Microsoft Confirms Windows Server Reboot Loops After April Patches
Key Takeaways Microsoft has confirmed that the April 2026 cumulative update, KB5082063, is causing Windows Server 2025 domain controllers to enter persistent reboot loops. The issue primarily impacts...
Key Takeaways
- Microsoft has confirmed that the April 2026 cumulative update, KB5082063, is causing Windows Server 2025 domain controllers to enter persistent reboot loops.
- The issue primarily impacts domain controllers, particularly non-Global Catalog servers, after installing update KB5082063. Some systems are also failing to install the update with error code 0x800F0983.
- Affected servers can be restored by booting into Directory Services Restore Mode (DSRM) and uninstalling the problematic update.
- Microsoft has not yet released a formal fix or workaround, advising administrators to pause deployment on domain controllers and monitor official channels.
Microsoft has officially acknowledged a critical problem affecting Windows Server 2025 domain controllers. Following the installation of the April 2026 Patch Tuesday cumulative update, KB5082063, affected servers are reportedly entering continuous reboot cycles.
Table Of Content
The update, identified as KB5082063 (OS Build 26100.32690), was distributed on April 14, 2026. It represents the standard monthly security release for Windows Server 2025, incorporating the latest security fixes along with non-security enhancements from the optional preview released in March.
However, Microsoft’s official release notes, updated on April 16, 2026, now include a “known issue” warning. This states that “Domain controllers might restart repeatedly after installing this update,” directly addressing the reboot loop predicament for IT professionals managing enterprise environments.
Compounding the problem, a subset of Windows Server 2025 installations is entirely failing to apply the update, generating error code 0x800F0983 during the deployment process.
Microsoft confirmed it is actively collecting diagnostic data related to these installation failures, noting that “a limited number of affected servers might experience an installation failure accompanied by the error code 800F0983.”
Reports from system administrators on Reddit’s Patch Tuesday discussion threads corroborate Microsoft’s advisory. One administrator specifically mentioned a domain controller becoming “stuck in a reboot loop” after deploying KB5082063.
Administrators have found that booting into Directory Services Restore Mode (DSRM) remains functional, and uninstalling the update successfully resolves the reboot loop, allowing the affected domain controller to restart normally. This evidence strongly suggests the update itself is the root cause, particularly for non-Global Catalog (non-GC) domain controllers within complex Active Directory infrastructures.
BitLocker Recovery Triggered
In a separate alert, Microsoft cautioned that devices configured with non-standard BitLocker Group Policy settings might be forced into BitLocker recovery mode subsequent to installing KB5082063. This known issue was added to the changelog on April 14, 2026.
While this situation is unlikely to impact individual home users, enterprise-managed servers utilizing specific BitLocker policies could experience disruptions, necessitating the manual input of recovery keys to regain access.
What’s Fixed in KB5082063
Despite the current challenges, the cumulative update KB5082063 introduces several important security and stability enhancements across various Windows components:
- Kerberos protocol — Modifies the default
DefaultDomainSupportedEncTypesvalue to AES-SHA1 for accounts without explicit Active Directory encryption type definitions, addressing CVE-2026-20833. - Secure Boot — Incorporates high-confidence device targeting data for the phased rollout of new Secure Boot certificates, aiming to minimize BitLocker recovery risks during transitions.
- Remote Desktop — Enhances phishing protection by displaying all requested connection settings before establishing a connection to a malicious .rdp file.
- Windows Deployment Services (WDS) — Disables the “Hands-Free Deployment” feature by default, bolstering defenses against CVE-2026-0386.
- SMB over QUIC — Improves compression reliability, thereby reducing timeouts in hybrid and cloud-connected environments.
- PowerShell — Corrects an issue with the
Set-GPPrefRegistryValuecmdlet to ensure all imported registry values are properly preserved.
Microsoft has not yet released a formal workaround or provided a timeline for a fix addressing the reboot loop. An investigation into the 0x800F0983 installation failure is also ongoing.
The servicing stack update KB5082062 (Build 26100.32692) is bundled with this release to maintain the integrity of the update infrastructure.
What You Should Do
- Pause Deployment: Administrators are strongly advised to pause the deployment of KB5082063 on Windows Server 2025 domain controllers until Microsoft releases an official fix.
- Monitor Health Dashboard: Regularly check the Windows Server 2025 release health dashboard for real-time updates and official guidance from Microsoft.
- Prepare for BitLocker: Ensure that all BitLocker recovery keys are securely backed up and accessible offline, in case of unexpected BitLocker recovery mode activation.
- Backup Systems: As a general best practice, ensure recent backups of all domain controllers are available before applying any significant updates.
- Test in Staging: If possible, test new updates in a controlled staging environment before broad deployment to production systems.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.