Official KIR Group Policy for RDP/RDS issues after KB5122876 and KB5122882

Max Max 0 Reputation points
2026-09-12T21:23:41.29+00:00

Hello,

I am looking for official Microsoft confirmation regarding the Remote Desktop Services / RDP issue reported after the September 2026 updates for Windows Server 2019 and Windows Server 2022.

Affected updates:

  • Windows Server 2019 — KB5122876
  • Windows Server 2022 — KB5122882

I would prefer not to uninstall the security updates and am looking for an officially supported mitigation.

I have found references to the following Known Issue Rollback packages:

  • Windows Server 2022 KB5122882 260911_18471 Known Issue Rollback
  • Windows 10 1809 and Windows Server 2019 KB5122876 260911_18474 Known Issue Rollback

Could Microsoft please confirm:

  1. Are these the official KIR packages for the RDP/RDS issue associated with KB5122876 and KB5122882?
  2. Where can these packages be downloaded from an official Microsoft source?
  3. What is the exact Group Policy setting that must be configured to activate the rollback?
  4. Is a reboot required after applying the policy?
  5. Does the KIR keep all security fixes from KB5122876 / KB5122882 installed and only disable the problematic change?
  6. Are there any known limitations or side effects?
  7. Is there an estimated date for a permanent fix?

I would like to use only an officially supported Microsoft mitigation.

Thank you.

Windows for business | Windows Server | Devices and deployment | Install Windows updates, features, or roles
0 comments No comments

4 answers

Sort by: Most helpful
  1. Allan Solomon Mejia 8,175 Reputation points
    2026-09-12T21:52:06.43+00:00

    Hello @Max Max

    Be cautious about deploying those KIR packages based only on references to their package names.

    I can confirm from Microsoft's current release information that:

    • KB5122876 is the September 8, 2026 cumulative security update for Windows Server 2019, bringing it to OS build 17763.9245.
    • KB5122882 is the September 8, 2026 cumulative security update for Windows Server 2022, bringing it to OS build 20348.5622.

    However, I currently cannot find a public Microsoft KB/release-health entry that officially documents:

    KB5122882 260911_18471 Known Issue Rollback

    KB5122876 260911_18474 Known Issue Rollback

    as the supported mitigation for an RDP/RDS regression introduced by those September updates.

    That distinction matters because Microsoft normally publishes KIR Group Policy packages with a documented known issue, and the documentation identifies the affected Windows versions, the KIR download, and whether a restart is required.

    For enterprise-managed devices, a KIR policy is installed/configured through Group Policy, and the affected device generally needs to be restarted for the rollback to take effect. KIR reverses the specific non-security behavior change responsible for the regression rather than uninstalling the entire cumulative update. Therefore, the security fixes in the cumulative update remain installed.

    But that general KIR behavior doesn't establish that 260911_18471 or 260911_18474 are the correct policies for this particular RDS problem.

    Therefore, do not manually create registry values or Group Policy settings based on an unofficial KIR identifier, and don't download an ADMX/MSI package from a third-party source.

    Since you're specifically looking for a Microsoft-supported mitigation while retaining the September security updates, I would recommend waiting for one of the following:

    • Microsoft updates the KB/release-health documentation and publishes the applicable KIR package and deployment instructions, or
    • Microsoft Support provides the KIR package/instructions for your case and confirms that your RDS symptoms match the issue it addresses.

    If Microsoft confirms those two KIRs, the downloaded enterprise KIR policy package normally installs an administrative template under:

    Computer Configuration > Administrative Templates > KBxxxxxxx Issue xxx Rollback

    The exact policy name should come from the Microsoft-provided KIR package; you shouldn't guess it from the package identifier.

    Regarding your individual questions:

    1–3. Are these the official KIRs, where are they downloaded, and what policy should be enabled?

    I can't currently verify that from Microsoft's public documentation. I would wait for Microsoft to publish or provide the packages rather than use copies obtained elsewhere.

    1. Reboot required?

    For enterprise KIR Group Policy deployment, Microsoft generally requires you to apply the policy and restart the affected devices. Treat the issue-specific documentation as authoritative.

    1. Does KIR retain the security fixes?

    Yes; that's one of KIR's main purposes. It rolls back the specific problematic non-security change rather than removing the complete cumulative security update.

    1. Limitations/side effects?

    These depend on exactly which change Microsoft is rolling back. That's another reason not to deploy an unverified KIR package without its corresponding Microsoft documentation.

    1. Permanent fix date?

    I don't see a Microsoft-published ETA for a permanent RDS fix yet.

    Since these September updates were released only on September 8, 2026, and we're only a few days into the servicing cycle, Microsoft may still update the Windows release-health/KB documentation if it confirms a regression. The safest course for production RDS servers is to monitor Microsoft's release-health information rather than act on an undocumented KIR identifier.

    If you're already experiencing the RDP/RDS problem, open a Microsoft Support case and provide the exact Server version/build, RDS role, symptoms, Event Viewer entries, and confirmation that the problem began after KB5122876/KB5122882. Specifically ask Support whether KIR 260911_18474 / 260911_18471 applies to your environment.

    Official references:

    KB5122876 - Windows Server 2019 September 2026 update

    KB5122882 - Windows Server 2022 September 2026 update

    Windows Server release information

    =============================================================================

    Help make this community better for everyone: If this answer helped or resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution. Thank you.

    Was this answer helpful?

    1 person found this answer helpful.

  2. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  3. Max Max 0 Reputation points
    2026-09-14T17:43:25.1866667+00:00

    We have now deployed the official Microsoft Known Issue Rollback package for Windows Server 2022:

    Windows Server 2022 KB5122882 260911_18471 Known Issue Rollback

    The package was installed and the corresponding Group Policy was configured according to Microsoft’s instructions, including the required restart.

    Unfortunately, on one server the same RDP/RDS issue occurred again after the KIR had been correctly applied. Existing RDP sessions continued to work, but new users were no longer able to connect. Microsoft-Windows-Winlogon Event ID 6005 related to SessionEnv was also present.

    We would also like to better understand Microsoft’s position regarding communication of this incident.

    This issue affects Windows Server and has a significant impact on RDP/RDS availability, but the public Windows Release Health page still does not contain a complete mitigation procedure or direct links to the KIR packages.

    At the same time, the KIR information and official download links are available through the Microsoft 365 Admin Center, which means that administrators without access to that portal cannot easily obtain the same official guidance.

    Could you please clarify the following:

    1. Is Microsoft aware of cases where the RDP/RDS issue reoccurs after applying Windows Server 2022 KB5122882 260911_18471 Known Issue Rollback?
    2. Are there any additional official mitigations or workarounds for systems where the issue still occurs after applying this KIR?
    3. Why has the KIR information and deployment guidance not yet been published on the public Windows Release Health page?
    4. Is Microsoft planning to release a permanent fix or an out-of-band update for this issue?
    5. Is there any estimated timeframe for the permanent fix?

    For administrators without access to the Microsoft 365 Admin Center, the current situation is particularly difficult: the incident is publicly acknowledged by Microsoft, but the official mitigation and download links are currently available only through a restricted corporate channel.

    Any additional information or clarification would be greatly appreciated.

    Was this answer helpful?

    0 comments No comments

  4. Brent-H 0 Reputation points
    2026-09-14T17:00:20.46+00:00

    Hello,

    I also was looking to see if Microsoft had released a KIR for this, but the public https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-1809-and-windows-server-2019#4981msgdesc page does not list one.

    However, when I looked in the Microsoft 365 admin center under Health > Windows Release Health, I did see the issue listed there ( link from initial notification email: https://admin.cloud.microsoft/Adminportal/Home?source=applauncher#/windowsreleasehealth/:/issue/WI1470789 (for Server 2019 but it looks the same for 2022/2025) but you should be able to find it without this link if you have access to the admin center). In that page, it lists: "Workaround: Mitigation for this issue is available through the Group Policy listed below. ..." and provides links to the KIR from download.microsoft.com.

    The message also links to https://learn.microsoft.com/en-us/troubleshoot/windows-client/group-policy/use-group-policy-to-deploy-known-issue-rollback for instructions, which states "KIRs apply to only nonsecurity updates because rolling back a fix for a nonsecurity update doesn't create a potential security vulnerability." and "You have to restart the affected computers in order to apply this Group Policy change."

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.