Set - MachineIdentityIsolation
Summary
Use this script to identify and remediate domain trust failures caused by Machine Identity Isolation (MII) enforcement after the September 2026 Windows 11 updates. It never restarts the device.
Affected devices can show: The trust relationship between this workstation and the primary domain failed.
Sample Run

Dependencies
Parameters
| Parameter | Required | Default | Type | Description |
|---|---|---|---|---|
Action | No | Status | String | Choose Status, Disable, or Repair. |
domainUser | For Repair | PSCredential | Domain User name used to reset the computer account secure channel. | |
domainPassword | For Repair | PSCredential | Domain password used to reset the computer account secure channel. |
Implementation
-
Export the agent procedure from ProVal's VSA RMM instance.
Name:Set - MachineIdentityIsolationThe export will download the necessary XML file.
-
Import this XML file into the partner's VSA RMM instance.
-
Export the
Set-MachineIdentityIsolation-KI.ps1from the ProVal's Internal VSA. This is also placed under the below path:
Manage Files>Shared Files>PVAL>Set-MachineIdentityIsolation-KI.ps1
- Map the
Set-MachineIdentityIsolation-KI.ps1into the28thstep of the script in the client's environment.
Output
Agent Procedure Log C:\ProgramData_Automation\Script\Set-MachineIdentityIsolation\Set-MachineIdentityIsolation-log.txt
Changelog
2026-09-22
- Initial version of the document