The documented issue with Kerberos and NTLM authentication failures due to duplicate SIDs is explicitly scoped to:
- Windows 11, version 24H2
- Windows 11, version 25H2
- Windows Server 2025
The cause is tied to security changes introduced in updates for these versions starting August 29, 2025, which enforce stricter SID checks and block authentication when duplicate SIDs are detected.
Because these changes are described only for Windows 11, versions 24H2 and 25H2, and Windows Server 2025, the described behavior and required mitigations (such as rebuilding devices with unique SIDs or using the special Group Policy) are not stated as applying to Windows 11, version 23H2 in the provided documentation.
References: