News report
Microsoft Confirms Windows 11 Always On VPN Connection Issue
Microsoft says September 2026 Windows 11 updates can leave some Always On VPN connections stuck connecting when automatic protocol fallback is enabled.
On this page
September Windows updates can break a specific Always On VPN configuration
Microsoft has notified administrators of an Always On VPN connection problem affecting Windows 11 systems after the September 2026 security updates. The issue can occur when a VPN profile is configured to automatically try another connection method after the first method fails, such as automatic selection between IKEv2 and SSTP.
Affected connections can remain stuck in a “Connecting” state or repeatedly retry without completing. Later attempts can also report that the specified port is already in use. Microsoft lists Windows 11 24H2 and 25H2 with KB5124008 as affected, along with Windows 11 26H1 systems using KB5124012.
| Windows version | Originating update | Affected configuration |
|---|---|---|
| Windows 11 24H2 | KB5124008 | Always On VPN using automatic protocol selection/fallback |
| Windows 11 25H2 | KB5124008 | Always On VPN using automatic protocol selection/fallback |
| Windows 11 26H1 | KB5124012 | Always On VPN using automatic protocol selection/fallback |
Microsoft’s workaround is to stop using automatic protocol selection
Microsoft’s temporary mitigation is an administrative profile change rather than removal of the September security update. Administrators can configure the Always On VPN profile to use one protocol only — either SSTP or IKEv2 — instead of automatically switching between them.
Which protocol is appropriate depends on the organization’s VPN infrastructure, security requirements and deployment configuration. That makes this primarily an enterprise-management issue: users on managed devices should not independently rewrite a corporate VPN profile unless their administrator instructs them to do so.
Why automatic fallback can make this regression disruptive
Always On VPN is designed to establish managed remote connectivity in the background, including on domain-joined and Microsoft Entra ID-joined devices. A connection loop therefore has a different operational impact from a user manually launching a VPN application: access to internal services can fail before the user has a useful opportunity to troubleshoot the tunnel.
The workaround also narrows a profile that was deliberately configured with more than one connection method. Administrators should therefore treat the single-protocol setting as a mitigation and validate it against their own VPN gateways rather than assuming SSTP or IKEv2 is interchangeable in every environment.
A permanent fix is still pending
Microsoft says it is working on a resolution. Until that arrives, the concrete supported mitigation is to select a single protocol in the affected Always On VPN profile.
The September Windows servicing cycle has produced several separate regressions, but they should not be conflated. The File History backup issue, domain trust failures, Remote Desktop problems and this Always On VPN failure have different symptoms and mitigations. For VPN troubleshooting, the useful identifying signal is an affected September update together with an Always On VPN profile using automatic protocol selection and the connection-loop or port-in-use symptoms Microsoft describes.
Sources
Primary and technical sources
These sources support the reporting and analysis above. Current stories are updated when later evidence materially changes the facts.
01 Microsoft Learn
Always On VPN overview02 BleepingComputer
Microsoft: September Windows updates break Always On VPN connections03 Microsoft Support
KB5124008 Windows 11 September 2026 security update04 Microsoft Support
KB5124012 Windows 11 September 2026 security update