Ticker

6/recent/ticker-posts

Ad Code

Responsive Advertisement

Microsoft Confirms September Windows 11 Updates Break Always On VPN Connections

Microsoft has confirmed that the security updates for Windows 11 which are scheduled for September 2026 may cause Always On VPN connections to fail, leaving the affected devices unable to access corporate networks.

The company mentioned the issue in a Windows release health service alert aimed at IT administrators and has put out a temporary workaround while a permanent solution is being developed.

Microsoft states that when the September update has been installed, affected systems experience problems when attempting to connect to an organisation's enterprise network via Always On VPN.

The connection might remain in a "Connecting" state or may cause repeated retry attempts which are unsuccessful. The error message "The specified port is already in use" may also occur on later attempts.

Affected Windows 11 Versions and Updates

Microsoft lists three Windows 11 releases as affected, each tied to a specific September cumulative update:

  • Windows 11, version 26H1, after installing KB5124012
  • Windows 11, version 25H2, after installing KB5124008
  • Windows 11, version 24H2, after installing KB5124008

The programme relies on a single configuration option; according to Microsoft, the problem occurs when the VPN is configured to attempt another connection method if the first one fails, for example when automatic protocol selection is used with IKEv2 and SSTP.

Always On VPN is the remote access solution that Microsoft is presenting as a replacement for DirectAccess; it is compatible with domain-joined, non-domain-joined, and Microsoft Entra ID joined devices and automatically sets up a tunnel to the corporate network each time a device goes online. This alert does not apply to devices that are not using an Always On VPN profile.

How Administrators Can Work Around the Always On VPN Issue

At the moment, there is no permanent solution available, so Microsoft advises that affected profiles be moved away from automatic protocol selection until one is released.

  1. Open the Always On VPN profile configuration that is used by the affected Windows 11 devices.
  2. Set the tunneling option to use a single protocol instead of having it automatically select the protocol.
  3. Choose between SSTP alone and IKEv2 alone depending on the organization's environment, security needs, and deployment requirements.
  4. Install the updated profile and make sure that the devices leave the 'Connecting' state and set up the tunnel.

The result is greater flexibility; when automatic selection is disabled, the device can't switch to the second protocol if the first one fails on a particular network, which is why Microsoft lets each organization decide which protocol to use rather than recommending a specific one.

The VPN issue is now part of an increasing number of problems associated with the September 2026 cumulative updates. Microsoft has already issued emergency updates to correct failures of Remote Desktop Services, problems with Hyper-V, and issues with USB audio.

The company has also provided a workaround for a bug that prevents some Windows 11 users from logging in with valid domain credentials, and is currently investigating a different issue that can cause the File History backup feature to stop working.

Microsoft has not stated when a permanent fix for the Always On VPN problem will be released or whether it will come in an out-of-band update or in a regular monthly update.

Thank you for being a Ghacks reader. The post Microsoft Confirms September Windows 11 Updates Break Always On VPN Connections appeared first on gHacks.

Enregistrer un commentaire

0 Commentaires