Microsoft’s Confirms Recent Updates Cause Login Issues on Windows 11 24H2, 25H2, and Windows Server 2025
## Update on Windows Authentication Issues
Update on Windows Authentication Issues
Microsoft has identified an authentication issue affecting users of recent Windows versions due to security updates released since late August 2025. These updates have led to Kerberos and NTLM failures on devices with identical Security Identifiers (SIDs), causing login disruptions across enterprise networks.
Users of Windows 11 version 24H2, version 25H2, and Windows Server 2025 have experienced issues following the installation of updates such as KB5064081 on August 29, 2025, and KB5065426 on September 9, 2025. Common problems include repeated credential prompts, error messages like "Login attempt failed," and disruptions in network access and Remote Desktop Protocol (RDP) sessions.
Failover Clustering operations have also been affected, with "access denied" errors complicating high-availability setups in data centers. Event Viewer logs reveal indicators such as SEC_E_NO_CREDENTIALS and Event ID 6167, signaling a machine ID mismatch.
These issues are significant in virtual desktop infrastructure (VDI) environments, particularly those using Citrix MCS. The updates now rigorously verify SIDs during authentication to prevent unauthorized access, and duplicate SIDs are not tolerated, often resulting from improper cloning without the Sysprep tool.
Microsoft has identified an authentication issue affecting users of recent Windows versions due to security updates released since late August 2025.
Microsoft advises using Sysprep to ensure SID uniqueness, which aligns with their policy against unsupported disk duplication methods. For immediate relief, IT administrators can deploy a specialized Group Policy to mitigate authentication blocks, available through Microsoft Support for business.
The definitive solution involves rebuilding impacted devices using approved cloning procedures with Sysprep to ensure unique SIDs. Organizations using VMware or Citrix for VDI provisioning may need to revise workflows to comply with these changes.
As of October 21, 2025, no broader patch has been released, but Microsoft continues to monitor reports from affected users.
Based on reporting by Cyber Security News.
