This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Note
Access to this page requires authorization. You can trysigning in orchanging directories.
Access to this page requires authorization. You can trychanging directories.
Find information on recently resolved issues for Windows Server 2025. To find a specific issue, use the search function on your browser (CTRL + F for Microsoft Edge). For immediate help with Windows update issues,click here if you are using a Windows device to open the Get Help app or go tosupport.microsoft.com. Follow@WindowsUpdate on X for Windows release health updates. If you are an IT administrator and want to programmatically get information from this page, use theWindows Updates API in Microsoft Graph.
| Summary | Originating update | Status | Date resolved |
|---|---|---|---|
| Non-admins might receive unexpected UAC prompts when doing MSI repair operations This issue can affect apps that use Windows Installer (MSI), such as Autodesk AutoCAD or Office Professional Plus 2010. | OS Build 26100.4946 KB5063878 2025-08-12 | Resolved KB5065426 | 2025-09-09 10:00 PT |
| IIS websites might fail to load Server-side applications that rely on HTTP.sys may experience issues with incoming connections. | OS Build 26100.6899 KB5066835 2025-10-14 | Resolved KB5068861 | 2025-11-11 10:00 PT |
| Directory synchronization fails for AD groups exceeding 10,000 members Issue affects Active Directory Domain Services (AD DS) synchronization, including Microsoft Entra Connect Sync | OS Build 26100.6584 KB5065426 2025-09-09 | Resolved KB5068861 | 2025-11-11 10:00 PT |
| Smartcard authentication issues might occur with the October 2025 Windows update This issue is related to a security change introduced for strengthening Windows Cryptographic Services. | OS Build 26100.6899 KB5066835 2025-10-14 | Resolved | 2025-10-22 17:31 PT |
| USB mouse and keyboard not working in the Windows Recovery Environment (WinRE) This issue affects USB devices only within WinRE after installing Windows updates released on October 14, 2025. | OS Build 26100.6899 KB5066835 2025-10-14 | Resolved KB5070773 | 2025-10-20 14:00 PT |
| Issues occur when using Microsoft Changjie Input Method Only devices using Traditional Chinese are affected. Reverting to the previous IME version prevents the issue. | OS Build 26100.4652 KB5062553 2025-07-08 | Resolved KB5062660 | 2025-07-22 10:00 PT |
| Some Azure Virtual Machines with Trusted Launch disabled might fail to start This impacts a small subset of Gen 2 VMs on specific SKUs with VBS enabled after installing the July security update. | OS Build 26100.4652 KB5062553 2025-07-08 | Resolved KB5064489 | 2025-07-13 14:00 PT |
| Logon might fail with Windows Hello in Key Trust mode and log Kerberos Events The April 2025 update may trigger behavior in domain controllers that logs Kerberos event IDs 45 and 21 | OS Build 26100.3775 KB5055523 2025-04-08 | Resolved KB5060842 | 2025-06-10 10:00 PT |
| Domain controllers manage network traffic incorrectly after restarting Domain firewall profiles aren't used, resulting in applications or services failing | N/A | Resolved KB5060842 | 2025-06-10 10:00 PT |
| Windows Server 2025 might not run as expected on devices with high core count This is observed on servers with more than 256 logical processors. Issues may not trigger consistently. | N/A | Resolved KB5046617 | 2024-11-12 10:00 PT |
| Remote Desktop might freeze after installing the February 2025 update This issue currently affects Windows Server 2025 devices. A resolution is available for Windows 11, version 24H2. | OS Build 26100.3194 KB5051987 2025-02-11 | Resolved KB5055523 | 2025-04-08 10:00 PT |
| Authentication issues due to failed password rotation in Kerberos This issue is observed in a niche scenario when using PKINIT protocol and is resolved in the April 2025 security update. | N/A | Resolved KB5055523 | 2025-04-08 10:00 PT |
| Some text might appear in English during the installation process This only occurs when utilizing certain media, such as CD or USB, to install Windows Server 2025 | N/A | Resolved KB5055523 | 2025-04-08 10:00 PT |
| Error 'boot device inaccessible' might appear in iSCSI environments Servers might see error 'boot device inaccessible' after the installation of Windows Server 2025 | N/A | Resolved KB5051987 | 2025-02-11 10:00 PT |
IIS websites might fail to load
| Status | Originating update | History |
|---|---|---|
| ResolvedKB5068861 | OS Build 26100.6899 KB5066835 2025-10-14 | Resolved: 2025-11-11, 10:00 PT Opened: 2025-10-16, 16:06 PT |
After further investigation, we concluded that this issue was not applicable to Windows Server 2025. It affects only Windows 11, version 25H2 and 24H2.
