Loading...
Loading...
When attempting to perform a restore using the Veeam Recovery Media, the restore fails while establishing the connection to the local VeeamAgent.exe process, and the following error occurs: The Local Security Authority cannot be contacted Because the failure occurs before a recovery operation can begin, it prevents restoring from any backup location, including local storage, a network shared folder or Veeam backup repository, and cloud repositories.
This issue occurs due to a regression introduced by the Microsoft June 2026 security update for Windows 11 and Windows Server 2025. The update changed the behavior of the Windows security subsystem (Local Security Authority and Schannel) within the Windows Recovery Environment (WinRE), on which the Veeam Recovery Media is based. As a result, the TLS handshake that secures the connection between the restore wizard and the local VeeamAgent.exe process cannot be completed. This behavior has been confirmed with the following Microsoft Windows updates for Windows 11 (versions 24H2 and 25H2) and Windows Server 2025, and any later updates: KB5094126 (OS builds 26100.8655 and 26200.8655) KB5099536 (OS build 26100.33158) Recovery media created from a system running an earlier update (for example, KB5089549, OS build 26200.8457, or earlier) is not affected. Microsoft has acknowledged the issue, and it is currently under investigation.
Until Microsoft resolves this issue, the Veeam Recovery Media can be built using the Windows Assessment and Deployment Kit (Windows ADK) instead of the Windows Recovery Environment (WinRE). Recovery media built using the Windows ADK is not affected by this issue. Workaround Ensure that the Windows Assessment and Deployment Kit (Windows ADK) and the corresponding Windows PE add-on are installed on the machine where the Veeam Recovery Media will be recreated. Create the following registry value on the machine where Veeam Agent for Microsoft Windows is installed to configure it to build the Veeam Recovery Media using the Windows ADK: Location: HKEY_LOCAL_MACHINE\SOFTWARE\Veeam\Veeam Endpoint BackupValue Type: DWORD (32-Bit) ValueValue Name: ForceUseAdkForRecoveryMediaValue Data: 1 Alternatively, the registry value can be created using the following PowerShell command:
Veeam Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.