Hardening administrative actions: Windows imaging, cloning, and auth workflows
Administrative actions are undergoing hardening changes that might require operational change to support your organization’s security posture. With the August 2025 Windows non-security update, devices were hardened against unauthorized attempts to bypass loopback detection. However, if you’ve cloned machines without Sysprep, you might see Kerberos and NTLM authentication failures. This is by design. The recommended solution is to rebuild affected devices using supported imaging methods. A temporary workaround is also available. When will this happen: September 2025 and later: Windows security updates include hardening changes that strengthen the trust boundary between identity, authentication, and User Account Control (UAC). April 2026 and later: Windows security updates include a temporary workaround for machines cloned without Sysprep. This registry-based compatibility option isn’t recommended. It reduces security protections introduced by recent updates. End of 2027: The temporary workaround expires. How this will affect your organization: This affects your organization if: You manage devices on Windows 11, version 24H2 and later or Windows Server 2025. You installed the August 2025 non-security update or September 2025 security update (or later) on these devices. You notice Kerberos or NTLM authentication failures. These failures surface as LsaSrv Event ID 6167 in the System event log of the target machine. You need to adjust your strategy to clone Windows images. What you need to do to prepare: Take the following actions: Stop any automation that clones devices without Sysprep. If not addressed, devices end up with duplicate security IDs (SIDs). Rebuild all devices with duplicate SIDs from scratch, then run Sysprep. It’s not sufficient to unjoin devices and run Sysprep. If needed for transition only, temporarily roll back the hardening change with a registry-based option. Please contact Microsoft Commercial Customer Service and Support (CSS) to get information about this registry value. For details and instructions, review Hardening administrative actions: What IT pros need to know. Additional information: Hardening administrative actions: What IT pros need to know KB5070568: Kerberos and NTLM authentication failures due to duplicate SIDs KB5068222: Strengthening administrator protection and Kerberos authentication The Microsoft policy for disk duplication of Windows installations Sysprep Message ID: MC1275343
The post Hardening administrative actions: Windows imaging, cloning, and auth workflows appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Hardening administrative actions: Windows imaging, cloning, and auth workflows
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
Intune: Windows Health Attestation Migration to Microsoft Azure Attestation
Microsoft Intune will migrate Windows Health Attestation compliance evaluation from the current Device Health Attestation (DHA) service to Mic...
Dynamics 365 Commerce – Print receipts using Adyen payment terminal printers
We are announcing the ability to print receipts using the built-in printer on supported Adyen payment terminals in Dynamics 365 Commerce. This...
Outlook: Multi Account Search
Users will be able to see results from multiple mailboxes interweaved in a single ranked list and will be able to do standard mail actions. Pr...
Dynamics 365 Field Service: Manage rental service demand with work order requests
Rental organizations need to coordinate commercial rental activity, equipment availability, asset condition, and service execution across mult...
Microsoft Teams: Schedule Channel Meetings from Outlook Calendar
Users will be able to schedule Microsoft Teams channel meetings directly from Outlook Calendar. This streamlines meeting creation and helps ke...
Microsoft 365 admin center: Optional Public CDN Support in Brand Center Setup
We are updating the Brand Center setup experience so that administrators can set up Brand Center without enabling Public CDN. Today, Public CD...
Dynamics 365 Field Service: Book Work Orders with Multiple Requirements
Dispatchers can now select which resource requirement to schedule when booking a work order that has multiple requirements. The new Book exper...
Brand Skill support now available in PPT Copilot [Web]
Brand managers can upload custom presentation skills as Markdown files to Brand Kit for use with Copilot in PowerPoint Web, enabling consisten...
Brand Skill support now available in PPT Copilot [Desktop]
Brand managers can now upload custom presentation skills as Markdown files to Brand Kit for use with Copilot in PowerPoint Desktop, enabling c...