{"id":15849,"date":"2026-04-10T03:01:01","date_gmt":"2026-04-09T18:01:01","guid":{"rendered":"https:\/\/m365jp.net\/?p=15849"},"modified":"2026-04-10T03:01:29","modified_gmt":"2026-04-09T18:01:29","slug":"mc1275343-hardening-administrative-actions-windows-imaging-cloning-and-auth-workflows","status":"publish","type":"post","link":"https:\/\/m365jp.net\/index.php\/2026-04-10-mc1275343-hardening-administrative-actions-windows-imaging-cloning-and-auth-workflows","title":{"rendered":"MC1275343 | Hardening administrative actions: Windows imaging, cloning, and auth workflows"},"content":{"rendered":"<div class=\"postie-post\">\n<div>\n<hr>\n<table id=\"section\">\n<tbody>\n<tr>\n<th width=\"95%\">MC1275343 | Hardening administrative actions: Windows imaging, cloning, and auth workflows<\/th>\n<\/tr>\n<\/tbody>\n<\/table>\n<hr>\n<table id=\"data\">\n<tbody>\n<tr>\n<th>Classification<\/th>\n<td>stayInformed<\/td>\n<\/tr>\n<tr>\n<th>Last Updated<\/th>\n<td>04\/09\/2026 17:01:43<\/td>\n<\/tr>\n<tr>\n<th>Start Time<\/th>\n<td>04\/09\/2026 17:01:38<\/td>\n<\/tr>\n<tr>\n<th>End Time<\/th>\n<td>04\/09\/2027 17:01:38<\/td>\n<\/tr>\n<tr>\n<th>Message Content<\/th>\n<td>\n<div>Administrative actions are undergoing hardening changes that might require operational change to support your organization\u2019s security posture.&nbsp;With the&nbsp;August 2025 Windows&nbsp;non-security update,&nbsp;devices&nbsp;were&nbsp;hardened&nbsp;against&nbsp;unauthorized&nbsp;attempts to bypass   loopback detection.&nbsp;However, if&nbsp;you\u2019ve&nbsp;cloned machines without&nbsp;Sysprep, you might see Kerberos and NTLM authentication failures. This&nbsp;is by design.&nbsp;The recommended solution is to rebuild affected devices using supported imaging methods.&nbsp;A&nbsp;temporary workaround   is also available.&nbsp;<\/div>\n<div>&nbsp;<\/div>\n<div><b>When will this happen:<\/b><\/div>\n<ul>\n<li><b>September&nbsp;2025 and later<\/b>: Windows&nbsp;security&nbsp;updates include hardening changes that strengthen the trust boundary between identity, authentication, and User Account Control (UAC).<\/li>\n<li><b>April&nbsp;2026 and later<\/b>: Windows&nbsp;security&nbsp;updates include a temporary workaround&nbsp;for machines cloned without&nbsp;Sysprep. This&nbsp;registry-based compatibility&nbsp;option&nbsp;isn\u2019t&nbsp;recommended. It reduces security protections introduced by recent updates.<\/li>\n<li><b>End of 2027<\/b>: The temporary workaround expires.&nbsp;<\/li>\n<\/ul>\n<div>&nbsp;<\/div>\n<div><b>How this will affect your organization:<\/b><\/div>\n<div>This affects your organization if:&nbsp;<\/div>\n<ul>\n<li>You manage devices on Windows 11, version 24H2 and later or Windows Server 2025.<\/li>\n<li>You installed the August 2025 non-security update or September 2025 security update (or later) on these devices.<\/li>\n<li>You notice Kerberos or NTLM authentication failures. These failures surface as LsaSrv&nbsp;Event ID 6167 in the System event log&nbsp;of the target machine.