KB5019959Catastrophic
Kerberos authentication destroyed on domain controllers
What broke
For the second year in a row, Microsoft’s November update broke Kerberos on domain controllers. This time, any account with AES 256-bit or AES 128-bit encryption flags set in Active Directory couldn’t authenticate. Domain user sign-in failed. AD FS authentication failed. Group Managed Service Accounts for IIS failed. RDP for domain users failed. File share access failed. Every single supported Windows Server version was affected simultaneously. Emergency OOB patches took ten days to arrive. Nothing says “quality assurance” like breaking enterprise authentication the exact same way two Novembers in a row.