Skip to content

Security1 publisher2 min readPublished

Microsoft confirms its September updates break Remote Desktop Services back to Server 2012

Microsoft's release health note says RDP connections can fail after several minutes and servers can hang at the Remote Desktop Configuration screen. Group Policy mitigations cover ten build families while a permanent fix is still in work.

The Watch · Security desk

Illustration accompanying Microsoft confirms its September updates break Remote Desktop Services back to Server 2012

What happened

  • Microsoft confirmed in a release health update on Friday that its September 2026 security updates cause Remote Desktop Services failures on Windows Server 2012 and later, and on Windows 10 and Windows 11 devices.
  • The confirmation followed widespread admin reports that this month's Patch Tuesday updates stopped users connecting, with some servers requiring a hard reset to restore functionality.
  • Microsoft says Microsoft Management Console, the RDS Licensing Diagnoser and File Explorer might also become unresponsive, and the Windows Update page might hang on a loading indicator.
  • Microsoft has published ten Group Policy mitigations, one per build family from Windows Server 2012 up to Windows 11 26H1, while it works on a permanent fix.
  • Admins have also restored Remote Desktop by uninstalling the updates; removing them takes this month's security fixes off the host as well.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Every affected RDS host needs a call before the next maintenance window: keep the update and deploy the Group Policy, or get sessions back by uninstalling and running without September's fixes.
  • constraint Microsoft scopes the Group Policy to enterprise-managed devices, so standalone and unmanaged servers are down to restarting the machine or pulling the updates.
  • precedent The last comparable RDS regression took Microsoft about two months to close, from January 2025 updates to a March 2025 fix. Admins could be running the Group Policy for about that long.

The failure here is availability, with no attacker involved. Microsoft's description of it stays conditional: "In some environments, RDS might become unstable, resulting in RDP connections failing after several minutes, sign-in issues, or servers hanging at 'Please wait for the Remote Desktop Configuration'," the company said on Friday [3]. Administrators reporting the same behaviour put it harder, with some servers needing a hard reset before they came back [5]. Once a host starts failing, existing Remote Desktop sessions may not disconnect or log off properly, and new connection attempts hang during setup [6].

The three documented responses do different things. The Group Policy Microsoft published is per build: KB5124008 for Windows 11 24H2, 25H2 and Windows Server 2025, KB5123065 for Windows Server 2012, KB5124012 for Windows 11 26H1, and seven further entries [8]. It sits under Computer Configuration > Administrative Templates, and Microsoft scopes it to enterprise-managed devices administered by IT departments [7]. That path leaves this month's updates installed.

For a machine an admin cannot reach over RDP, Microsoft's suggestion is a reboot: stopping and restarting the affected virtual machine, which it describes as a temporary restoration of RDS connectivity while work on a permanent fix continues [9].

Uninstalling is the third route, and the only one that moves a host's patch level backwards: pulling the updates restores Remote Desktop and takes the September security content with it [10]. The machines under discussion are the RDS hosts themselves, so the systems left running September-unpatched code are the ones accepting inbound remote sessions [15].

Microsoft has shipped this class of regression before. Windows updates released from January 2025 onward triggered Remote Desktop and RDS connection failures, and the fix landed in March 2025 [11], roughly two months later [13]. Admins running the Group Policy could be on that workaround for about as long.

What to watch

  • Whether the permanent fix arrives out-of-band or waits for the October Patch Tuesday release.
  • Whether Microsoft widens the affected-build list or revises the Group Policy entries already published.
  • Exploitation of any vulnerability closed in the September release, which would change what rollback costs.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories