I have found that this service was disabled before the December update, for some reason it has gone to automatic and cannot be started, maybe this behavior is normal if you are not using this feature. After the January security patch the service still does not start, I think microsoft should report this problem.
Windows Server 2025 | Kerberos Local Key Distribution Center (LocalKDC) service fails to start

Hello,
After installing the latest cumulative update for December, KB5048667, on my Windows Server 2025 system, the Kerberos Local Key Distribution Center (LocalKDC) service fails to start due to the following generic exception:
- "Some services stop automatically if they are not in use by other services or programs."
This issue appears to be related to the recent changes regarding NTLM deprecation and the optional shift to Kerberos for local user authentication.
After uninstalling the cumulative update for December, the service gets stuck at START_PENDING and never starts, that gives me some chills.
Cannot find any events regarding the Local KDC service, even after enabling logging for Microsoft-Windows-Kerberos-Local-Key-Distribution-Center/Operational.
Given the importance of these changes, I’d like to report this as a potential issue with the latest GA implementation.
Is this a known issue with KB5048667?
3 answers
Sort by: Most helpful
-
-
Randy Smith 0 Reputation points
2025-03-07T16:38:49.4633333+00:00 I opened a case with Microsoft on this. The answer I received did not make me feel warm and fuzzy, but I include it below. They could not give a clear answer on when this service will start working, what will happen if it is left disabled, or anything else of that nature. Without further ado...
Incident Description:
Local KDC service failing to start on Windows Server 2025 after December 2024 updates.
Expected Outcome:
Understand why the service is failing to start and what actions are needed to resolve the issue.
Environment:
Company had implemented around 7 Windows Servers 2025.
Company already promoted at least one of the servers as Domain Controllers and the goal is to continue refreshing DCs with the latest version of Windows Server.
Company discovered that other customers are also facing the same issue with Local KDC service as published in the link (link is to this thread).
Troubleshooting
MS Support performed internal research and discovered similar incidents reported.
As per Product Group analysis from previous cases, the local KDC feature is currently not in General Availability (GA), even though the service may be shown in OS.
Microsoft Product Group is actively working on this feature. Once it is ready for public preview, there will be more communication and updates provided via public article.
MS Support recommendation:
- Disable the service on all your Windows Server 2025 servers, as this is a new feature that shouldn’t impact applications or other services.
- Continue applying Updates to your Windows Servers.
-
Hania Lian - MSFT 21,906 Reputation points Microsoft External Staff
2024-12-24T02:11:10.0333333+00:00 Hello,
Based on the information available, there are no officially documented issues specifically related to the Kerberos Local Key Distribution Center (LocalKDC) service in the KB5048667 update
You can send feedback to Microsoft by referring to this link:
Best Regards,
Hania Lian
============================================
If the Answer is helpful, please click "Accept Answer" and upvote it.