Microsoft confirms recent Windows security update breaks VPNs, no fix yet

Windows 10 Settings
(Image credit: Shutterstock)

Bad news for those of us quick to click the "update" button: Microsoft has confirmed that the suite of April security updates for Windows has broken the functionality of VPN services on the operating system in its release health dashboard.

Microsoft describes the issue as "Windows devices might face VPN connection failures" on the new updates — the wording makes it unclear whether the bug effects all users or only some. Microsoft has not given any updates on when the bug will be fixed or what the reason for it is, but we can rest assured it will solve the problem "in an upcoming release." The bug affects security updates extended to Windows 10 and 11 releases and various Windows Server releases, as seen below:

Latest Videos FromTom's Hardware
Sunny Grimm
Contributing Writer

Sunny Grimm is a contributing writer for Tom's Hardware. He has been building and breaking computers since 2017, serving as the resident youngster at Tom's. From APUs to RGB, Sunny has a handle on all the latest tech news.

  • JamesJones44
    I guess that is one way to ensure people come into the office.
    Reply
  • brandonjclark
    JamesJones44 said:
    I guess that is one way to ensure people come into the office.
    Zero-Trust security means no device is automatically trusted.

    There are many enterprises which require VPN even when internal to an office.
    Reply
  • JamesJones44
    brandonjclark said:
    Zero-Trust security means no device is automatically trusted.

    There are many enterprises which require VPN even when internal to an office.
    This can be done with device filtering at the network layer and/or required provisioning software installed (MDM for example). None of the fortune 500 companies I've ever worked at required logging into VPN on site, they simply didn't allow a device to connect to the network if it was unregistered. Several of the companies I worked for wouldn't allow an unregistered device to work with VPN either.
    Reply
  • Alvar "Miles" Udell
    Bad news for those of us quick to click the "update" button

    Of which there shouldn't be any except for those on the insider channel. Everyone else should be using the Pro version and delay updates for 30 days and upgrades for at least 90. For corporate users, IT should issue their own updates only after vetting them.
    Reply
  • RaiderB0t
    Its clearly a case of "might be some but certainly not all" as I can see the patch KB503693 installed on my corporate Win11 lappy. I am currently connected at home via VPN right now without any issues, so unless there is some problem, there is no need to go remove it. If its an enterprise device you probably wouldn't have perm's to remove it anyway. My .02cnts
    Reply