Microsoft Confirms Windows 11 September Updates Are Breaking Always On VPN Connections
Microsoft has confirmed that the September 2026 security updates are causing Always On VPN connection problems for some Windows 11 users. The issue affects KB5124012 for Windows 11 26H1, along with KB5124008 for Windows 11 25H2 and Windows 11 24H2.
A permanent fix is not yet available, but Microsoft says it is working on a resolution. In the meantime, IT administrators have been given a temporary workaround to restore VPN access for affected devices.
Always On VPN is Microsoft’s modern remote access solution and serves as the replacement for DirectAccess. It is supported on Windows 10, Windows 11, and Windows Server. The feature is widely used by businesses because it automatically creates a secure VPN tunnel in the background whenever a device connects to the internet.
The technology supports domain-joined devices, non-domain-joined devices, and Microsoft Entra ID-joined devices. It also works with IKEv2 and SSTP tunneling protocols and supports multi-factor authentication, making it a key part of many enterprise remote work setups.
The problem appears to affect Always On VPN profiles configured to use automatic protocol selection. In this setup, the VPN client typically attempts to connect using IKEv2 first. If that fails, it should automatically fall back to SSTP.
After installing the September Windows 11 updates, that fallback behavior can stop working correctly. As a result, affected VPN connections may get stuck in a “Connecting” state or continue trying to reconnect without success. Some users may also see the error message: “The specified port is already in use.”
For organizations that rely on Always On VPN, this can be a serious disruption. A failed VPN connection may prevent employees from accessing internal company systems, shared files, business applications, and other private network resources.
Until Microsoft releases a permanent fix, the company recommends changing affected Always On VPN profiles from automatic protocol selection to a single protocol. Administrators should configure the VPN profile to use either SSTP only or IKEv2 only, depending on the organization’s network environment, security policies, and deployment requirements.
Microsoft has not named one required management tool for applying this change. That means IT teams should use their existing configuration method, such as mobile device management, Group Policy, PowerShell, or other deployment tools already used to manage Always On VPN settings.
This VPN issue is not the only problem linked to the September 2026 Windows cumulative updates. Microsoft has also released emergency fixes for other update-related bugs, including Hyper-V problems, Remote Desktop Services failures, and USB audio issues.
The company has also provided a workaround for a separate problem that can prevent some users from signing in with valid domain credentials. Another known issue affecting the Windows File History backup feature is still being investigated.
For now, organizations using Always On VPN on Windows 11 should check whether devices have installed KB5124012 or KB5124008 and monitor for connection failures. If users report VPN sessions stuck on “Connecting” or repeated connection attempts, switching from automatic protocol selection to a fixed VPN protocol is currently the recommended workaround.






