Updated 07:07
Windows 11 26H2 is out, and its worst known issue comes from a domain setting it starts to honor
Windows 11 26H2 resets the support clock, removes default trust for cross-signed drivers, and starts honoring Machine Identity Isolation settings that only work against Windows Server 2025 domain controllers.
Microsoft made Windows 11, version 26H2 generally available on September 29, 2026. For most managed fleets it is less an upgrade than a switch: the features are already on disk, and the release turns them on. The release also arrives with three known issues on Microsoft's release health page, and the most consequential one is caused by a setting the update starts to respect, not by a bug in new code.
A feature update that is mostly a switch
Microsoft's IT pro guide says 26H2 "is delivered as an enablement package for eligible devices running Windows 11, versions 25H2 or 24H2," and explains the mechanism: "New features and capabilities have been delivered to supported devices through monthly cumulative updates, with some functionality remaining dormant until activated by the version 26H2 enablement package." The package "Installs similarly to a monthly quality update" and "Requires a small download."
The release health page says the rollout "is phased and will expand over the next few months," starting with devices whose users turned on "Get the latest updates as soon as they're available."
Installing 26H2 resets the support lifecycle: 24 months for Home and Pro, 36 months for Enterprise and Education. Monthly release notes for the version begin with "the first monthly security update for version 26H2, slated for October 13, 2026."
What changes on the security side
The guide's security list bundles features that rolled out to 24H2 and 25H2 over the past year:
- Administrator protection, which "provides just-in-time administrative privileges and profile separation," enabled through Intune or Group Policy.
- Built-in Sysmon, which "is off by default."
- Smart App Control can now be turned on or off "without requiring a clean installation of Windows."
- Post-quantum cryptography: "API support for NIST-standardized ML-KEM and ML-DSA algorithms," through CNG and .NET.
- Driver trust: the kernel changes "remove default trust for cross-signed drivers while maintaining support for WHCP and designated trusted legacy drivers."
The driver change is the one to test on older peripherals. The guide does not say which drivers count as "designated trusted legacy drivers."
The known issue that comes from a setting
Domain-joined devices with Credential Guard protected machine accounts can lose their secure channel to on-premises Active Directory, and users see the familiar trust relationship failure. Microsoft's explanation is precise:
While the update does not directly enable Machine Identity Isolation enforcement, it does cause Windows to begin honoring any existing or policy-provisioned settings that enabled Machine Identity Isolation enforcement.
Microsoft, Windows release health
The feature "is only supported for environments connected to domain controllers running at a Windows Server 2025 Domain Functional Level (DFL) and above." Cached offline sign-in "might continue to work," and domain controllers are not affected. The workaround is to disable the feature by whatever method enabled it. For registry-set values, Microsoft gives these paths and steps:
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\MachineIdentityIsolation
HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard\MachineIdentityIsolation
MachineIdentityIsolation = 2 (change to 0, then restart)
Test-ComputerSecureChannel -Repair -Credential (Get-Credential)
Microsoft says it plans a fix that works by "temporarily preventing Machine Identity Isolation enforcement." The page lists 24H2 and 25H2 among the affected platforms too, so a fleet that searches for that value of 2 before it deploys can avoid the lockout.
Two more, both opened before release day
The other two issues are also marked "Mitigated" as of September 29. Some USB Audio Class 1.0 devices show "This device cannot start (Code 10)" or produce no sound; this one was opened September 11, and its affected list reaches back to Windows 10 and Windows Server 2012. Black screens after sign-in, mostly on Azure Virtual Desktop hosts using FSLogix, were opened September 24 and are mitigated with a Known Issue Rollback Group Policy (KB5124010 for 24H2, 25H2 and 26H2). The opening dates come before general availability, which fits a release built on the same servicing branch as the versions it replaces.
Primary sources: Microsoft, An IT pro's guide to Windows 11, version 26H2; Microsoft Learn, Windows 11, version 26H2 known issues and notifications, read 2026-10-02.