I'd read on here about CVE-2020-1472 that was deployed with August update.
https://support.microsoft.com/en-us/help/4557222/how-to-manage-the-changes-in-netlogon-secure-channel-connections-assoc
I have an Event ID 5827 for a Windows device. I thought you said Windows is not impacted?
By default, supported versions of Windows that have been fully updated should not be using vulnerable Netlogon secure channel connections. If an event ID 5827 is logged in the system event log for a Windows device:
Confirm that the device is running a supported versions of Windows.
Ensure the device is fully updated from Windows Update.
Check to ensure that Domain member: Digitally encrypt or sign secure channel data (always) is set to Enabled in a GPO linked to the OU for all your DCs, such as the default domain controllers GPO.
--please don't forget to Accept as answer if the reply is helpful--