Hello Seif Osman,
Windows cumulative updates regularly introduce security enforcements across the core networking stack, such as Schannel cipher adjustments, IPsec modifications, or strict certificate validation in RasMan. When third-party SaaS VPN clients use legacy virtual miniport drivers or deprecated cryptographic suites, the connection process fails or drops immediately after the host initializes the updated networking components.
To maintain production stability while preserving baseline protection, you should defer KB5124008 and KB5126052 temporarily using your endpoint management policy or WSUS targeting group. Concurrently, reach out to your SaaS VPN vendor to acquire their latest client build compiled for the updated Windows kernel networking binaries, or verify if their tunnel protocol requires an updated intermediate CA certificate or updated tap adapter drivers.
Please also examine the Event Viewer under Applications and Services Logs, Microsoft, Windows, RemoteAccess-RemoteAccessServer or the SaaS VPN diagnostic logs to pinpoint the exact failure code. If this guidance helps clarify the path forward and manage the rollout, please accept the answer.
Tracy Le.