Windows Server 2025 AD DS synchronization disruption after KB5065426
Service Disruption
Summary
Hide ▲
Show ▼
A Windows Server 2025 known issue is disrupting Active Directory Domain Services (AD DS) synchronization, causing incomplete sync for large AD security groups and risking directory inconsistency. The bug affects systems that installed the September 2025 Windows security update (KB5065426) or later updates and can break Microsoft Entra Connect Sync workflows. Administrators can mitigate the problem with a Known Issue Rollback Group Policy or a temporary registry change. A full fix is rolling out before next month's Patch Tuesday.
Related Happenings
Microsoft Windows Server 2016 domain controller discovery failure after KB5087537
Service Disruption
First: 26.05.2026 10:41
Last: 26.05.2026 10:41
Sources 1
About this happening:
Microsoft confirmed a **known issue** in **Windows Server 2016** after **KB5087537** that can prevent **domain controller discovery**, disrupting administrative operations and app...
Microsoft Windows Server 2016 domain controller discovery failure after KB5087537
Service DisruptionAbout this happening: Microsoft confirmed a **known issue** in **Windows Server 2016** after **KB5087537** that can prevent **domain controller discovery**, disrupting administrative operations and app...
Microsoft Windows Update restricted-network download failure
Service Disruption
First: 19.05.2026 14:22
Last: 19.05.2026 14:22
Sources 1
About this happening:
Microsoft's **Windows Update** is failing in **restricted network environments** after the **January 2026 optional non-security preview updates**, leaving affected systems unable...
Microsoft Windows Update restricted-network download failure
Service DisruptionAbout this happening: Microsoft's **Windows Update** is failing in **restricted network environments** after the **January 2026 optional non-security preview updates**, leaving affected systems unable...
Microsoft Windows 11 KB5089549 cumulative update
Security Patch Release
First: 18.05.2026 11:33
Last: 18.05.2026 11:33
Sources 1
About this happening:
Microsoft's **KB5089549** **Windows 11** security update is failing to install on some systems, forcing affected devices to roll back during reboot. The problem is tied to a nearl...
Microsoft Windows 11 KB5089549 cumulative update
Security Patch ReleaseAbout this happening: Microsoft's **KB5089549** **Windows 11** security update is failing to install on some systems, forcing affected devices to roll back during reboot. The problem is tied to a nearl...
Windows cldflt.sys MiniPlasma privilege escalation zero-day privilege-escalation flaw
Vulnerability
First: 18.05.2026 07:59
Last: 18.05.2026 07:59
Sources 1
About this happening:
**MiniPlasma** is a **Windows privilege-escalation zero-day** in **cldflt.sys** that can give attackers **SYSTEM** privileges on **fully patched Windows systems**. The flaw affect...
Windows cldflt.sys MiniPlasma privilege escalation zero-day privilege-escalation flaw
VulnerabilityAbout this happening: **MiniPlasma** is a **Windows privilege-escalation zero-day** in **cldflt.sys** that can give attackers **SYSTEM** privileges on **fully patched Windows systems**. The flaw affect...
Windows 11 25H2 BitLocker recovery fix (KB5089549)
Security Patch Release
First: 13.05.2026 18:42
Last: 13.05.2026 18:42
Sources 1
About this happening:
Microsoft shipped **KB5089549** for **Windows 11 25H2** to fix a **BitLocker Recovery** problem that could trap devices after the **April 2026 security updates**. The issue involv...
Windows 11 25H2 BitLocker recovery fix (KB5089549)
Security Patch ReleaseAbout this happening: Microsoft shipped **KB5089549** for **Windows 11 25H2** to fix a **BitLocker Recovery** problem that could trap devices after the **April 2026 security updates**. The issue involv...
Timeline
-
20.10.2025 18:27 3 articles · 7mo ago
Microsoft rolls out fix for Windows Server 2025 AD DS sync issue
Initial DisclosureMicrosoft is rolling out a fix for a known issue affecting Windows Server 2025 systems that installed the September 2025 Windows security update (KB5065426) or later, where Active Directory Domain Services (AD DS) synchronization and Microsoft Entra Connect Sync can produce incomplete synchronization for large AD security groups exceeding 10,000 members. Administrators can apply a Known Issue Rollback Group Policy on managed devices or use the temporary registry value 2362988687 under Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides until the fix reaches all customers next month.
Show sources
- Microsoft fixes Windows Server Active Directory sync issues — www.bleepingcomputer.com — 20.10.2025 18:27
- Microsoft fixes Windows Server Active Directory sync issues — www.bleepingcomputer.com — 20.10.2025 18:27
- Microsoft: Sept Windows Server updates cause Active Directory issues — www.bleepingcomputer.com — 15.10.2025 18:54