← Back to blog IT support

Windows 11 KB5124008 breaks domain trust: what to do when the PCs of your Mexico operation can no longer log in to the network

4 min read

September’s Patch Tuesday came with a nasty surprise. The Windows 11 cumulative update KB5124008 knocks some machines out of the domain: the user types a valid password and gets ‘The trust relationship between this workstation and the primary domain failed’. BleepingComputer reported it on September 16, 2026.

If your Mexico office runs on an Active Directory domain (the Windows directory that decides who can log in to what) and gets its patches from headquarters through WSUS or Intune, this one is yours. Here is how to spot it, fix it without losing profiles, and stop patching blind.

What happened and who it hits

Second stumble this month First Remote Desktop on Windows Server, now domain trust on Windows 11. Same recipe: patch with a safety net.

Every domain-joined PC has its own machine password, separate from the user’s. When that relationship breaks, the domain controller stops recognizing the machine and nobody can log in with a domain account, even with the right password.

Your staff in Mexico will see the message in Spanish: ‘La relación de confianza entre esta estación de trabajo y el dominio principal ha fallado’. If someone in Monterrey sends you that screenshot, this is it. Machines that only use local accounts or Microsoft 365 with no on-premise domain are not part of this story.

How to find the affected machines

The first alert is usually a person: the receptionist at the Querétaro plant turns on her PC on Wednesday and cannot get in. Before it spreads to accounting, go by the list.

Where to lookWhat to look for
WSUS or IntuneMachines that already installed KB5124008
On the PC, with a local accountTest-ComputerSecureChannel in PowerShell; False means it is broken
Event ViewerNETLOGON errors at logon

In our experience not every patched machine fails. Check them one by one before a user finds out on Monday morning, Mexico time, while your team is still asleep.

How to rejoin them without losing profiles

Repair, do not rebuild Repairing the secure channel keeps the desktop, the files and the Outlook profile already set up.

What not to do: unjoin the machine and join it again ‘to make it stick’. It works, but it is the fastest route to a temporary profile and a user swearing everything got deleted.

What to do:

  1. Log in with the machine’s local administrator account.
  2. Open PowerShell as administrator and run Test-ComputerSecureChannel -Repair -Credential (Get-Credential) with domain admin credentials.
  3. If that fails, try Reset-ComputerMachinePassword -Server DC-NAME -Credential (Get-Credential).
  4. Reboot and log in with the domain account. The profile is still there.

If none of that works, then yes: workgroup, reboot, join again. The profile is tied to the user, not the machine, and usually survives, but back up that user’s folder first. Nobody ever regretted an extra backup.

Pause or stagger the rollout: deployment rings

Controlled patching across borders A handful of machines first, then one department, then everyone. Include Mexican PCs in the pilot ring.

If you have not approved KB5124008 for everyone yet, do not. In WSUS, remove the approval; in Intune, pause quality updates on the broad ring. Then build what should have existed already: rings.

RingWhoWhen
PilotA handful of PCs owned by people who speak up, IT includedPatch day
MiddleOne full departmentA few days later, if the pilot is clean
EveryoneThe rest of the operationOne or two weeks later

Patching is mandatory; patching the whole operation on the same day is not. Uninstalling the update on machines that have not failed yet is the last card: it leaves them without the month’s security fixes. And mind the time zone: a patch approved from Madrid or Chicago lands in Mexico at a different hour, so your pilot ring should include Mexican machines.

What to watch for in Microsoft’s fix

Three places: the KB page on Microsoft support, the Windows release health dashboard and the Intune admin center. Expect it as a KIR (Known Issue Rollback, a switch that disables the failed change without removing the update) or as an out-of-band update.

This incident exposes the gap in remote-only setups: someone has to sit at a desk in Guadalajara with a local account, and it cannot be done over Teams. Read what remote IT support in Mexico covers and what it does not.

ProcessBi technician at work
PCs locked out of the domain today? Tell us and we fix it remotely or on site Foto: Pexels

And in your Mexico operation?

If users cannot log in today, the urgent part is rescuing those machines without losing profiles. The important part is making sure the next Patch Tuesday does not surprise you.

At ProcessBi this is part of the support plan: controlled patching in rings, servers and Active Directory, and remote or on-site response anywhere in Mexico, with a written SLA and invoicing in MXN or USD.

Tell us about your case — we reply the same business day.

Your path

Running IT in Mexico from abroad

21 of 32
  1. Smart hands ✓ Read You are here 2 min
  2. Remote support ✓ Read You are here 3 min
  3. Nearshoring checklist ✓ Read You are here 2 min
  4. Retail rollouts ✓ Read You are here 2 min
  5. Fake IT support ✓ Read You are here 3 min
  6. Backups that restore ✓ Read You are here 3 min
  7. Secure M365 ✓ Read You are here 3 min
  8. Windows 10 deadline ✓ Read You are here 4 min
  9. Audit app access ✓ Read You are here 3 min
  10. CEO fraud ✓ Read You are here 4 min
  11. Office 2016 cutoff ✓ Read You are here 3 min
  12. Patch today ✓ Read You are here 4 min
  13. Patch VMware ✓ Read You are here 4 min
  14. Office 2021 EOL ✓ Read You are here 3 min
  15. Starlink for sites ✓ Read You are here 3 min
  16. Cardless access ✓ Read You are here 4 min
  17. Control AI on PCs ✓ Read You are here 4 min
  18. ScreenConnect flaw ✓ Read You are here 4 min
  19. Server 2022 EOL ✓ Read You are here 3 min
  20. Exposed cameras ✓ Read You are here 3 min
  21. Domain trust fix ✓ Read You are here 4 min
  22. Patch Cisco ISE ✓ Read You are here 3 min
  23. Protect the plant ✓ Read You are here 3 min
  24. Move to 25H2 ✓ Read You are here 4 min
  25. Outages and UPS ✓ Read You are here 3 min
  26. IT maintenance ✓ Read You are here 4 min
  27. Third-party scripts ✓ Read You are here 3 min
  28. License audit ✓ Read You are here 4 min
  29. Bajío fiber corridor ✓ Read You are here 3 min
  30. Check Point flaw ✓ Read You are here 4 min
  31. Cashless payments ✓ Read You are here 3 min
  32. AI that hacks alone ✓ Read You are here 3 min
  33. Field services
Next Cisco ISE max-severity zero-day under attack: what to check today if your Mexico sites use Cisco for network access control