[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f9zoTZ8zfGHTyeD0onzktTVWE3I9JJ9kH-kqxb5XVpE0":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"54d2afb1-be99-4c96-b620-adf32bc3620c","windows-security-update-breaks-always-on-vpn-protocol-misconfiguration-at-root","0fa09696-1671-4491-b76e-0a70c7792dd3","Windows Security Update Breaks Always On VPN — Protocol Misconfiguration at Root","Microsoft's September 2026 Windows 11 security updates introduced a regression that disrupts Always On VPN connections configured for automatic protocol selection, specifically when switching between IKEv2 and SSTP. This highlights the inherent risk of deploying security patches without adequate pre-production testing, particularly for critical remote access infrastructure. Organizations relying on Always On VPN for secure remote workforce connectivity may find employees suddenly unable to connect, creating both productivity and security gaps. The fact that a manual workaround exists underscores the importance of having documented fallback procedures before patch deployment. Patch management must account not only for vulnerability remediation but also for functional regression in security-critical services.","**Immediate actions:**\n- Apply the documented workaround by manually setting the VPN profile to a single protocol (SSTP or IKEv2) until Microsoft releases a fix.\n- Audit all Always On VPN profiles across the environment to identify configurations using automatic protocol selection.\n- Communicate the issue and workaround steps to IT helpdesk and end users experiencing connectivity failures.\n\n**Long-term improvements:**\n- Establish a phased patch deployment pipeline (Dev → Staging → Pilot → Production) that includes testing of VPN and remote access services before broad rollout.\n- Maintain documented rollback procedures for every patch cycle, enabling rapid reversion if critical services are disrupted.\n- Implement a configuration baseline for VPN profiles using a policy management tool (e.g., Intune, Group Policy) to enable rapid, consistent remediation.\n\n**Detection measures:**\n- Configure monitoring and alerting on VPN gateway connection failure rates to detect patch-induced regressions immediately after update deployment.\n- Subscribe to Microsoft's Windows Health Dashboard and release notes to receive advance warning of known issues before patches reach production.\n- Track VPN service availability as a key metric in post-patch change review processes.",[12,13,14,15,16,17,18,19,20],"CIS Control 7.3 – Perform Automated Operating System Patch Management","CIS Control 7.4 – Perform Automated Application Patch Management","CIS Control 4.1 – Establish and Maintain a Secure Configuration Process","NIST SP 800-40 Rev. 4 – Guide to Enterprise Patch Management Planning","NIST CM-6 – Configuration Settings","NIST CM-3 – Configuration Change Control","NIST IR-4 – Incident Handling","ITIL Change Management – Standard and Emergency Change Procedures","NIST SP 800-113 – Guide to SSL VPNs","published","2026-09-23T12:21:10.972342+00:00","2026-09-23T12:21:10.893+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fmicrosoft\u002Fmicrosoft-september-2026-windows-updates-break-always-on-vpn-connections\u002F","microsoft-september-windows-updates-break-always-on-vpn-connections-5cd3f2","Microsoft: September Windows updates break Always On VPN connections",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"182e11d5-57c4-444e-8ec8-4682ad60261b","Incident Response","incident-response","Slow detection, poor containment, missing playbooks","#14b8a6",{"id":36,"name":37,"slug":38,"description":39,"color":40},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":42,"name":43,"slug":44,"description":45,"color":46},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]