Microsoft confirmed that recent Windows updates have introduced a critical issue causing Kerberos and NTLM authentication failures on systems with duplicate Security Identifiers (SIDs). The updates, released since August 29, 2025, enforce stricter checks on SIDs, resulting in failed authentication handshakes between devices sharing the same SID. This has led to widespread login issues, including failed remote desktop connections, 'access denied' errors, and unsuccessful login attempts even with valid credentials, particularly affecting Windows 11 24H2, Windows 11 25H2, and Windows Server 2025 systems.
The root cause is linked to Windows installations that were cloned or duplicated without proper preparation using the Sysprep tool, which can result in duplicate SIDs across devices. Microsoft has acknowledged the problem and provided guidance, noting that affected users may see specific errors such as SEC_E_NO_CREDENTIALS and warnings about machine ID mismatches in the Event Viewer. The company is working to address the issue and has published support documentation to help organizations identify and remediate impacted systems.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
Recent Windows updates released in October 2025 caused login and authentication problems on some systems, particularly affecting PCs that share security identifiers. Reported impact included broken Kerberos and NTLM authentication and resulting sign-in failures.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.