KB5007186Catastrophic

Kerberos SSO authentication broken enterprise-wide

What broke

November’s update broke Kerberos S4U2self authentication on every domain controller that installed it, silently killing single sign-on across entire enterprises. Azure AD Application Proxy, Web Application Proxy, and any service using Kerberos Constrained Delegation stopped authenticating users. Employees just… couldn’t sign into things. Microsoft rushed out emergency OOB updates five days later, but they weren’t available through WSUS — admins had to manually import them. Because when your authentication infrastructure is down, what you really want is more manual steps.

Sources

  1. BleepingComputer: KB5007186 incident report

Related Windows update incidents