Want the full details? Click the link below!
On July 14, 2026, Microsoft released KB updates that conflict with Netwrix Threat Prevention (formerly StealthINTERCEPT) agents used by Threat Manager for AD to collect AD event data. If these KBs are applied before updating the agents, certain NTLM Authentication and Kerberos Authentication events will no longer be captured or blocked.
Netwrix recommends delaying the deployment of these KBs if the impacted event types are important to your organization. The Netwrix development and QA teams are working on updated agents compatible with these KBs and will send another notice when they are available.
Important Details
If your Threat Manager for AD deployment does not use Threat Prevention (formerly StealthINTERCEPT) agents for the following activity event collection, or such events are not deemed important, you may elect to deploy the following Microsoft KBs in advance of updated Netwrix Threat Prevention agents.
No other aspect of Threat Manager operation is impacted by the July 14, 2026 KBs beyond what is described below. There is no adverse impact to domain controllers if the KBs are deployed without updating the agents.
Event Types Affected:
- Windows Server 2025 – Capture or block Kerberos Authentication activity
- Windows Server 2022 – Capture or block NTLM Authentication activity and Kerberos Authentication activity
- Windows Server 2019 – Capture or block NTLM Authentication activity and Kerberos Authentication activity
- Windows Server 2016 – Capture or block Kerberos Authentication activity
Severity:
MEDIUM
Affected Products:
- Netwrix Threat Prevention (formerly StealthINTERCEPT) for Active Directory
- Netwrix Threat Manager (formerly StealthDEFEND) for Active Directory
Affected Systems:
- Windows Server 2025 (for Active Directory)
- Windows Server 2022 (for Active Directory)
- Windows Server 2019 (for Active Directory)
- Windows Server 2016 (for Active Directory)
Affected Microsoft KBs:
- Windows Server 2025 – KB5099536
- Windows Server 2022 – KB5099540
- Windows Server 2019 – KB5099538
- Windows Server 2016 – KB5099535
Impact:
Functional:
Windows Server 2025 – KB5099536
- Netwrix Threat Prevention (formerly StealthINTERCEPT) agents will lose the ability to capture or block Kerberos authentication activity.
- Log: Couldn’t resolve I_GetASTicket
- Log: Couldn’t resolve SslTryS4U2Self
Windows Server 2022 – KB5099540
- Netwrix Threat Prevention (formerly StealthINTERCEPT) agents will lose the ability to capture or block NTLM and Kerberos authentication activity.
- Log: Couldn’t resolve NlpLogonSamLogon
- Log: Couldn’t resolve NlpUserValidate
- Log: Couldn’t resolve SslTryS4U2Self
Windows Server 2019 – KB5099538
- Netwrix Threat Prevention (formerly StealthINTERCEPT) agents will lose the ability to capture or block NTLM and Kerberos authentication activity.
- Log: Couldn’t resolve NlpLogonSamLogon
- Log: Couldn’t resolve NlpUserValidate
- Log: resolving KdcVerifyKdcRequest failed
- Log: Couldn’t resolve SslTryS4U2Self
Windows Server 2016 – KB5099535
- Netwrix Threat Prevention (formerly StealthINTERCEPT) agents will lose the ability to capture or block Kerberos authentication activity.
- Log: Couldn’t resolve SslTryS4U2Self
Stability:
No stability impact on any server platforms or domain controllers
What are your thoughts?
We are always happy to hear from our users on what you like, and what you hope to see in the future. Please, share your thoughts below!
