๐ย Secure Bits ๐ก
๐ช๐ถ๐ป๐ฑ๐ผ๐๐ ๐ฆ๐ฒ๐ฟ๐๐ฒ๐ฟ ๐ฎ๐ฌ๐ฎ๐ฑ โ ๐ฌ๐ผ๐ ๐ ๐ถ๐ด๐ต๐ ๐ช๐ฎ๐ป๐ ๐๐ผ ๐ฅ๐ฒ๐ฎ๐ฑ ๐ง๐ต๐ถ๐ ๐๐ฒ๐ณ๐ผ๐ฟ๐ฒ ๐จ๐ฝ๐ด๐ฟ๐ฎ๐ฑ๐ถ๐ป๐ด
Are you planning to upgrade your infrastructure toย ๐ช๐ถ๐ป๐ฑ๐ผ๐๐ ๐ฆ๐ฒ๐ฟ๐๐ฒ๐ฟ ๐ฎ๐ฌ๐ฎ๐ฑ?
Wellโฆ maybe hold on just a bit longer.
Over the last 4โ5 months, Iโve builtย four full environmentsย running only Windows Server 2025. There have been some issues of course โ like needing to ๐ฟ๐ฒ๐๐๐ฎ๐ฟ๐ ๐๐ต๐ฒ ๐ป๐ฒ๐๐๐ผ๐ฟ๐ธ ๐ฎ๐ฑ๐ฎ๐ฝ๐๐ฒ๐ฟ ๐ฎ๐ณ๐๐ฒ๐ฟ ๐ฒ๐ฎ๐ฐ๐ต ๐ฏ๐ผ๐ผ๐ on DCs, or problems withย Kerberos encryption keys.
But one problem stands out:ย ๐ช๐ถ๐ป๐ฑ๐ผ๐๐ ๐จ๐ฝ๐ฑ๐ฎ๐๐ฒ ๐ฏ๐ฒ๐ต๐ฎ๐๐ถ๐ผ๐ฟ ๐ถ๐ ๐ฐ๐ผ๐บ๐ฝ๐น๐ฒ๐๐ฒ๐น๐ ๐๐ป๐ฟ๐ฒ๐น๐ถ๐ฎ๐ฏ๐น๐ฒ.
๐ฏ ๐ช๐ต๐ฒ๐ป ๐๐๐ถ๐ป๐ด ๐ช๐ฆ๐จ๐ฆ, you usually control updates with GPOs (example):
โช๏ธ Install every day at 6 PM
โช๏ธ Download and schedule the install
โช๏ธ Force restart (disable active hours)
This usually works fineโฆ
๐ก๐ผ๐ ๐ผ๐ป ๐ช๐ถ๐ป๐ฑ๐ผ๐๐ ๐ฆ๐ฒ๐ฟ๐๐ฒ๐ฟ ๐ฎ๐ฌ๐ฎ๐ฑ.
Hereโs what Iโve seenย ๐ฎ๐ด๐ฎ๐ถ๐ป ๐ฎ๐ป๐ฑ ๐ฎ๐ด๐ฎ๐ถ๐ป:
๐บ Some servers install updates, butย donโt restart
๐บ Othersย restart at random times
๐บ Someย donโt install anything at all
๐บ And occasionally โ theyย do follow the GPOs
โ ๏ธย ๐ง๐ต๐ฒ ๐ฟ๐ฒ๐๐๐น๐?
๐ง๐ผ๐๐ฎ๐น ๐๐ป๐ฝ๐ฟ๐ฒ๐ฑ๐ถ๐ฐ๐๐ฎ๐ฏ๐ถ๐น๐ถ๐๐ย โ and thatโs a huge problem in enterprise environments. When you rely on GPO-controlled updates to patch hundreds of servers, this behavior breaks the entire process.
Iโve had to deal with this in customer environments, and I can tell you:
๐๐โ๐ ๐ฎ ๐ป๐ถ๐ด๐ต๐๐บ๐ฎ๐ฟ๐ฒย to manage inconsistent patching across your entire infrastructure.
๐งช This behavior is reproducible โ Iโve included screenshots from my own demo (one of the better results actually…), but you can test it yourself easily.
So if youโre considering a full upgrade toย ๐ช๐ถ๐ป๐ฑ๐ผ๐๐ ๐ฆ๐ฒ๐ฟ๐๐ฒ๐ฟ ๐ฎ๐ฌ๐ฎ๐ฑ, my recommendation:
๐กย ๐ช๐ฎ๐ถ๐ ๐ฎ ๐ณ๐ฒ๐ ๐บ๐ผ๐ฟ๐ฒ ๐บ๐ผ๐ป๐๐ต๐.
Let these issues settle down first.
UPDATE: We cooperated with Microsoft to fix this issues in 12/2025 – it is fixed now.
I also ran into a weird Kerberos encryption issue, but couldnโt reproduce it again โ so that mystery remains for nowโฆ
๐๐ฎ๐๐ฒ ๐๐ผ๐ ๐ต๐ฎ๐ฑ ๐ฎ๐ป๐ ๐ถ๐๐๐๐ฒ๐ ๐๐ถ๐๐ต ๐ช๐ถ๐ป๐ฑ๐ผ๐๐ ๐ฆ๐ฒ๐ฟ๐๐ฒ๐ฟ ๐ฎ๐ฌ๐ฎ๐ฑ?