<\/li>\n<\/ul>\n<div>You need to&nbsp;adjust your strategy to clone Windows images.<\/div>\n<div>&nbsp;<\/div>\n<div><b>What you need to do to prepare:<\/b><\/div>\n<div>Take the following actions:&nbsp;<\/div>\n<ul>\n<li>Stop any automation that clones&nbsp;devices without Sysprep. If not addressed, devices end up with duplicate security IDs (SIDs).<\/li>\n<li>Rebuild all devices with duplicate SIDs from scratch, then run Sysprep. It&#8217;s&nbsp;not sufficient to unjoin devices and run Sysprep.&nbsp;<\/li>\n<li>If needed for transition only,&nbsp;temporarily roll back the hardening change with a registry-based&nbsp;option.&nbsp;Please contact  <a href=\"https:\/\/support.serviceshub.microsoft.com\/supportforbusiness\/manage\" rel=\"noopener noreferrer\" target=\"_blank\">  Microsoft Commercial Customer Service and Support (CSS)<\/a>&nbsp;to get information about this registry value.&nbsp;<\/li>\n<\/ul>\n<div>  <\/div>\n<div>For details and instructions, review <a href=\"https:\/\/aka.ms\/HardeningAdministrativeActions\" rel=\"noopener noreferrer\" target=\"_blank\">  Hardening administrative actions: What IT pros need to know<\/a>.&nbsp;<\/div>\n<div>&nbsp;<\/div>\n<div><b>Additional&nbsp;information:<\/b><\/div>\n<ul>\n<li><a href=\"https:\/\/aka.ms\/HardeningAdministrativeActions\" rel=\"noopener noreferrer\" target=\"_blank\">Hardening administrative actions: What IT pros need to know<\/a><\/li>\n<li><a href=\"https:\/\/support.microsoft.com\/en-us\/topic\/kerberos-and-ntlm-authentication-failures-due-to-duplicate-sids-76f7394d-c460-4882-9ed1-d27e0960f949\" rel=\"noopener noreferrer\" target=\"_blank\">KB5070568<\/a>:  <a href=\"https:\/\/support.microsoft.com\/topic\/kerberos-and-ntlm-authentication-failures-due-to-duplicate-sids-76f7394d-c460-4882-9ed1-d27e0960f949\" rel=\"noopener noreferrer\" target=\"_blank\">  Kerberos and NTLM authentication failures due to duplicate SIDs<\/a><\/li>\n<li><a href=\"https:\/\/support.microsoft.com\/topic\/strengthening-administrator-protection-and-kerberos-authentication-f67abf78-41c5-4a89-a2da-a7b2fe280270\" rel=\"noopener noreferrer\" target=\"_blank\">KB5068222:\u202fStrengthening administrator protection and Kerberos   authentication<\/a><\/li>\n<li><a href=\"https:\/\/learn.microsoft.com\/troubleshoot\/windows-server\/setup-upgrade-and-drivers\/windows-installations-disk-duplication\" rel=\"noopener noreferrer\" target=\"_blank\">The Microsoft policy for disk duplication of Windows installations<\/a><\/li>\n<li><a href=\"https:\/\/learn.microsoft.com\/windows-hardware\/manufacture\/desktop\/sysprep--generalize--a-windows-installation?view=windows-11\" rel=\"noopener noreferrer\" target=\"_blank\">Sysprep<\/a><\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<th>Machine