Full Breakdown
Microsoft April 2026 Patch Causes Domain Controller Failures
4/18/2026, 12:23:41 AM
Overview of the Issue
Microsoft's April 2026 cumulative security update, designated KB5082063, has led to significant disruptions in enterprise environments by causing domain controllers to enter continuous reboot cycles. This issue arises from crashes in the Local Security Authority Subsystem Service (LSASS) on non-Global Catalog domain controllers utilized in Privileged Access Management (PAM) deployments. The affected Windows Server versions include 2016, 2019, 2022, 23H2, and 2025. As a result, Active Directory authentication and directory services become unavailable, severely impacting enterprise operations.
Background on Previous Issues
This incident is not isolated; it follows a troubling pattern of problematic updates from Microsoft. In March 2024, an emergency fix was required after a Patch Tuesday update caused domain controller crashes. Similar issues arose in April 2024 and April 2025, where updates disrupted NTLM authentication and led to unplanned restarts. The recurring nature of these failures has raised concerns among IT administrators regarding the reliability of Microsoft's updates.
Current Impact and Workarounds
With no immediate patch available for KB5082063, administrators face three options: delay the update, isolate a test domain controller to assess the patch's behavior, or seek mitigation guidance from Microsoft Support for Business. Microsoft has indicated that the LSASS crash occurs during the startup sequence, leading to repeated reboots without recovery. Additionally, some Windows Server 2025 systems may experience installation failures with this update.
BitLocker Recovery Issues
The April 2026 update also introduces a separate issue where some devices, including Windows Server 2025 and Windows 11, are prompted for a BitLocker recovery key upon reboot. This problem is linked to specific TPM Group Policy configurations and marks the fourth occurrence of unexpected BitLocker recovery prompts following Patch Tuesday updates since 2022. Microsoft recommends removing the TPM validation policy before applying the update or utilizing a Known Issue Rollback to prevent the issue.
Criticism and Concerns
The situation has drawn criticism from IT professionals who express frustration over the reliability of Microsoft's updates. The irony of a security patch disabling critical infrastructure has not gone unnoticed. Administrators are increasingly concerned that they must now account for potential disruptions in their patch management workflows, as security updates have repeatedly compromised authentication systems.
Official Statements & Responses
Microsoft has acknowledged the issues associated with KB5082063 and is working on a permanent fix. In its communications, the company has emphasized that affected administrators can reach out for mitigation steps. Furthermore, Microsoft has reassured users that the BitLocker recovery key only needs to be entered once, provided the group policy configuration remains unchanged.
What's Next
As Microsoft investigates the ongoing issues with KB5082063, IT teams are advised to monitor the Windows Release Health dashboard closely for updates. The company has committed to addressing the LSASS crash and BitLocker recovery problems, but until a permanent solution is implemented, enterprise environments must navigate these challenges carefully.
