Microsoft KB Update (September 8, 2026) – Medium Severity

Want the full details? Click the link below!

On September 8, 2026 Microsoft released KB updates that conflict with Netwrix Threat Prevention (formerly StealthINTERCEPT) agents used by Threat Manager for AD to collect AD event data. If these KBs are applied before updating the agents, certain LDAP and Kerberos events will no longer be captured or blocked.

Netwrix recommends delaying the deployment of these KBs if the impacted event types are important to your organization. The Netwrix development and QA teams are working on updated agents compatible with these KBs and will send another notice when they are available.

:double_exclamation_mark: Important Details
If your Threat Manager for AD deployment does not use Threat Prevention (formerly StealthINTERCEPT) agents for the following activity event collection, or such events are not deemed important, you may elect to deploy the following Microsoft KBs in advance of updated Netwrix Threat Prevention agents.

No other aspect of Threat Manager operation is impacted by the September 8 KBs beyond what is described below. There is no adverse impact to domain controllers if the KBs are deployed without updating the agents.

Event Types Affected:
Kerberos, AD Replication, NTLM, RDP authentication (JumpBox cases)

Severity:
Medium

Affected Products:

  • Netwrix Threat Prevention (formerly StealthINTERCEPT) for Active Directory
  • Netwrix Threat Manager (formerly StealthDEFEND) for Active Directory

Affected Systems:

  • Windows Server 2025
  • Windows Server 2022
  • Windows Server 2016
  • Windows Server 2012 R2

Affected Microsoft KBs:

  • KB5122871
  • KB5122882
  • KB5123099
  • KB5123066

Impact:

Functional:

Windows Server 2025 / KB5122871: Kerberos events will not be collected or blocked
Log messages observed:
Couldn’t resolve I_GetASTicket

Windows Server 2022 / KB5122882: Kerberos, AD Replication events will not be collected or blocked
Log messages observed:
resolving KdcVerifyKdcRequest failed
Couldn’t resolve IDL_DRSGetNCChanges

Windows Server 2016 / KB5123099: Kerberos, AD Replication events will not be collected or blocked
Log messages observed:
Couldn’t resolve I_RenewTicket
Couldn’t resolve I_GetASTicket
Couldn’t resolve IDL_DRSGetNCChanges

Windows Server 2012 R2 / KB5123066: NTLM, RDP authentication (JumpBox cases) events will not be collected or blocked
Log messages observed:
resolving NlpLogonSamLogon (New) failed
resolving CConnectionEx::InitializeClientData (2 param) failed

Stability:
No stability impact on any server platforms or domain controllers


Need help with this update?

There are many different ways to get help with our products!

Situation Action
If you feel the product is broken and not working as intended… Contact Support
If you have a question you’d like to ask other experts… Create a discussion in the community: Threat Manager > Discussions & Questions
If you have a feature request… Let our product team know directly: Threat Manager > Ideas
If you have something cool to show… Show everyone what you built: Threat Manager > Show & Tell

What are your thoughts?

We are always happy to hear from our users on what you like, and what you hope to see in the future. Please share your thoughts below!