Translation<\/th>\n<td>\n<div>\u7ba1\u7406\u4e0a\u306e\u64cd\u4f5c\u306f\u5f37\u5316\u5909\u66f4\u304c\u9032\u3081\u3089\u308c\u3066\u304a\u308a\u3001\u7d44\u7e54\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u4f53\u5236\u3092\u652f\u63f4\u3059\u308b\u305f\u3081\u306b\u904b\u7528\u4e0a\u306e\u5909\u66f4\u304c\u5fc5\u8981\u306b\u306a\u308b\u5834\u5408\u304c\u3042\u308a\u307e\u3059\u3002&nbsp;2025\u5e748\u6708\u306e&nbsp;Windows&nbsp;\u975e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30a2\u30c3\u30d7\u30c7\u30fc\u30c8\u306b\u3088\u308a\u3001&nbsp;\u30c7\u30d0\u30a4\u30b9&nbsp;\u306f\u30eb\u30fc\u30d7\u30d0\u30c3\u30af\u691c\u51fa\u3092\u56de\u907f\u3057\u3088\u3046\u3068\u3059\u308b\u4e0d\u6b63&nbsp;\u306a\u8a66\u307f\u306b\u5bfe\u3057\u3066&nbsp;\u5f37\u5316&nbsp;\u3055\u308c\u307e\u3057\u305f&nbsp;\u3002&nbsp;\u3057\u304b\u3057\u3001&nbsp;Sysprep\u306a\u3057\u3067&nbsp;\u30de\u30b7\u30f3\u3092\u30af\u30ed\u30fc\u30f3\u3057\u305f\u5834\u5408&nbsp;\u3001Kerberos\u3084NTLM\u8a8d\u8a3c\u306e\u5931\u6557\u304c\u8d77\u3053\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002\u3053\u308c\u306f&nbsp;\u8a2d\u8a08\u4e0a\u306e\u3082\u306e\u3067\u3059\u3002&nbsp;\u63a8\u5968\u3055\u308c\u308b\u89e3\u6c7a\u7b56\u306f\u3001\u5bfe\u5fdc\u53ef\u80fd\u306a\u30a4\u30e1\u30fc\u30b8\u30f3\u30b0\u624b\u6cd5\u3067\u5f71\u97ff\u3092\u53d7\u3051\u305f\u30c7\u30d0\u30a4\u30b9\u3092\u518d\u69cb\u7bc9\u3059\u308b\u3053\u3068\u3067\u3059\u3002&nbsp;\u4e00\u6642\u7684\u306a\u56de\u907f\u7b56&nbsp;\u3082\u3042\u308a\u307e\u3059\u3002&nbsp;<\/div>\n<div>&nbsp;<\/div>\n<div><b>\u3053\u308c\u306f\u3044\u3064\u5b9f\u73fe\u3057\u307e\u3059\u304b:<\/b><\/div>\n<ul>\n<li><b>2025\u5e749\u6708&nbsp;\u4ee5\u964d<\/b>:Windows&nbsp;\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3&nbsp;\u30a2\u30c3\u30d7\u30c7\u30fc\u30c8\u306b\u306f\u3001\u30a2\u30a4\u30c7\u30f3\u30c6\u30a3\u30c6\u30a3\u3001\u8a8d\u8a3c\u3001\u30e6\u30fc\u30b6\u30fc\u30a2\u30ab\u30a6\u30f3\u30c8\u5236\u5fa1(UAC)\u9593\u306e\u4fe1\u983c\u5883\u754c\u3092\u5f37\u5316\u3059\u308b\u5f37\u5316\u5909\u66f4\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002<\/li>\n<li><b>2026\u5e744\u6708&nbsp;\u4ee5\u964d<\/b>:Windows&nbsp;\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3&nbsp;\u30a2\u30c3\u30d7\u30c7\u30fc\u30c8\u306b\u306f\u3001Sysprep\u306a\u3057&nbsp;\u306e\u30af\u30ed\u30fc\u30f3\u30de\u30b7\u30f3\u5411\u3051\u306e\u4e00\u6642\u7684\u306a\u56de\u907f\u7b56&nbsp;\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u306e&nbsp;\u30ec\u30b8\u30b9\u30c8\u30ea\u30d9\u30fc\u30b9\u306e\u4e92\u63db\u6027&nbsp;\u30aa\u30d7\u30b7\u30e7\u30f3&nbsp;\u306f\u63a8\u5968\u3055\u308c\u307e\u305b\u3093&nbsp;\u3002\u3053\u308c\u306f\u6700\u8fd1\u306e\u30a2\u30c3\u30d7\u30c7\u30fc\u30c8\u306b\u3088\u3063\u3066\u5c0e\u5165\u3055\u308c\u305f\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u4fdd\u8b77\u3092\u5f31\u3081\u307e\u3059\u3002<\/li>\n<li><b>2027\u5e74\u672b<\/b>:\u4e00\u6642\u7684\u306a\u56de\u907f\u7b56\u304c\u671f\u9650\u5207\u308c\u3002&nbsp;<\/li>\n<\/ul>\n<div>&nbsp;<\/div>\n<div><b>\u3053\u308c\u304c\u3042\u306a\u305f\u306e\u7d44\u7e54\u306b\u3069\u306e\u3088\u3046\u306a\u5f71\u97ff\u3092\u4e0e\u3048\u308b\u304b:<\/b><\/div>\n<div>\u3053\u308c\u306f\u4ee5\u4e0b\u306e\u5834\u5408\u306b\u7d44\u7e54\u306b\u5f71\u97ff\u3092\u4e0e\u3048\u308b\u3002&nbsp;<\/div>\n<ul>\n<li>Windows 