October 26, 2021 non-security update (KB5006745) and KIR on standalone machines

Bill Nolan 1 Reputation point
2021-12-07T21:50:46.583+00:00

My team and i run Win10 ver 21H1 running on virtual machines within VirtualBox. The Oct 2021 patches came along and broke our RDP access using PIV-I authentication. As per, https://support.microsoft.com/en-us/topic/october-26-2021-non-security-update-kb5006745-572c595a-aff6-4976-a961-07aafb257973, the KIR was suppose to fix the issue. As of today, we are still broken even after the November 2021 patches were applied. The KIR GPO pushed by our enterprise to our host machines fixed our host machines. Our VM's are still not able to RDP via PIV-I.

Is there a way to tell the KIR ran on our VM's? My understanding is that the KIR process will run in the background automatically on standalone machines?

Thank you

Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Limitless Technology 39,931 Reputation points
    2021-12-10T08:52:25.59+00:00

    Hi there,

    You can also force KIR by using group policy.

    For non-enterprise customers, the Windows Update process applies the KIR automatically. No user action is required.

    For enterprise customers, Microsoft provides a policy definition MSI file. Enterprise customers can propagate the KIR to managed systems by using the enterprise Group Policy infrastructure.

    A KIR policy definition has a limited lifespan (a few months, at most). After Microsoft publishes an amended update to address the original issue, the KIR is no longer necessary. The policy definition can then be removed from the Group Policy infrastructure.

    Using Group Policy to apply a KIR to a single device
    https://learn.microsoft.com/en-us/troubleshoot/windows-client/group-policy/use-group-policy-to-deploy-known-issue-rollback

    ------------------------------------------------------------------------------------------------------------------------------------------------------------

    --If the reply is helpful, please Upvote and Accept it as an answer--

    0 comments No comments

  2. Bill Nolan 1 Reputation point
    2021-12-13T16:08:11.723+00:00

    Thank you for your reply. That was my understanding of how the KIR processed worked. Unfortunately on our individual machines our RDP access is still broken. So I am not sure if the KIR fix was implemented or was implemented but is not working. Is there a way to verify our individual machines received the KIR fix? Or to find out what was included in the KIR to attempt a fix ourselves?

    So far the November 2021 patches have not corrected our situation.

    Thank you

    0 comments No comments

  3. Bill Nolan 1 Reputation point
    2021-12-17T02:10:11.4+00:00

    Appears that the December's MS security patches have resolved my issue. Service Stack 10.0.1904.1371 and KB5008212 were installed the other day. Today I can RDP using PIV-I again.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.