KB5007186Catastrophic
Kerberos SSO authentication broken enterprise-wide
What broke
November’s update broke Kerberos S4U2self authentication on every domain controller that installed it, silently killing single sign-on across entire enterprises. Azure AD Application Proxy, Web Application Proxy, and any service using Kerberos Constrained Delegation stopped authenticating users. Employees just… couldn’t sign into things. Microsoft rushed out emergency OOB updates five days later, but they weren’t available through WSUS — admins had to manually import them. Because when your authentication infrastructure is down, what you really want is more manual steps.