11\u3001\u30d0\u30fc\u30b8\u30e7\u30f324H2\u4ee5\u964d\u3001\u307e\u305f\u306fWindows Server 2025\u3067\u30c7\u30d0\u30a4\u30b9\u3092\u7ba1\u7406\u3057\u307e\u3059\u3002<\/li>\n<li>\u3053\u308c\u3089\u306e\u30c7\u30d0\u30a4\u30b9\u306b2025\u5e748\u6708\u306e\u975e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30a2\u30c3\u30d7\u30c7\u30fc\u30c8\u3001\u307e\u305f\u306f2025\u5e749\u6708\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30a2\u30c3\u30d7\u30c7\u30fc\u30c8(\u307e\u305f\u306f\u305d\u308c\u4ee5\u964d)\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u307e\u3057\u305f\u3002<\/li>\n<li>Kerberos\u3084NTLM\u306e\u8a8d\u8a3c\u5931\u6557\u306b\u6c17\u3065\u304f\u3067\u3057\u3087\u3046\u3002\u3053\u308c\u3089\u306e\u969c\u5bb3\u306f\u3001\u30bf\u30fc\u30b2\u30c3\u30c8\u30de\u30b7\u30f3\u306e\u30b7\u30b9\u30c6\u30e0\u30a4\u30d9\u30f3\u30c8\u30ed\u30b0&nbsp;\u306bLsaSrv&nbsp;\u30a4\u30d9\u30f3\u30c8ID 6167\u3068\u3057\u3066\u73fe\u308c\u307e\u3059\u3002<\/li>\n<\/ul>\n<div>Windows\u30a4\u30e1\u30fc\u30b8\u306e\u30af\u30ed\u30fc\u30f3\u6226\u7565\u3092&nbsp;\u8abf\u6574\u3059\u308b\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\u3002<\/div>\n<div>&nbsp;<\/div>\n<div><b>\u6e96\u5099\u306e\u305f\u3081\u306b\u3084\u308b\u3079\u304d\u3053\u3068:<\/b><\/div>\n<div>\u4ee5\u4e0b\u306e\u884c\u52d5\u3092\u53d6\u3063\u3066\u304f\u3060\u3055\u3044\u3002&nbsp;<\/div>\n<ul>\n<li>Sysprep\u306a\u3057\u3067\u30c7\u30d0\u30a4\u30b9\u306e\u30af\u30ed\u30fc\u30f3&nbsp;\u3092\u884c\u3046\u81ea\u52d5\u5316\u306f\u505c\u6b62\u3057\u3066\u304f\u3060\u3055\u3044\u3002\u30a2\u30c9\u30ec\u30b9\u304c\u306a\u3051\u308c\u3070\u3001\u30c7\u30d0\u30a4\u30b9\u306f\u91cd\u8907\u3057\u305f\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3ID(SID)\u3092\u6301\u3064\u3053\u3068\u306b\u306a\u308a\u307e\u3059\u3002<\/li>\n<li>\u8907\u88fdSID\u3092\u6301\u3064\u3059\u3079\u3066\u306e\u30c7\u30d0\u30a4\u30b9\u3092\u4e00\u304b\u3089\u518d\u69cb\u7bc9\u3057\u3001\u305d\u306e\u5f8cSysprep\u3092\u5b9f\u884c\u3057\u307e\u3059\u3002&nbsp;\u30c7\u30d0\u30a4\u30b9\u3092\u30a2\u30f3\u30b8\u30e7\u30a4\u30f3\u3057\u3066Sysprep\u3092\u5b9f\u884c\u3059\u308b\u3060\u3051\u3067\u306f\u4e0d\u5341\u5206\u3067\u3059\u3002&nbsp;<\/li>\n<li>\u79fb\u884c\u306e\u307f\u304c\u5fc5\u8981\u306a\u5834\u5408\u306f\u3001&nbsp;\u30ec\u30b8\u30b9\u30c8\u30ea\u30d9\u30fc\u30b9\u306e&nbsp;\u30aa\u30d7\u30b7\u30e7\u30f3\u3067\u4e00\u6642\u7684\u306b\u30cf\u30fc\u30c9\u30cb\u30f3\u30b0\u5909\u66f4\u3092\u30ed\u30fc\u30eb\u30d0\u30c3\u30af\u3057\u3066\u304f\u3060\u3055\u3044\u3002&nbsp;\u3053\u306e\u30ec\u30b8\u30b9\u30c8\u30ea\u5024\u306b\u95a2\u3059\u308b\u60c5\u5831\u306b\u3064\u3044\u3066\u306f <a href=\"https:\/\/support.serviceshub.microsoft.com\/supportforbusiness\/manage\" rel=\"noopener noreferrer\" target=\"_blank\">  \u3001Microsoft Commercial Customer Service