Administrators who applied the Microsoft Windows updates from November 8 have reported problems with Kerberos network authentication.
Updates to Windows Servers compromised their capacity to serve as Domain Controllers for network and identity security demands, according to Microsoft’s weekend Windows Health Dashboard report.
The version that is impacted is OS Build 22621.819, KB5019980.
The effects include failed domain user sign-ins, failed Active Directory Federation Services authentication, failed authentication for Group Managed Service Accounts (used for services like the IIS Web server), failed remote desktop connections for domain users, failed authenticated printing.
Microsoft provided an example of the error message along with the statement, “When this issue is encountered you can receive a Microsoft-Windows-Kerberos-Key-Distribution-Center Event ID 14 error event in the System section of Event Log on your Domain Controller.”
Microsoft stated that a patch is anticipated in the next few weeks.
The DirectAccess remote access service is also affected by a problem.
Users of DirectAccess shouldn’t need to manually start and stop the connection like they would with a VPN service because the connection should always be active.
However, Microsoft warned customers that after downloading KB5019509, they might experience issues with their DirectAccess connections if their client’s network connectivity was disrupted (for example, by moving between different wi-fi access points).
Administrators can temporarily address the issue by forcing users to restart their devices or by using the Known Issue Rollback feature.


