Vulnerabilities

September 2026 Windows Updates Disrupt Always On VPN Connections on Windows 11

September 23, 2026 12:00 · 5 min read
September 2026 Windows Updates Disrupt Always On VPN Connections on Windows 11

Microsoft Confirms Always On VPN Breakage After September 2026 Updates

Microsoft has issued a service alert notifying IT administrators that users may experience disruptions in Always On VPN connectivity following the installation of the September 2026 Windows 11 security updates. Always On VPN, which supersedes the legacy DirectAccess technology, enables automatic, secure tunneling to corporate networks for domain-joined, non-domain-joined, and Microsoft Entra ID–joined devices across Windows 10, Windows 11, and Windows Server platforms.

The service allows administrators to enforce app-specific routing and supports modern protocols including IKEv2 and SSTP, along with multi-factor authentication (MFA). According to Microsoft, the issue arises specifically when Always On VPN is configured to use automatic protocol selection — such as attempting both IKEv2 and SSTP in sequence when the initial connection fails.

Symptoms and Error Messages

Affected systems may exhibit VPN connections that remain stuck in a 'Connecting' state or repeatedly attempt to establish a connection without success. In some cases, subsequent attempts trigger the error message: 'The specified port is already in use.' This behavior prevents reliable access to enterprise resources and disrupts remote work workflows.

Affected Windows 11 Versions and Corresponding Updates

Microsoft confirmed that the issue impacts the following Windows 11 versions and their respective September 2026 cumulative updates:

These updates are part of Microsoft’s regular Patch Tuesday cycle and have been associated with multiple other system issues, including Hyper-V instability, Remote Desktop Services failures, USB audio malfunctions, domain login problems, and File History backup failures.

Temporary Workaround Recommended by Microsoft

While a permanent fix is under development, Microsoft advises administrators to disable automatic protocol selection in Always On VPN profiles and instead configure a single, static tunneling protocol — either IKEv2 only or SSTP only — based on their environment’s compatibility, security needs, and deployment constraints.

"IT administrators can mitigate this issue by changing the Always On VPN profile from automatic protocol selection to a single protocol, either SSTP only or IKEv2 only, depending on their environment and configuration,"

Microsoft stated in the service alert.

The guidance emphasizes that protocol selection should align with organizational infrastructure, firewall rules, and client capabilities to ensure stable and secure remote access.

Context: Broader Impact of September 2026 Updates

This Always On VPN issue is one of several post-update problems reported after the September 2026 patch release. Just one week prior, Microsoft released emergency out-of-band updates to address critical failures in Hyper-V, Remote Desktop Services, and USB audio functionality — all traced back to the same cumulative updates.

Additionally, the company has acknowledged and provided workarounds for a separate authentication bug that prevents some Windows 11 users from logging in with valid domain credentials, as well as an ongoing investigation into a defect causing the built-in File History feature to cease functioning unexpectedly.

Microsoft continues to monitor feedback from enterprise customers and MVP contributors, including Susan Bradley, who originally shared the service alert with BleepingComputer. Administrators are encouraged to test the single-protocol workaround in controlled environments before broader deployment and to monitor official channels for updates on a permanent resolution.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free