This issue can be disregarded by Windows Server users.
To learn about the impact of this issue for Windows 11, select from the links below:
The issue mentioned below was published prior to this finding and November 14, 2025 edits:
Following installation of Windows updates releases on or after September 29, server-side applications that rely on HTTP.sys may experience issues with incoming connections. As a result, IIS websites might fail to load, displaying a message such as "Connection reset - error (ERR_CONNECTION_RESET)", or similar error. This includes websites hosted on http://localhost/, and other IIS connections.
Affected platforms:
Directory synchronization fails for AD groups exceeding 10,000 members
| Status | Originating update | History |
|---|---|---|
| ResolvedKB5068861 | OS Build 26100.6584 KB5065426 2025-09-09 | Resolved: 2025-11-11, 10:00 PT Opened: 2025-10-14, 17:49 PT |
Applications that use the Active Directorydirectory synchronization (DirSync) control for on-premises Active Directory Domain Services (AD DS), such as when usingMicrosoft Entra Connect Sync, can result in incomplete synchronization of large AD groups exceeding 10,000 members. This issue occurs only on Windows Server 2025 after installing the September 2025 Windows security update (KB5065426), or later updates.
Resolution:This issue was resolved by Windows updates released November 11, 2025,KB5068861, and updates released after that date. We recommend you install the latest update for your device as it contains important improvements and issue resolutions, including this one.
If you have installed updates released on or after November 11, 2025, (KB5068861), you do not need to use a Known Issue Rollback (KIR) or a special Group Policy to resolve this issue.
If you are using an update released before November 11, 2025, and have this issue, your IT administrator can resolve it by installing and configuring the special Group Policy listed below.
Group Policy downloads with Group Policy name:
The special Group Policy can be found in Computer Configuration -> Administrative Templates -> Windows 11 24H2, Windows 11 25H2 and Windows Server 2025 KB5066835 251016_21401 Known Issue Rollback. After installing the group policy, configure theKB5066835 251016_21401 Known Issue Rollbackvalue toDisabledand restart Windows Server 2025 to apply the group policy setting. (Windows 11 is out of scope of this notification and guidance.) For information on deploying and configuring this special Group Policy, please seeHow to use Group Policy to deploy a Known Issue Rollback.
Alternatively, affected customers can apply the following registry key as a workaround to disable the feature change.
Warning: Serious problems might occur if you modify the registry incorrectly by using Registry Editor or by using another method. These problems might require that you reinstall the operating system. Microsoft cannot guarantee that these problems can be solved. Modify the registry at your own risk. For more information, seeWindows registry for advanced users.
Path: Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides
Name: 2362988687
Type: REG_DWORD
Value: 0
Affected platforms:
Smartcard authentication issues might occur with the October 2025 Windows update
| Status | Originating update | History |
|---|---|---|
| Resolved | OS Build 26100.6899 KB5066835 2025-10-14 | Resolved: 2025-10-22, 17:31 PT Opened: 2025-10-17, 20:06 PT |
Smart card authentication and other certificate operations might intentionally fail after installing Windows Updates released on or after October 14, 2025 (KB5066835) that contain protections for the security vulnerability, CVE-2024-30098. As part of this cryptography improvement, RSA-based smart card certificates are required to use KSP (Key Storage Provider) instead of CSP (Cryptographic Service Provider).
