Microsoft: April Windows Server updates cause NTLM auth failures

Microsoft: April Windows Server updates cause NTLM auth failures

May 1, 2024 at 11:18AM

Microsoft has acknowledged NTLM authentication failures and high loads after installing recent Windows Server security updates. The issue affects domain controllers with high NTLM traffic and few primary DCs. Affected versions and updates include Windows Server 2022 (KB5036909) and others. While Microsoft works on a fix, organizations can uninstall the updates as a temporary solution.

Based on the meeting notes, here are the key takeaways:

– Microsoft has acknowledged reports of NTLM authentication failures and high load on Windows domain controllers after installing the latest Windows Server security updates.
– This issue particularly impacts organizations with a significant amount of NTLM traffic and few primary domain controllers.
– The affected Windows versions and specific problematic security updates have been identified, including workarounds for uninstalling the updates to temporarily address the NTLM authentication issues.
– Microsoft is currently working on a fix for this known issue but has not provided information on the root cause. Small and large enterprise customers can seek assistance through the “Support for Business” portal.
– It’s important to note that removing the problematic security updates will also remove all security fixes released in the same month.
– Microsoft has previously released emergency updates to address issues such as memory leaks and domain controller crashes caused by previous security updates.
– Additionally, the April 2024 Windows security updates have been reported to cause VPN connection issues on Windows 11, Windows 10, and Windows Server systems.

Please let me know if you need any further information or clarification.

Full Article