Request for the Group Policy template to disable SID uniqueness check to avoid Kerberos/NTLM authentication failures

KENICHI HAGIHARA 0 Reputation points
2025-12-11T02:43:24.1533333+00:00

Since the Windows Updates released after September 2025, the security behavior regarding SID uniqueness has become stricter. As a result, environments where duplicated machine SIDs exist can no longer access file shares, which is causing operational issues.

We have been temporarily uninstalling the corresponding security updates as a workaround. However, we have learned that Microsoft provides a method to disable SID uniqueness checking through a Group Policy setting.

Because the affected client devices are already deployed in production, regenerating machine SIDs (sysprep /generalize) is not a feasible option. Therefore, we would like to use the temporary workaround by applying the Group Policy that disables the SID uniqueness check.

Could you please provide the Group Policy Administrative Template (ADMX/ADML) that includes the “Disable SID uniqueness check” setting, or advise where we can download the official template from?

Windows for home | Windows 11 | Windows update
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Carl-L 4,155 Reputation points Microsoft External Staff Moderator
    2025-12-11T09:08:52.7466667+00:00

    Hello KENICHI HAGIHARA,

    Welcome to Microsoft Q&A forum. It's my pleasure to help you today.

    I understand that you are trying to obtain a special Group Policy template to temporary disable SID uniqueness check. Microsoft provide this as a temporary solution for IT Administrators, so the template is not publicly provided on public forum like this. To obtain this, you will need to contact Microsoft Business support so they can provide you with the templates. You can follow the instructions and resolution in this article to contact them: Kerberos and NTLM authentication failures due to duplicate SIDs. Thank you for your understanding.

    Please keep in mind that this is just a temporary solution, for a permanent fix, you will still need to rebuild the affected PCs with Sysprep /generalize.

    Feel free to contact us again if you have any other questions.


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.