Technology3 min read
KB5124008 breaks Always On VPN on Windows 11: what admins should do
Windows 11 update KB5124008 breaks Always On VPN with certificate authentication: connections stop establishing on 24H2 and 25H2 clients and in infrastructures with Windows Server 2019, RRAS and NPS. Microsoft had not responded officially at publication time, but proven workarounds exist.

What breaks
The problem appears during certificate negotiation while the IPsec connection is set up: the client fails authentication and the tunnel does not come up. An independent consultant assesses it as a regression in the network stack or in IPsec certificate handling rather than a configuration error. Indirect confirmation: everything works after removing the update.

Ring updates with a pilot group follow the same logic as a website staging environment: the error is caught on ten machines, not a thousand. We never push website changes without checking them on a copy first.
Who is affected
Client PCs on Windows 11 24H2 and 25H2 with Always On VPN profiles deployed through Microsoft Intune, and the server side on Windows Server 2019 with RRAS and NPS roles. If your VPN uses other protocols or username and password authentication, the update does not interfere.
What to do now
Specialist advice comes down to three steps.
- Pause deployment of KB5124008 through WSUS and Intune until a fix ships.
- Open a Microsoft support case so the issue enters the statistics and speeds up the patch.
- Temporarily switch profiles to EAP-TLS authentication through Intune: connections establish with it.
A lesson for the update process
The story repeats monthly: an update breaks a narrow scenario and people learn about it from user calls. Ring deployment with a pilot group and a one-week pause costs less than one day without VPN for remote staff. The same rule applies to CMS and module updates on a website: staging first, production second.
Summary
KB5124008 and certificate-based Always On VPN are incompatible until the fix. Pause deployment, move profiles to EAP-TLS and roll back where damage is already done.
Sources
Follow the journal
New pieces on websites, SEO and AI come out in the QIO journal. Follow in Google, by RSS or in Telegram to get them first.


