What has happened?

Microsoft released its September Windows security updates on 8 September 2026. In the following days, it confirmed several issues affecting particular configurations, including Remote Desktop Services becoming unstable, File History failing to create or update backups, some USB audio devices failing to start, shared folders becoming unavailable in certain Linux virtual machines and a limited domain trust issue affecting devices with specific security settings.

On 14 September, Microsoft released out-of-band updates addressing the Remote Desktop problem, the virtual-machine folder-sharing issue and some USB audio symptoms. An out-of-band update is an update released outside Microsoft's normal monthly schedule because it contains fixes that should not wait until the next regular update.

Microsoft added the File History problem to its Windows 11 release notes on 19 September. At the time this article was reviewed, that issue remained under investigation.

These problems do not affect every computer, and organisations should not assume that all September updates are unsafe. The important step is to identify the Windows versions and services in use, install the latest applicable updates and verify that essential systems are working.

Check Remote Desktop systems

Microsoft confirmed that some Remote Desktop Services environments became unstable after September's security updates. Symptoms could include Remote Desktop connections failing after several minutes, users being unable to sign in, servers remaining on 'Please wait for the Remote Desktop Configuration', or File Explorer, Microsoft Management Console, the Remote Desktop Licensing Diagnoser or Windows Update becoming unresponsive.

Microsoft says the problem is resolved by Windows updates released on or after 14 September. For Windows 11 versions 24H2 and 25H2, one applicable update is KB5129195. Other supported Windows and Windows Server versions may use different update numbers, so the update must match the operating system concerned.

Windows 365 and Azure Virtual Desktop were not affected by this particular Remote Desktop issue. If your organisation operates a Remote Desktop server, check both the installed update history and the service itself. A successful update installation does not confirm that users can connect and work normally.

Confirm that backups are still running

The File History issue deserves particular attention because a failed backup can remain unnoticed until somebody needs to recover a file.

Microsoft says that some Windows 11 computers may display 'Reconnect your drive' even when a compatible backup drive is connected. The last-backup date may stop updating, previously backed-up files may show no available previous version and Windows may record errors involving FileHistory.exe.

As of 21 September 2026, Microsoft had not published a complete resolution. Do not rely solely on a green status message: a small test restoration provides much better evidence that the backup is usable.

File History is not the same as OneDrive, a server backup or a managed third-party backup service. Those products are not automatically affected by this specific problem, but their dashboards and recent recovery points should still be checked regularly.

  • Open Control Panel, select System and Security, then open File History.
  • Confirm that the expected backup location is connected.
  • Check the date and time of the most recent backup.
  • Select a non-critical test file and confirm that an earlier version can be restored.

Review audio and specialist equipment

Some USB Audio Class 1.0 devices may fail to start or produce sound after the September update. Symptoms can include a Device Manager Code 10 error, no audio output, unavailable sound settings or volume controls remaining at zero.

The out-of-band update resolved problems affecting some devices using eight-channel or 3D audio. Microsoft says other USB audio symptoms are still being investigated.

Test important equipment after updating, particularly where it is needed for lessons, meetings or customer services. Avoid downloading unofficial replacement drivers or removing security updates without first confirming the cause.

  • Classroom audio systems
  • USB headsets
  • Conference-room equipment
  • Recording or public-address equipment
  • Specialist accessibility devices

Watch for domain sign-in problems

Microsoft has also documented a more limited problem in which some domain-connected computers could lose their secure trust relationship with an on-premises Active Directory domain.

This is not expected to affect ordinary domain-joined computers unless Machine Identity Isolation was previously enabled through policy or directly in the registry. The feature is supported only with domain controllers operating at the Windows Server 2025 Domain Functional Level or later.

Affected users may see a message saying that the trust relationship between the computer and domain has failed. Cached sign-in may continue to work while the computer is disconnected from the network.

Microsoft has published a workaround, but it involves changing security policy or registry settings and repairing the computer's secure channel. These changes should be completed by an administrator who has confirmed that the documented issue applies. Registry changes should not be attempted speculatively.

Continue updating, but use a controlled rollout

Known update problems can tempt organisations to disable Windows Update completely. That leaves computers without the security fixes included in the same updates and can create a more serious long-term risk.

The National Cyber Security Centre recommends an update-by-default policy. Its guidance also supports phased deployment, where updates are installed on a small number of representative devices before wider release.

The NCSC's vulnerability-management guidance recommends completing normal operating-system and application updates within seven days, using a phased rollout and pausing or rolling back where genuine problems are found.

  • Maintain a list of supported computers, servers and Windows versions.
  • Select a small group of representative test devices across different hardware, departments and important applications.
  • Install updates promptly on the test group.
  • Check sign-in, printing, sound, networking, backups and business software.
  • Review Microsoft's release-health information for known problems.
  • Expand the rollout once the initial checks have passed.
  • Keep a record of failed or offline devices requiring attention.
  • Maintain a documented recovery or rollback process.

Practical checklist

Use this checklist to confirm that the September updates have not disrupted an important service and to improve the next update rollout.

  • Record which Windows version each computer and server is running.
  • Check whether the latest update available for that version is installed.
  • Test Remote Desktop sign-in and stability where RDS is used.
  • Confirm that File History shows a recent successful backup.
  • Restore a test file rather than relying only on the backup status.
  • Review other backup dashboards and investigate missed jobs.
  • Test important USB audio, classroom and conference-room equipment.
  • Investigate any new domain trust warnings promptly.
  • Check Microsoft's official known-issues information before applying manual workarounds.
  • Use a small test group for future updates.
  • Do not disable security updates indefinitely because of an isolated problem.
  • Record any decision to defer an update, including the reason and planned review date.

Official sources and further reading

These primary sources were checked when this article was last reviewed.

Written by

Christopher Lomax

Director of Bury I.T. Support Ltd, with more than 20 years of hands-on experience supporting business IT, Microsoft 365, networks, servers and cyber security.

About the team