Common symptoms for certificates that use CSP include:
You can detect if your smart card will be affected by this security enforcement if, prior to installing the October 2025 Windows security update (KB5066835), the System log contains Smart Card Service or Microsoft-Windows-Smartcard-Server Event ID: 624 with the message text: "Audit: This system is using CAPI for RSA cryptography operations. Please refer to the following link for more detail: https://go.microsoft.com/fwlink/?linkid=2300823."
Resolution:
For a permanent resolution, developers should update their authenticating app to perform Key Storage Retrieval using Key Storage API documented at Key Storage and Retrieval. Developers should complete this change before Windows updates released in April 2026, at which time theDisableCapiOverrideForRSAworkaround listed below is planned to be removed.
Workaround:
If you encounter this issue, you can temporarily resolve it by setting the DisableCapiOverrideForRSA registry key value to 0. This is documented in CVE-2024-30098. Detailed steps to modify the registry key are listed below.Note: This option will be removed in Windows updates, planned for release in April 2026.
Steps to Modify the Registry
⚠️ Important: Editing the registry incorrectly can cause system issues. Always back up the registry before making changes.
1. Open Registry Editor.
2. Navigate to the subkey.
3. Edit the key and set the value.
Note: The DisableCapiOverrideForRSA registry setting is NOT added by the default OS install or the installation of Windows Updates and must be manually added on each device.
4. Close and restart.
Affected platforms:
USB mouse and keyboard not working in the Windows Recovery Environment (WinRE)
| Status | Originating update | History |
|---|---|---|
| ResolvedKB5070773 | OS Build 26100.6899 KB5066835 2025-10-14 | Resolved: 2025-10-20, 14:00 PT Opened: 2025-10-17, 22:18 PT |
After installing the Windows security update released on October 14, 2025 (KB5066835), USB devices, such as keyboards and mice, do not function in theWindows Recovery Environment (WinRE). This issue prevents navigation of any of the recovery options within WinRE. Note that the USB devices continue to work normally within the Windows operating system.
Resolution:This issue was resolved by the Windows out-of-band update, released October 20, 2025 (KB5070773), which is available via the Microsoft Update Catalog, and updates released after that date. We recommend you install the latest update for your device as it contains important improvements and issue resolutions, including this one.
Workaround: If your device is impacted by this issue and is unable to boot to Windows to install the latest Windows update, you can work around this issue using one of the following methods:
Affected platforms:
Non-admins might receive unexpected UAC prompts when doing MSI repair operations
| Status | Originating update | History |
|---|---|---|
| ResolvedKB5065426 | OS Build 26100.4946 KB5063878 2025-08-12 | Resolved: 2025-09-09, 10:00 PT Opened: 2025-09-03, 14:28 PT |
(Updated 11/26/25: Additional improvements were added to the Resolution section.)
A security improvement was included in the August 2025 Windows security update (KB5063878) and later updates to enforce the requirement that User Account Control (UAC) prompt for administrator credentials when performing Windows Installer (MSI) repair and related operations. This improvement addressed security vulnerability CVE-2025-50173.
As a result, after installing the August 2025 Windows security update and later updates, UAC prompts for administrator rights can appear for standard users in the following scenarios:
If a standard user runs an app that initiates an MSI repair operation without displaying UI, it will fail with an error message. For example, installing and running Office Professional Plus 2010 as a standard user will fail with Error 1730 during the configuration process.
Resolution:
After installing the September 2025 Windows security update (KB5065426) or later updates, UAC prompts will only be required during MSI repair operations if the target MSI file contains an elevatedcustom action. This requirement is further refined after installing Windows updates released on and after November 11, 2025, so that UAC prompts will only be required if the elevated custom actions are executed during the repair flow.
Installing the latest Windows updates will resolve this issue for apps that do not execute such elevated custom actions, such as Autodesk AutoCAD.
Since UAC prompts will still be required for apps that perform custom actions, after installing the September 2025 update, IT admins will have access to a workaround to disable UAC prompts for specific apps by adding MSI files to an allowlist. For details, see the KB article:Unexpected UAC prompts when running MSI repair operations after installing the August 2025 Windows security update.
