Windows 11 24H2 Breaks VDI Authentication: How Cross-Domain Apps Lock Your Horizon Account (Event ID 4648)
Windows 11 24H2 Breaks VDI Authentication: How Cross-Domain Apps Lock Your Horizon Account (Event ID 4648) Published: 2026 | Category: VDI Infrastructure / Windows Authentication The Short Version After upgrading to Windows 11 24H2, users in environments where a VDI domain and a separate application domain share the same account username begin experiencing unexpected VDI account lockouts. The trigger is any application — Outlook, internal messengers, network-mapped drives, SSO-integrated systems — that attempts to authenticate against its own domain at runtime. Windows 11 24H2 changed how it handles explicit credential logon internally, causing the application's authentication request to bleed into the VDI domain. The result: Event ID 4648, failed logon attempts against the VDI domain, and account lockout. Microsoft has not released a fix as of 25H2. 1. The Environment Where This Breaks This issue surfaces specifically in environments with the following conditions: VM...