Windows 11 September 2026 Updates Break Always On VPN Connections
Microsoft confirms a new bug tied to the September 2026 updates for Windows 11. This time, Always On VPN connections can fail, so it’s more of an Always Off approach. Jokes aside, this bug occurs especially when the VPN profile is configured to automatically choose the protocol. Here’s what we know.
Always On VPN Stuck on "Connecting"
Microsoft informed business users about this new bug through a notification in the Microsoft 365 Admin Center (reference WI1477233). This time, the issue concerns a malfunction with the Always On VPN feature. This remote access solution, which replaced DirectAccess, now obsolete as I mentioned in a previous article, automatically establishes a tunnel to the company network as soon as the device has an Internet connection.
Following the installation of the September 2026 updates, some devices can no longer connect. According to Microsoft, the issue occurs "when the VPN is configured to automatically try another connection method if the initial connection fails", for example with automatic protocol selection between IKEv2 and SSTP.
The direct result for the user is that the VPN connection remains stuck in the "Connecting" state or keeps trying to connect in a loop without succeeding. In some cases, subsequent attempts may display the following error message: "The specified port is already in use".
According to the Redmond company, three Windows 11 versions are affected after installing the cumulative updates released on September 8, 2026. Here is a quick reminder of the associated KB numbers:
| Windows version | Update causing the issue |
|---|---|
| Windows 11 26H1 | KB5124012 |
| Windows 11 25H2 | KB5124008 |
| Windows 11 24H2 | KB5124008 |
How Can You Work Around This Bug?
Microsoft is working on a fix, but no timeline has been shared for now. In the meantime, the company recommends modifying the Always On VPN profile (via Intune, for example) to stop using automatic protocol selection in favor of a single protocol: SSTP only or IKEv2 only.
"Organizations should select the protocol based on their environment, security requirements, and deployment needs", Microsoft says.
With automatic selection enabled, here is what normally happens: Windows tries IKEv2 first, then falls back to SSTP if UDP ports 500 and 4500 are filtered out (hotel networks, public Wi-Fi, and so on). SSTP relies on HTTPS (TCP 443) and therefore passes through most firewalls. Forcing IKEv2 only may leave some roaming users without access to the company network, while SSTP only ensures better compatibility at the expense of performance.
This bug adds to an already long list as October updates are approaching... KB5124010 is already available as an optional update. Let’s hope next month is calmer.


