Updates

Windows 11 Update KB5124008 Breaks Always On VPN — What You Need to Know

4 min read Editorial
  • Status: Confirmed — bug discovered; IT admins advised to halt deployments
  • Affected: Windows 11 (September Patch Tuesday update)
  • KB article: KB5124008
  • Issue: Always On VPN connections fail due to handshake authentication interference

Microsoft’s September Patch Tuesday update for Windows 11 has arrived with an unwelcome surprise. The newly released patch, KB5124008, is breaking Always On VPN connections for some users, and the problem has been flagged closely enough that IT administrators are being advised to hold off on rolling it out to their fleets.

Always On VPN is one of Windows 11’s more enterprise-focused features, maintaining a persistent, always-connected tunnel between a device and its organization’s network. When it works, you barely notice it. When it breaks — as it now does under this update — remote workers can suddenly find themselves locked out of company resources, shared drives, and internal applications.

The bug at a glance

According to the report, the core problem lies in how the update handles handshake authentication. A handshake is the initial exchange of messages that two devices perform to establish a secure connection — in VPN terms, it’s the moment your PC proves its identity and negotiates the encryption parameters with the VPN server. If that handshake fails, the tunnel never fully forms, and the connection drops.

Advertisement

The update appears to interfere with that process, which is why Always On VPN connections are failing after installation. Microsoft has not yet published detailed technical notes on the exact mechanism, so the specifics remain somewhat murky — but the symptom is clear and consistent enough to warrant a deployment pause.

A close-up of a Windows 11 Settings window showing Windows Update and an installed update labeled KB5124008, soft blue a
The problematic KB5124008 update listed in Windows Update history.

Who is affected

The affected update is KB5124008, part of the September Patch Tuesday rollout for Windows 11. Patch Tuesday is Microsoft’s monthly cadence of security and quality updates, typically released on the second Tuesday of the month, and this cycle’s package is the one carrying the bug.

Because Always On VPN is primarily an enterprise and power-user feature, the impact is concentrated among organizations that deploy persistent VPN tunnels rather than casual home users. If your organization relies on Always On VPN for remote access, this is the update you’ll want to scrutinize before pushing it out.

Why admins are halting deployments

The decision to pause deployment is a cautious but sensible one. Pushing an update fleet-wide without vetting it first is a common source of widespread outages, and with Always On VPN in the mix, a bad rollout could take a large portion of a remote workforce offline at once.

From an IT-pro standpoint, the standard practice is to test updates on a small pilot group before a full rollout. In this case, the bug is significant enough that the recommendation is to hold the update entirely until Microsoft clarifies the issue and, ideally, ships a fix.

What this means for Always On VPN users

For the average Windows 11 user who doesn’t use Always On VPN, this bug has essentially no impact on your daily experience. You’ll still get your normal updates, and there’s nothing you need to do.

If you do rely on Always On VPN for work, though, the practical takeaway is simple: don’t install KB5124008 until Microsoft confirms it’s safe. If you’ve already installed it and your VPN is broken, hold tight for a fix rather than trying risky workarounds that could make things worse.

How to check and what to do

To see whether you’ve received the problematic update, open Settings > Windows Update > Update history and look for KB5124008 in the list. If it’s there and your Always On VPN is still working fine, you may choose to stay put — but if the connection is failing, the safest move is to wait.

For IT administrators managing a fleet, the recommendation is to pause the deployment of KB5124008 through your update management channel — such as Windows Update for Business, Intune, or WSUS — until Microsoft provides further guidance. Keep an eye on official channels for an updated package or an explanatory support document.

What to expect next

When Microsoft discovers a bug this disruptive in a Patch Tuesday release, the typical pattern is to acknowledge the issue, work on a fix, and ship it in a later cumulative update — or, in some cases, pull the update from distribution entirely until it can be corrected.

Until then, the burden falls on IT teams to manage the risk manually. The good news is that holding back a single update is a well-trodden path, and organizations with proper testing procedures are already equipped to handle it.

Source: Neowin

Over to you: If your organization relies on Always On VPN, would you hold off on KB5124008, or risk the update to stay current?

Advertisement
Share:
Editorial
Written by
Editorial

Windows & Microsoft news editor at 9to5Windows. Covering everything from Windows 11 builds to enterprise updates.

Advertisement