Windows Server 2025 Updating Issues

๐Ÿ”’ย Secure Bits ๐Ÿ’ก
๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€ ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ฒ๐—ฟ ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฑ โ€“ ๐—ฌ๐—ผ๐˜‚ ๐— ๐—ถ๐—ด๐—ต๐˜ ๐—ช๐—ฎ๐—ป๐˜ ๐˜๐—ผ ๐—ฅ๐—ฒ๐—ฎ๐—ฑ ๐—ง๐—ต๐—ถ๐˜€ ๐—•๐—ฒ๐—ณ๐—ผ๐—ฟ๐—ฒ ๐—จ๐—ฝ๐—ด๐—ฟ๐—ฎ๐—ฑ๐—ถ๐—ป๐—ด

Are you planning to upgrade your infrastructure toย ๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€ ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ฒ๐—ฟ ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฑ?
Wellโ€ฆ maybe hold on just a bit longer.

Over the last 4โ€“5 months, Iโ€™ve builtย four full environmentsย running only Windows Server 2025. There have been some issues of course โ€” like needing to ๐—ฟ๐—ฒ๐˜€๐˜๐—ฎ๐—ฟ๐˜ ๐˜๐—ต๐—ฒ ๐—ป๐—ฒ๐˜๐˜„๐—ผ๐—ฟ๐—ธ ๐—ฎ๐—ฑ๐—ฎ๐—ฝ๐˜๐—ฒ๐—ฟ ๐—ฎ๐—ณ๐˜๐—ฒ๐—ฟ ๐—ฒ๐—ฎ๐—ฐ๐—ต ๐—ฏ๐—ผ๐—ผ๐˜ on DCs, or problems withย Kerberos encryption keys.

But one problem stands out:ย ๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€ ๐—จ๐—ฝ๐—ฑ๐—ฎ๐˜๐—ฒ ๐—ฏ๐—ฒ๐—ต๐—ฎ๐˜ƒ๐—ถ๐—ผ๐—ฟ ๐—ถ๐˜€ ๐—ฐ๐—ผ๐—บ๐—ฝ๐—น๐—ฒ๐˜๐—ฒ๐—น๐˜† ๐˜‚๐—ป๐—ฟ๐—ฒ๐—น๐—ถ๐—ฎ๐—ฏ๐—น๐—ฒ.

๐ŸŽฏ ๐—ช๐—ต๐—ฒ๐—ป ๐˜‚๐˜€๐—ถ๐—ป๐—ด ๐—ช๐—ฆ๐—จ๐—ฆ, you usually control updates with GPOs (example):
โ–ช๏ธ Install every day at 6 PM
โ–ช๏ธ Download and schedule the install
โ–ช๏ธ Force restart (disable active hours)

This usually works fineโ€ฆ
๐—ก๐—ผ๐˜ ๐—ผ๐—ป ๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€ ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ฒ๐—ฟ ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฑ.

Hereโ€™s what Iโ€™ve seenย ๐—ฎ๐—ด๐—ฎ๐—ถ๐—ป ๐—ฎ๐—ป๐—ฑ ๐—ฎ๐—ด๐—ฎ๐—ถ๐—ป:
๐Ÿ”บ Some servers install updates, butย donโ€™t restart
๐Ÿ”บ Othersย restart at random times
๐Ÿ”บ Someย donโ€™t install anything at all
๐Ÿ”บ And occasionally โ€” theyย do follow the GPOs

โš ๏ธย ๐—ง๐—ต๐—ฒ ๐—ฟ๐—ฒ๐˜€๐˜‚๐—น๐˜?
๐—ง๐—ผ๐˜๐—ฎ๐—น ๐˜‚๐—ป๐—ฝ๐—ฟ๐—ฒ๐—ฑ๐—ถ๐—ฐ๐˜๐—ฎ๐—ฏ๐—ถ๐—น๐—ถ๐˜๐˜†ย โ€” and thatโ€™s a huge problem in enterprise environments. When you rely on GPO-controlled updates to patch hundreds of servers, this behavior breaks the entire process.

Iโ€™ve had to deal with this in customer environments, and I can tell you:
๐—œ๐˜โ€™๐˜€ ๐—ฎ ๐—ป๐—ถ๐—ด๐—ต๐˜๐—บ๐—ฎ๐—ฟ๐—ฒย to manage inconsistent patching across your entire infrastructure.

๐Ÿงช This behavior is reproducible โ€” Iโ€™ve included screenshots from my own demo (one of the better results actually…), but you can test it yourself easily.

So if youโ€™re considering a full upgrade toย ๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€ ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ฒ๐—ฟ ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฑ, my recommendation:
๐Ÿ’กย ๐—ช๐—ฎ๐—ถ๐˜ ๐—ฎ ๐—ณ๐—ฒ๐˜„ ๐—บ๐—ผ๐—ฟ๐—ฒ ๐—บ๐—ผ๐—ป๐˜๐—ต๐˜€.
Let these issues settle down first.

UPDATE: We cooperated with Microsoft to fix this issues in 12/2025 – it is fixed now.

I also ran into a weird Kerberos encryption issue, but couldnโ€™t reproduce it again โ€” so that mystery remains for nowโ€ฆ

๐—›๐—ฎ๐˜ƒ๐—ฒ ๐˜†๐—ผ๐˜‚ ๐—ต๐—ฎ๐—ฑ ๐—ฎ๐—ป๐˜† ๐—ถ๐˜€๐˜€๐˜‚๐—ฒ๐˜€ ๐˜„๐—ถ๐˜๐—ต ๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€ ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ฒ๐—ฟ ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฑ?