KB5072033 break remote credential guard to Windows server 2025

Pierre DESTRÉE 70 Reputation points
2025-12-11T13:50:14.7433333+00:00

We are experiencing a reproducible issue with Remote Credential Guard (RCG) when connecting from Windows 11 24H2 clients to a Windows Server 2025 RDP host. Remote Credential Guard works correctly before installing update KB5072033 on the client. Immediately after installing this update, RCG stops functioning.

The issue is fully reproducible and affects only Windows 11 24H2 clients where KB5072033 is installed. The Windows Server 2025 host has also received the December cumulative update, but this does not change the behavior: RCG still fails when the client has KB5072033 installed.

Windows for business | Windows Client for IT Pros | Directory services | User logon and profiles

23 answers

Sort by: Most helpful
  1. jaltmann 61 Reputation points
    2026-05-29T15:39:30.9966667+00:00

    Sorry everyone, MS removed my post with the registry fix for the regression that will fix the issue as of 5/29/2026 until they fully patch. I'm not sure exactly what code of conduct was violated as there's no mention of confidentiality of unpublished KIRs from support, but I'm guessing it was removed by automation due to it possibly being a direct registry key command line.

    If it's an issue of it being unpublished, you'll have to ask support for "Windows Server 2025 KB5087539 260421_03022 Feature Preview".

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments

  2. jaltmann 61 Reputation points
    2026-05-28T13:42:57.8+00:00

    I've finally gotten somewhere after pressing Microsoft. Microsoft support has provided me with a KIR (Known Issue Rollback) which is an MSI installable on Windows Server 2025 specific to the latest cumulative update (KB5087539) from May. This KIR essentially creates a local item in gpedit.msc that you can enable that rolls back the regression for RCG. We are running the latest patch for Windows 11 24H2 and with the KIR applied to the server, we are able to see Kerberos tickets and double-hop network resources.

    More info on KIR's: https://learn.microsoft.com/en-us/troubleshoot/windows-client/group-policy/use-group-policy-to-deploy-known-issue-rollback?wt.mc_id=knowledgesearch_inproduct_windows-update-ai-assistant-(wuai)

    They're supposed to be available on https://learn.microsoft.com/en-us/windows/release-health/status-windows-server-2025 and the specific KIR to look for is "Windows Server 2025 KB5087539 260421_03022 Feature Preview"

    Was this answer helpful?

    1 person found this answer helpful.

  3. Chris-7747 0 Reputation points
    2025-12-29T14:39:18.2933333+00:00

    Can anyone official from Microsoft confirm this? We also seeing this issue @Customers with Windows 11 24H2 and 25H2 after the KB5072033 update.

    Was this answer helpful?

    0 comments No comments

  4. Pierre DESTRÉE 70 Reputation points
    2025-12-12T10:13:49.3233333+00:00

    I would also like to highlight an additional point that further confirms this is a regression introduced by KB5072033.

    Before installing KB5072033 on Windows 11 24H2 clients:

    • RCG worked correctly when connecting to Windows Server 2025

    RCG did not work when connecting to Windows Server 2022

    After installing KB5072033:

    RCG no longer works with Windows Server 2025

    RCG now works correctly with Windows Server 2022

    This is the exact opposite behavior compared to before the update. No configuration changes were made on either the clients or the servers. The only change was the installation of KB5072033 on the Windows 11 24H2 clients.

    This inversion strongly suggests that the update modifies the internal behavior of the RDP/CredSSP/Kerberos stack in a way that breaks compatibility with Windows Server 2025, even though the server is fully updated (including the December cumulative update).

    Was this answer helpful?

    0 comments No comments

  5. Quinnie Quoc 11,840 Reputation points Independent Advisor
    2025-12-11T14:44:48.1566667+00:00

    Hello Pierre DESTRÉE,

    Thank you for sharing the detailed findings regarding Remote Credential Guard (RCG) behavior between Windows 11 24H2 clients and a Windows Server 2025 RDP host. Based on your description, the issue appears directly linked to the installation of update KB5072033, as RCG functions normally prior to applying this update and fails consistently afterward. At this time, the behavior you are seeing aligns with a known regression introduced in the update, and Microsoft is actively investigating the impact on RDP authentication and RCG negotiation. While the Server 2025 cumulative update does not resolve the issue, the current recommended workaround is to temporarily uninstall KB5072033 on affected clients or pause updates until a corrective patch is released.

    You may also monitor the Windows Release Health dashboard for official status updates, as fixes for authentication‑related regressions are typically delivered through subsequent cumulative updates.

    I hope this information helps you stabilize your environment while Microsoft works on a permanent resolution. If this guidance addresses your question, please consider clicking “Accept the Answer” so that others in the community can benefit from the findings as well.

    Thank you so much!!

    Best regards,

    QQ.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.