Windows 11 KB5124008 breaks domain trust: what to do when the PCs of your Mexico operation can no longer log in to the network
September’s Patch Tuesday came with a nasty surprise. The Windows 11 cumulative update KB5124008 knocks some machines out of the domain: the user types a valid password and gets ‘The trust relationship between this workstation and the primary domain failed’. BleepingComputer reported it on September 16, 2026.
If your Mexico office runs on an Active Directory domain (the Windows directory that decides who can log in to what) and gets its patches from headquarters through WSUS or Intune, this one is yours. Here is how to spot it, fix it without losing profiles, and stop patching blind.
What happened and who it hits
Every domain-joined PC has its own machine password, separate from the user’s. When that relationship breaks, the domain controller stops recognizing the machine and nobody can log in with a domain account, even with the right password.
Your staff in Mexico will see the message in Spanish: ‘La relación de confianza entre esta estación de trabajo y el dominio principal ha fallado’. If someone in Monterrey sends you that screenshot, this is it. Machines that only use local accounts or Microsoft 365 with no on-premise domain are not part of this story.
How to find the affected machines
The first alert is usually a person: the receptionist at the Querétaro plant turns on her PC on Wednesday and cannot get in. Before it spreads to accounting, go by the list.
| Where to look | What to look for |
|---|---|
| WSUS or Intune | Machines that already installed KB5124008 |
| On the PC, with a local account | Test-ComputerSecureChannel in PowerShell; False means it is broken |
| Event Viewer | NETLOGON errors at logon |
In our experience not every patched machine fails. Check them one by one before a user finds out on Monday morning, Mexico time, while your team is still asleep.
How to rejoin them without losing profiles
What not to do: unjoin the machine and join it again ‘to make it stick’. It works, but it is the fastest route to a temporary profile and a user swearing everything got deleted.
What to do:
- Log in with the machine’s local administrator account.
- Open PowerShell as administrator and run
Test-ComputerSecureChannel -Repair -Credential (Get-Credential)with domain admin credentials. - If that fails, try
Reset-ComputerMachinePassword -Server DC-NAME -Credential (Get-Credential). - Reboot and log in with the domain account. The profile is still there.
If none of that works, then yes: workgroup, reboot, join again. The profile is tied to the user, not the machine, and usually survives, but back up that user’s folder first. Nobody ever regretted an extra backup.
Pause or stagger the rollout: deployment rings
If you have not approved KB5124008 for everyone yet, do not. In WSUS, remove the approval; in Intune, pause quality updates on the broad ring. Then build what should have existed already: rings.
| Ring | Who | When |
|---|---|---|
| Pilot | A handful of PCs owned by people who speak up, IT included | Patch day |
| Middle | One full department | A few days later, if the pilot is clean |
| Everyone | The rest of the operation | One or two weeks later |
Patching is mandatory; patching the whole operation on the same day is not. Uninstalling the update on machines that have not failed yet is the last card: it leaves them without the month’s security fixes. And mind the time zone: a patch approved from Madrid or Chicago lands in Mexico at a different hour, so your pilot ring should include Mexican machines.
What to watch for in Microsoft’s fix
Three places: the KB page on Microsoft support, the Windows release health dashboard and the Intune admin center. Expect it as a KIR (Known Issue Rollback, a switch that disables the failed change without removing the update) or as an out-of-band update.
This incident exposes the gap in remote-only setups: someone has to sit at a desk in Guadalajara with a local account, and it cannot be done over Teams. Read what remote IT support in Mexico covers and what it does not.
And in your Mexico operation?
If users cannot log in today, the urgent part is rescuing those machines without losing profiles. The important part is making sure the next Patch Tuesday does not surprise you.
At ProcessBi this is part of the support plan: controlled patching in rings, servers and Active Directory, and remote or on-site response anywhere in Mexico, with a written SLA and invoicing in MXN or USD.
Tell us about your case — we reply the same business day.
Your path
Running IT in Mexico from abroad
21 of 32- Smart hands ✓ Read You are here 2 min
- Remote support ✓ Read You are here 3 min
- Nearshoring checklist ✓ Read You are here 2 min
- Retail rollouts ✓ Read You are here 2 min
- Fake IT support ✓ Read You are here 3 min
- Backups that restore ✓ Read You are here 3 min
- Secure M365 ✓ Read You are here 3 min
- Windows 10 deadline ✓ Read You are here 4 min
- Audit app access ✓ Read You are here 3 min
- CEO fraud ✓ Read You are here 4 min
- Office 2016 cutoff ✓ Read You are here 3 min
- Patch today ✓ Read You are here 4 min
- Patch VMware ✓ Read You are here 4 min
- Office 2021 EOL ✓ Read You are here 3 min
- Starlink for sites ✓ Read You are here 3 min
- Cardless access ✓ Read You are here 4 min
- Control AI on PCs ✓ Read You are here 4 min
- ScreenConnect flaw ✓ Read You are here 4 min
- Server 2022 EOL ✓ Read You are here 3 min
- Exposed cameras ✓ Read You are here 3 min
- Domain trust fix ✓ Read You are here 4 min
- Patch Cisco ISE ✓ Read You are here 3 min
- Protect the plant ✓ Read You are here 3 min
- Move to 25H2 ✓ Read You are here 4 min
- Outages and UPS ✓ Read You are here 3 min
- IT maintenance ✓ Read You are here 4 min
- Third-party scripts ✓ Read You are here 3 min
- License audit ✓ Read You are here 4 min
- Bajío fiber corridor ✓ Read You are here 3 min
- Check Point flaw ✓ Read You are here 4 min
- Cashless payments ✓ Read You are here 3 min
- AI that hacks alone ✓ Read You are here 3 min
- Field services →