Change Auditor Agent stops working and may cause the domain controller to crash (in some cases) after installing the Microsoft Windows February 2026 Patch (KB5075904). The "CAADHook.dll.nptlog" Change Auditor Active Directory Plug-In log file will display the warning "LdapControlsToControlArg not found" line.
The LDAP control hook module stops working on Change Auditor agent versions 7.5 or earlier.
It has been observed mainly on Windows Server 2019 and 2022 with Change Auditor agent versions 7.5 or earlier that the Microsoft patch affects the Change Auditor LDAP control hook responsible for integrating initiator data from Active Roles Server (ARS) and GPOAdmin, as well as the ability to add Comments to the RestoreAD feature. As a result, the agent service may stop functioning as expected and hang whenever it starts or stops, which could also negatively affect the domain controller host and explain the unexpected crash in some cases.
Solution:
Upgrade Change Auditor to version 7.6 or later.
Workaround:
Disable the LDAP control hook of the Change Auditor agent on each affected host to prevent it from loading by creating the following registry key:
Disclaimer: Quest does not provide support for problems that arise from improper modification of the registry. The Windows registry contains information critical to your computer and applications. Make sure you back up the registry before modifying it. For more information on the Windows Registry Editor and how to back up and restore it, refer to the Microsoft website.