolve the problem.
- Affected systems: Windows 11 devices that received the KB5124008 update.
- KB codes involved: KB5124008 introduced the broken secure domain logins; KB5129195 was issued as an emergency update to fix them but failed to do so.
What broke and what was supposed to fix it
The trouble began with Windows 11’s KB5124008 update, which left secure domain logins in a broken state. For organizations running domain-joined machines, that means employees can no longer authenticate against their Active Directory the way they normally would when signing in.
Microsoft responded by releasing KB5129195, an emergency update aimed directly at restoring that authentication. The intent was to roll out a targeted fix without forcing a full rollback of the problematic update.
According to Neowin, administrators have now confirmed that this emergency patch did not work. The secure domain logins remain broken even after installing KB5129195.

Why secure domain logins breaking matters for your org
When domain authentication is working, a signed-in user’s credentials are validated against a central domain controller. That single sign-on keeps everything from file shares to enterprise apps accessible with one set of credentials.
When it breaks, the impact is immediate and widespread. Users may be locked out, redirected to local accounts, or unable to reach network resources they depend on for their daily work. For IT teams, a broken login flow is one of the highest-priority incidents because it affects productivity across the whole organization.
Emergency updates like KB5129195 are typically deployed precisely because the underlying issue is severe enough to warrant an out-of-band response. When such a fix fails, admins are left weighing their options.
What this means for you
If you’re on a personal PC connected to a home or small business network without a domain, this issue likely doesn’t touch your daily experience. The problem specifically affects domain-joined machines in an organizational setup.
If you or your organization run Windows 11 domain-joined devices, though, you should be aware that the emergency fix did not resolve the login breakage. Keep an eye out for further guidance from Microsoft before making any changes that could affect your fleet.
What to do about it
Until Microsoft ships a working correction, here are a few practical steps for admins managing affected machines:
- Hold on wider deployment: If you haven’t yet rolled out KB5124008 to your whole fleet, consider delaying it until a working fix exists.
- Monitor for follow-up patches: Microsoft typically issues a corrected update after a failed emergency fix. Watch official channels for the next release.
- Check your current build: Confirm which machines have received KB5124008 and whether KB5129195 was applied, so you can prioritize remediation.
- Have a fallback ready: Ensure you have a recovery path for users who are locked out, such as local admin access or documented workarounds.
As with any authentication issue, testing any remediation in a lab environment before pushing it to production is the safest approach.

Where things stand
The bottom line is that the emergency update did not do its job. Secure domain logins remain broken on Windows 11 machines that received KB5124008, and the KB5129195 patch failed to restore them.
For now, the onus is on Microsoft to identify why the fix missed and ship a corrected version. Administrators should hold off on assuming the problem is resolved and continue monitoring official support channels for an updated fix.
Source: Neowin
Over to you: If your organization is affected, would you roll back KB5124008 or wait for Microsoft to ship a corrected KB5129195?



