Sysprep Required for Windows Imaging

Beginning with recent non-security and security Windows updates, Microsoft has introduced security hardening to prevent unauthorized bypass of loopback detection. As a result, devices cloned without using Sysprep may experience Kerberos and NTLM authentication failures. This behavior is intentional and aligns with supported Windows imaging standards.

Your units may be impacted if you:

  • Manage devices running Windows 11 version 24H2 or later or Windows Server 2025.
  • Installed the August 2025 non-security update or September 2025 security update (or newer) on these devices.
  • Observe Kerberos or NTLM authentication failures. These failures surface as LsaSrv Event ID 6167 in the System event log of the target machine.

Units are encouraged to adjust their strategy to clone Windows images:

  1. Discontinue or disable any automation that clones devices without Sysprep to avoid duplicate security IDs (SIDs).
  2. Fully rebuild all devices with duplicate SIDs and apply Sysprep during imaging. Unjoining from the domain and running Sysprep afterward is not sufficient.

Learn more at the following Microsoft resources: