Hello Vincent,
Thank you for posting question on Microsoft Windows Forum.
Based on your query of using temporary Group Policy to relax SID enforcement. Well! Microsoft recently introduced stricter SID uniqueness enforcement in Windows 11 (24H2/25H2) and Windows Server 2025 updates. To temporarily relax this enforcement, there might be a Group Policy setting that can disable or relax SID checks, allowing duplicate SIDs to continue authenticating until systems are remediated.
For Temporary Group Policy Workaround.
- The location of policy is Computer Configuration → Administrative Templates → System → Security Identifiers (SID) Enforcement
- Key Setting: “Relax SID uniqueness enforcement” (name may vary slightly depending on build).
- Scope for this policy is to apply to Windows 11 24H2/25H2 and Windows Server 2025 and it is intended as a temporary mitigation until machines are properly generalized (e.g., via Sysprep) or reimaged with unique SIDs.
Please note: Security risk for relaxing SID enforcement weakens identity guarantees, potentially allowing impersonation or misattribution of machine identities. Using the Group Policy only as a short-term workaround. The permanent fix is to reimage or run Sysprep /generalize to regenerate unique machine SIDs.
Hope the above information is helpful! If it is. Free feel to hit "Accepted" for benefitting others in community having the same issue too.