I would like to sincerely know why Microsoft consistently demonstrates poor QA around Remote Credential Guard with their updates. RCG should be used by every organization and as such should also have better assurance that when an update comes out, that it's not going to break core functionality that this security enhancement provides. I've personally been dealing with these issues for 2 years like a game of whack-a-mole...
KB5072033 break remote credential guard to Windows server 2025
We are experiencing a reproducible issue with Remote Credential Guard (RCG) when connecting from Windows 11 24H2 clients to a Windows Server 2025 RDP host. Remote Credential Guard works correctly before installing update KB5072033 on the client. Immediately after installing this update, RCG stops functioning.
The issue is fully reproducible and affects only Windows 11 24H2 clients where KB5072033 is installed. The Windows Server 2025 host has also received the December cumulative update, but this does not change the behavior: RCG still fails when the client has KB5072033 installed.
Windows for business | Windows Client for IT Pros | Directory services | User logon and profiles
23 answers
Sort by: Newest
-
Pierre DESTRÉE 70 Reputation points
2025-12-12T10:13:49.3233333+00:00 I would also like to highlight an additional point that further confirms this is a regression introduced by KB5072033.
Before installing KB5072033 on Windows 11 24H2 clients:
- RCG worked correctly when connecting to Windows Server 2025
RCG did not work when connecting to Windows Server 2022
After installing KB5072033:
RCG no longer works with Windows Server 2025
RCG now works correctly with Windows Server 2022
This is the exact opposite behavior compared to before the update. No configuration changes were made on either the clients or the servers. The only change was the installation of KB5072033 on the Windows 11 24H2 clients.
This inversion strongly suggests that the update modifies the internal behavior of the RDP/CredSSP/Kerberos stack in a way that breaks compatibility with Windows Server 2025, even though the server is fully updated (including the December cumulative update).
-
Quinnie Quoc 11,840 Reputation points Independent Advisor
2025-12-11T14:44:48.1566667+00:00 Hello Pierre DESTRÉE,
Thank you for sharing the detailed findings regarding Remote Credential Guard (RCG) behavior between Windows 11 24H2 clients and a Windows Server 2025 RDP host. Based on your description, the issue appears directly linked to the installation of update KB5072033, as RCG functions normally prior to applying this update and fails consistently afterward. At this time, the behavior you are seeing aligns with a known regression introduced in the update, and Microsoft is actively investigating the impact on RDP authentication and RCG negotiation. While the Server 2025 cumulative update does not resolve the issue, the current recommended workaround is to temporarily uninstall KB5072033 on affected clients or pause updates until a corrective patch is released.
You may also monitor the Windows Release Health dashboard for official status updates, as fixes for authentication‑related regressions are typically delivered through subsequent cumulative updates.
I hope this information helps you stabilize your environment while Microsoft works on a permanent resolution. If this guidance addresses your question, please consider clicking “Accept the Answer” so that others in the community can benefit from the findings as well.
Thank you so much!!
Best regards,
QQ.