A Group Policy had previously been made available fromMicrosoft’s Support for business using Known Issue Rollback (KIR) to work around this issue. Organizations no longer need to install and configure this Group Policy to address this issue.
Affected platforms:
Issues occur when using Microsoft Changjie Input Method
| Status | Originating update | History |
|---|---|---|
| ResolvedKB5062660 | OS Build 26100.4652 KB5062553 2025-07-08 | Resolved: 2025-07-22, 10:00 PT Opened: 2025-07-11, 08:52 PT |
Following installation of the July 2025 Windows security updates (KB5062553), there might be issues when using theMicrosoft Changjie IME (input method editor) for Traditional Chinese.
This issue only affects devices where Traditional Chinese is a preferred or common language or input method, and specifically where Changjie IME is used. Reported symptoms include:
Microsoft Changjie is an IME that is included in Windows and available in currently supported versions.
Resolution: This issue is resolved in the July 2025 Windows non-security update (KB5062660) and later updates. We recommend you install the latest update for your device as it contains important improvements and issue resolutions, including this one.
If you have installed Windows updates released before before July 2025, you can use the following workaround. Windows IME supports a compatibility setting that allows using the previous version of an IME instead. Employing this option should help resolve this issue.
To revert to old version of the Microsoft Changjie IME, follow these steps:
Affected platforms:
Some Azure Virtual Machines with Trusted Launch disabled might fail to start
| Status | Originating update | History |
|---|---|---|
| ResolvedKB5064489 | OS Build 26100.4652 KB5062553 2025-07-08 | Resolved: 2025-07-13, 14:00 PT Opened: 2025-07-11, 00:18 PT |
A small subset of Azure Virtual Machines (VMs) running Windows Server 2025 or Windows 11, version 24H2, with Trusted Launch disabled, and Virtualization-Based Security (VBS) enforced via registry key might fail to boot after installing the July Windows security update (KB5062553).
To check if your virtual machine might be impacted:
Resolution:This issue was resolved in the out-of-band (OOB) updateKB5064489, which is available via the Microsoft Update Catalog. If your virtual machine configuration is impacted by this issue, we recommend installing this out-of-band update instead ofKB5062553.
Administrators can receive updated VM images for all editions of Windows Server 2025, including hotpatch editions. The new media is documented in the article,Windows Server images for July 2025.
Note: You can also prevent this issue by enablingTrusted Launch. Trusted Launch isrequired for Virtual Machines running Windows 11.
Affected platforms:
Logon might fail with Windows Hello in Key Trust mode and log Kerberos Events
| Status | Originating update | History |
|---|---|---|
| ResolvedKB5060842 | OS Build 26100.3775 KB5055523 2025-04-08 | Resolved: 2025-06-10, 10:00 PT Opened: 2025-05-06, 13:25 PT |
After installing the April Windows monthly security update released April 8, 2025 (KB5055523) or later, Active Directory Domain Controllers (DC) might experience authentication interruptions when processing Kerberos logons or delegations using certificate-based credentials that rely on key trust via the Active Directorymsds-KeyCredentialLink field.
Following these updates, the method by which DCs validate certificates used for Kerberos authentication has changed, and will now require that certificates are chained to an issuing certificate authority (CA) in the NTAuth store. This is related to security measures described inKB5057784 - Protections for CVE-2025-26647 (Kerberos Authentication). As a result, authentication failures might be observed in Windows Hello for Business (WHfB) Key Trust environments or environments that have deployed Device Public Key Authentication (also known as Machine PKINIT). Other products which rely on this feature can also be impacted.
Enablement of this validation method can be controlled by the Windows registry valueAllowNtAuthPolicyBypass inHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Kdc. Two scenarios can be observed following installation of the April 2025 Windows monthly security update on authenticating DCs:
Note that if theAllowNtAuthPolicyBypass registry key does not exist, the DC will behave as if the value is configured to “1”. The key may be created manually, if it does not exist, and configured as per above.
