Microsoft: September Windows updates break Always On VPN connections

Microsoft has notified IT administrators that users may experience Always On VPN connection issues after installing the September 2026 Windows 11 security updates.

Always On VPN is a remote access solution that replaces the legacy DirectAccess technology and works with domain-joined, non-domain-joined, and Microsoft Entra ID-joined devices.

It is available on Windows 10, Windows 11, and Windows Server, and it runs seamlessly in the background, establishing a secure tunnel back to the corporate network automatically whenever a device connects to the internet.

Always On VPN also lets administrators define which apps and services can use the VPN connection, and it supports modern VPN protocols like IKEv2 and SSTP, plus multi-factor authentication (MFA) for better security.

In a service alert seen by BleepingComputer and shared by Microsoft MVP Susan Bradley, Microsoft says that affected customers may experience issues when their systems attempt to connect to their organization’s enterprise network via Always On VPN.

“This issue can occur when the VPN is configured to automatically try another connection method if the initial connection fails (for example, when using automatic protocol selection with IKEv2 and SSTP),” Microsoft said.

“Affected VPN connections might remain in a ‘Connecting’ state or repeatedly attempt to connect without succeeding. Subsequent connection attempts might also display the error: ‘The specified port is already in use.'”

While Microsoft is still working on a permanent solution, it shared a temporary fix for affected customers that requires them to choose one of the two VPN tunneling protocols to work around the issue.

“IT administrators can mitigate this issue by changing the Always On VPN profile from automatic protocol selection to a single protocol, either SSTP only or IKEv2 only, depending on their environment and configuration,” it said.

“Organizations should select the protocol based on their environment, security, and deployment requirements.”

This month’s cumulative updates have been linked to multiple other issues affecting both home and enterprise Windows users.

One week ago, Microsoft released emergency updates to fix Hyper-V issues, Remote Desktop Services failures, and USB audio problems also triggered by the September 2026 updates.

It also shared a temporary workaround for a separate issue that blocks some Windows 11 users from logging in with valid domain credentials and announced that it is working to address another bug that may cause the built-in File History backup feature in Windows to stop working.

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Microsoft: September updates break File History backup feature

Microsoft fixes bug behind ‘Defender Antivirus is turned off’ alerts

Microsoft shares workaround for Windows domain login issues

Microsoft: September updates cause RDS failures on Windows Server

Microsoft: September updates break audio on some Windows PCs

Researchers escape OpenAI Codex sandbox to run commands on host

Malicious npm packages evade install-script defenses at runtime

Microsoft reminds admins to migrate Entra ID users to passkeys

Build cyber resilience with Wazuh: The open-source SIEM & XDR for proactive protection

Overdue a password health-check? Audit your Active Directory for free

Overdue a password health-check? Audit your Active Directory for free

Find out how long recovery really takes — and what it costs. Read the 2025 BCDR Report.

Automate Onboarding and Access Reviews with No-Code IGA: See how it works

Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure

Read our posting guidelinese to learn what content is prohibited.