and Support(CSS<\/a>&nbsp;)\u306b\u304a\u554f\u3044\u5408\u308f\u305b\u304f\u3060\u3055\u3044\u3002&nbsp;<\/li>\n<\/ul>\n<div>  <\/div>\n<div>\u8a73\u7d30\u3068\u624b\u9806\u306b\u3064\u3044\u3066\u306f\u3001\u300c <a href=\"https:\/\/aka.ms\/HardeningAdministrativeActions\" rel=\"noopener noreferrer\" target=\"_blank\">  \u5f37\u5316\u7ba1\u7406\u63aa\u7f6e:IT\u5c02\u9580\u5bb6\u304c\u77e5\u3063\u3066\u304a\u304f\u3079\u304d\u3053\u3068<\/a>\u300d\u3092\u3054\u89a7\u304f\u3060\u3055\u3044\u3002&nbsp;<\/div>\n<div>&nbsp;<\/div>\n<div><b>\u8ffd\u52a0&nbsp;\u60c5\u5831:<\/b><\/div>\n<ul>\n<li><a href=\"https:\/\/aka.ms\/HardeningAdministrativeActions\" rel=\"noopener noreferrer\" target=\"_blank\">\u7ba1\u7406\u4e0a\u306e\u5f37\u5316:IT\u5c02\u9580\u5bb6\u304c\u77e5\u3063\u3066\u304a\u304f\u3079\u304d\u3053\u3068<\/a><\/li>\n<li><a href=\"https:\/\/support.microsoft.com\/en-us\/topic\/kerberos-and-ntlm-authentication-failures-due-to-duplicate-sids-76f7394d-c460-4882-9ed1-d27e0960f949\" rel=\"noopener noreferrer\" target=\"_blank\">KB5070568<\/a>:  <a href=\"https:\/\/support.microsoft.com\/topic\/kerberos-and-ntlm-authentication-failures-due-to-duplicate-sids-76f7394d-c460-4882-9ed1-d27e0960f949\" rel=\"noopener noreferrer\" target=\"_blank\">  \u91cd\u8907SID\u306b\u3088\u308bKerberos\u304a\u3088\u3073NTLM\u8a8d\u8a3c\u306e\u5931\u6557<\/a><\/li>\n<li><a href=\"https:\/\/support.microsoft.com\/topic\/strengthening-administrator-protection-and-kerberos-authentication-f67abf78-41c5-4a89-a2da-a7b2fe280270\" rel=\"noopener noreferrer\" target=\"_blank\">KB5068222:?\u7ba1\u7406\u8005\u4fdd\u8b77\u3068Kerberos\u8a8d\u8a3c\u306e\u5f37\u5316<\/a><\/li>\n<li><a href=\"https:\/\/learn.microsoft.com\/troubleshoot\/windows-server\/setup-upgrade-and-drivers\/windows-installations-disk-duplication\" rel=\"noopener noreferrer\" target=\"_blank\">Windows\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u306e\u30c7\u30a3\u30b9\u30af\u8907\u88fd\u306b\u95a2\u3059\u308bMicrosoft\u30dd\u30ea\u30b7\u30fc<\/a><\/li>\n<li><a href=\"https:\/\/learn.microsoft.com\/windows-hardware\/manufacture\/desktop\/sysprep--generalize--a-windows-installation?view=windows-11\" rel=\"noopener noreferrer\" target=\"_blank\">Sysprep<\/a><\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>MC1275343 | Hardening administrative actions: Windows imaging, cloning, and auth workflows Classification stay [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-15849","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/posts\/15849","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/comments?post=15849"}],"version-history":[{"count":0,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/posts\/15849\/revisions"}],"wp:attachment":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/media?parent=15849"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/categories?post=15849"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/tags?post=15849"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}