Windows Updates released on and after April 8, 2025 incorrectly log Event IDs 45 and 21 when servicing authentication requests using self-signed certificates that will never chain to a CA in the NTAuth store. Self-signed certificates may be used by the AD PKINIT Key Trust feature in the following scenarios:
Resolution: This issue was resolved by Windows updates released June 10, 2025 (KB5060842), and later. We recommend you install the latest security update for your device as it contains important improvements and issue resolutions, including this one.
If you install an update released June 10, 2025 or later, you do not need to use a workaround for this issue. If you are using an update released before this date and have this issue, you should temporarily delay setting a value of ‘2’ to registry keyAllowNtAuthPolicyBypass on updated DCs servicing self-signed certificate-based authentication. For more information, see the Registry Settings section ofKB5057784.
Affected platforms:
Domain controllers manage network traffic incorrectly after restarting
| Status | Originating update | History |
|---|---|---|
| ResolvedKB5060842 | N/A | Resolved: 2025-06-10, 10:00 PT Opened: 2025-04-11, 13:20 PT |
Windows Server 2025 domain controllers (such as servers hosting the Active Directory domain controller role) might not manage network traffic correctly following a restart. As a result, Windows Server 2025 domain controllers may not be accessible on the domain network, or are incorrectly accessible over ports and protocols which should otherwise be prevented by the domain firewall profile.
This issue results from domain controllers failing to use domain firewall profiles whenever they’re restarted. Instead, the standard firewall profile is used. Resulting from this, applications or services running on the domain controller or on remote devices may fail, or remain unreachable on the domain network.
Workaround:The expected behavior can be restored if the network adapter is restarted. This can be performed manually in various ways, such as using the following command via PowerShell:
Restart-NetAdapter *
Please note that, since this issue triggers whenever the domain controller is restarted, this workaround must be repeated every time the domain controller is restarted. It may be helpful to create a scheduled task which restarts the network adapter any time the domain controller is restarted.
Resolution: This issue is resolved in the June 2025 Windows security update (KB5060842) and later updates. We recommend you install the latest update for your device as it contains important improvements and issue resolutions, including this one.
Affected platforms:
Authentication issues due to failed password rotation in Kerberos
| Status | Originating update | History |
|---|---|---|
| ResolvedKB5055523 | N/A | Resolved: 2025-04-08, 10:00 PT Opened: 2025-04-07, 16:30 PT |
After installing Windows Server 2025, devices using the Identity Update Manager certificate/Public Key Cryptography for Initial Authentication (PKNIT), might experience an issue with passwords not rotating correctly, causing authentication failures. This issue occurs particularly whenKerberos Authentication is used and theCredential Guard feature is enabled. Note that machine certification using PKINIT path is a niche use case, and this issue affects a small number of devices in enterprise environments.
With this issue, devices fail to change their password every 30 days as the default interval. Because of this failure, devices are perceived as stale, disabled, or deleted, leading to user authentication issues.
Devices running Windows Home edition are unlikely to be affected by this issue, as Kerberos authentication is typically used in enterprise environments and is not common in personal or home settings.
Resolution:
This issue is resolved in the April 2025 Windows security update (KB5055523) and later updates. We recommend you install the latest update for your device as it contains important improvements and issue resolutions, including this one.
Note: The featureMachine Accounts in Credential Guard, which is dependent on password rotation via Kerberos, has been disabled until a permanent fix is made available.
Affected platforms:
Remote Desktop might freeze after installing the February 2025 update
| Status | Originating update | History |
|---|---|---|
| ResolvedKB5055523 | OS Build 26100.3194 KB5051987 2025-02-11 | Resolved: 2025-04-08, 10:00 PT Opened: 2025-03-25, 10:26 PT |
After installing the February 2025 Security update (KB5051987), released February 11, 2025, and later updates, on Windows Server 2025 devices, you might experience Remote Desktop sessions freezing shortly after connection. When this issue occurs, mouse and keyboard input become unresponsive within the session, requiring users to disconnect and reconnect.
Resolution:
This issue is resolved inKB5055523. We recommend you install the latest update for your device as it contains important improvements and issue resolutions, including this one.
Affected platforms:
Windows Server 2025 might not run as expected on devices with high core count
| Status | Originating update | History |
|---|---|---|
| ResolvedKB5046617 | N/A | Resolved: 2024-11-12, 10:00 PT Opened: 2024-10-31, 13:11 PT |
Servers which have a high number of logical processors might experience issues running Windows Server 2025. This is presently observed on servers which have more than 256 logical processors.
On these devices, one or more of the following issues might be encountered:
Issues may not trigger consistently, for which it is also possible that the server will start and operate without problem.
To determine whether you are encountering this issue because thenumber of logical processors on the device exceeds 256, open the Windows Task Manager. This can be accomplished by pressingCTRL+SHIFT+ESC. From there, select thePerformance tab and note the number of logical processors reported in the bottom half of the window.
Resolution:This issue was resolved by Windows updates released November 12, 2024 (KB5046617), and later. We recommend you install the latest security update for your device as it contains important improvements and issue resolutions, including this one. If you install an update released November 12, 2024 (KB5046617) or later, you do not need to use a workaround for this issue. If you are using an update released before this date, and have this issue, you have the option to apply the following workaround:
To temporarily prevent this issue, you will need to limit the total number of logical processors on the server to 256 or under. Changing the number of logical processors will vary depending on the firmware installed on your device.
To adjust the number of logical processors, follow these steps:
Affected platforms:
Some text might appear in English during the installation process
| Status | Originating update | History |
|---|---|---|
| ResolvedKB5055523 | N/A | Resolved: 2025-04-08, 10:00 PT Opened: 2024-10-31, 13:12 PT |
When installing Windows Server 2025, some text might appear in English during the installation process, regardless of the language selected for the installation. This will be noticeable if a language other than English has been selected for installation.
Please note, this only occurs when utilizing media - such as CD and USB flash drives - to install Windows Server 2025. This issue is only present on Windows Server media 25100.1742 and above with the use of Multilanguage User Interface (MUI).
Resolution: This issue was resolved by Windows updates released April 8, 2025 (KB5055523), and later. We recommend you install the latest security update for your device as it contains important improvements and issue resolutions, including this one.
Affected platforms:
Error 'boot device inaccessible' might appear in iSCSI environments
| Status | Originating update | History |
|---|---|---|
| ResolvedKB5051987 | N/A | Resolved: 2025-02-11, 10:00 PT Opened: 2024-10-31, 16:09 PT |
Servers which use iSCSI (Internet Small Computer Systems Interface) technology might display an error upon startup, with the message 'boot device inaccessible'.
This is observed on servers operating under NDIS Poll Mode booting from an iSCSI LUN. Under such configuration, the server will experience the error during startup, after the installation of Windows Server 2025 is completed.
Resolution:This issue was resolved by Windows updates released February 11, 2025 (KB5051987), and later. We recommend you install the latest update for your device as it contains important improvements and issue resolutions, including this one.
Affected platforms:
To report an issue to Microsoft at any time, use theFeedback Hub app. To learn more, seeSend feedback to Microsoft with the Feedback Hub app.
Search, browse, or ask a question on theMicrosoft Support Community. If you are an IT pro supporting an organization, visit Windows release health on theMicrosoft 365 admin center for additional details.
For direct help with your home PC, use the Get Help app in Windows or contactMicrosoft Support. Organizations can request immediate support throughSupport for business.
This site is available in11 languages: English, Chinese Traditional, Chinese Simplified, French (France), German, Italian, Japanese, Korean, Portuguese (Brazil), Russian, and Spanish (Spain). All text will appear in English if your browser default language is not one of the 11 supported languages. To manually change the display language, scroll down to the bottom of this page, click on the current language displayed on the bottom left of the page, and select one of the 11 supported languages from the list.