Products Tech Info Downloads Purchase Software Support Partners Company
SIDCHG - SID changer utility
SIDCHG (SIDCHG64 on 64-bit Windows) 3.0h is a command-line utility to modify local computer SID and computer name, for Windows 2022/11/2019/2016/10/8.1/2012 R2/8/2012/7/2008 R2. It replaces current computer SID with new random SID. In addition, it changes the WSUS ID for Windows Updates, the MachineGuid, the Machine ID, the Device Identifier for modern Windows apps, the MSDTC CID, the Dhcpv6 DUID, the SQL Server Master database, the encryption state to preserve encrypted files, Windows Action Center settings, Certificates and other encrypted stored information. Preservation of credentials stored in Windows Vault is possible with prior preparation of Vault backup. Optionally OneDrive can be reset.
SIDCHG64 [options]
  /COMPNAME: New computername, ? = random hex character, * = mac address (hex)
  /F: Omit confirmation
  /R: Reboot after SID change
  /S: Shutdown after SID change
  /WS: Seconds to wait before shutdown/reboot
  /FS: Force Shutdown/Reboot without closing applications
  /NS: Don't change SID, only set computername
  /KEY: License key
  /SK: Store licence key in registry for later. SID will not be changed if /SK is specified
  /RMK: Remove license key from registry after SID change
  /OD: Reset OneDrive. This avoids OneDrive synchronization issues if both original and clone are active with same user. /OD requires OneDrive-Account to be reentered after SID change. Without /OD it is sufficient to reenter password of OneDrive-Account after SID change
 Following options are advanced (not for normal use):
  /CNMF: Map file /COMPNAME will be mapped against, with lines map=compname
  /OS: Windows-directory (e.g C:\Windows) of OS to modify, if not running OS
  /D: Drives to check for SID (e.g /D:CDE). Per default, SID will be changed on all local harddrives
  /SID: New SID value. Per default, SID will be set to random value
  /NW: Don't change WSUS ID
  /NCID: Don't reset MSDTC CID
  /NPP: No Run Once-post processing. Transparent post processing is needed to preserve encrypted files and other user settings.
  /NDI: Don't reset Device ID.
  /NMG: Don't reset Machine GUID.
  /NMID: Don't reset Machine ID
  /NDUID: Don't reset Dhcpv6 DUID.
  /NSQ: Don't change SQL Server master database. When changed, a backup copy of the original master database is copied to C:\Windows\Temp-directory
  /NMA: Don't reset McAfee ID.
  /FDID: Full reset of Device ID (can invalidate System Activation)
  /REVERT: Reverts SID back to previous value after complete or interrupted SID change
  /REPEAT: Repeats previous complete or interrupted SID change with same previous and new SID values. This can be useful if not all has been changed during first run.
  /CLEARMSG: Clears SID change message at login after interrupted SID change
  /FF: Allow SID change with anti-virus real-time protection left on, SID to be changed on removable drive, or for unsupported Windows version

Best usages:
 SIDCHG /COMPNAME:compname /F /R /OD

Set computername after mac address:
 SIDCHG /COMPNAME=* /CNMF=map.txt      where map.txt has lines macaddress=compname

Change of computer SID risks data loss and system damage. Do not interrupt SID change in process!

On Windows 11, 10, 8.1, and 8, user will be logged out and SID will be changed in background, after which the computer will shut down (default) rsp. reboot (if /R is specified), to preserve modern interface user settings.
Do not log in and do not turn off or shutdown the computer while SID change is running in background!

While SID change is running in background, following message appears at Login screen, showing actual progress state of SID change in process:

It is very important to not log into the computer and not shutdown the computer while SID change is running in background ! This is necessary to preserve the modern user interfaces and apps.

After completing the SID change, the system will automatically shut down or reboot. Do not do that yourself, do not log in, and do not interfere. Best is to not touch the PC at all before the automatic shutdown/reboot !

SIDCHG is free to try for evaluation for 30 days maximum, but not free to use.
SIDCHG/SIDCHG64 license agreement
Download Software
Visit Download page.
Trial key
Monthly trial keys for evaluation purposes are available. Trial key valid November 2022:

New trial key will be uploaded during 5th-10th day of month. Trial key has same technical functionality as License key you receive after purchase. SID changed using trial key will stay changed even after trial key expires.
Purchase license
Upon registration, you will be sent license key for SIDCHG 3.0. License key can be stored in registry, for easy management. Visit Purchase page.
Note on Anti-Virus
SIDCHG (not SIDCHGL) demands real-time antivirus protection Microsoft Defender Antivirus or other to be turned off before running SID change. There is too much danger otherwise that Anti-virus protection will stop running SID change process in the middle of operation, leaving the system in a bad state. Microsoft Defender Antivirus turns real-time protection back on automatically after reboot.

Alternatively, Process Exclusion can be applied (see below). SIDCHG commandline option /FF allows SID change to run with real-time anti-virus enabled, but it is not recommended.

SIDCHGL is an alternative to SIDCHG, if turning off antivirus is undesirable.
For SIDCHGL(64) it is only recommended but not demanded that real-time antivirus protection Microsoft Defender Antivirus or other be turned off before running SID change. SIDCHGL functions the same way as SIDCHG, with the difference that it skips change of SID within browser settings. If browser settings like homepage or bookmarks are not cloud-synced, they will be lost and reset to default values after changing the SID with SIDCHGL, because the stored browser settings are bound to the previous SID and no longer valid for the new SID. Changing the SID within browser settings and therefore making modifications at these locations causes Antivirus Software to stop the SID change process, leaving the system with incomplete SID change. SIDCHGL skips changing SID within browser settings and will therefore much less likely be stopped by Antivirus Software. Still it is recommended to turn real-time Anti-Virus Software off even with SIDCHGL. The SID needs to be changed at many locations within the system and the possibility remains that these changes are seen as a dangerous action by the Anti-Virus Software and that it interrupts or blocks the running SID change.

SIDCHGL and SIDCHGL64 have same command options and work with same license key. License and key for SIDCHG are valid also for SIDCHGL.

For best results it is recommended to use SIDCHG(64) with real-time Anti-virus turned off during SID change, not SIDCHGL.

How to further improve acceptance by Anti-virus
For SIDCHG to run in background, it will normally copy itself to C:\Windows\Temp\SIDCHG64_.exe rsp C:\Windows\Temp\SIDCHGL64_.exe for SIDCHGL. This copy operation is recognized and potentially disliked by Anti-Virus-Software. To avoid the copy operation, and have the SID change in background run from the calling .EXE, following conditions need to be met: 1. SIDCHG(L)(64).EXE must be run from one of the following directories or a subdirectory: C:\Windows, C:\Program Files, C:\Program Files (x86).
2. The Security-Attribute that this file came from another computer needs to be be Unblocked within downloaded SIDCHG(64).EXE file Properties.
Using Process Exclusion instead of turning off realtime Anti-Virus
An alternative from turning off Microsoft Defender Antivirus is to exclude the Process where SID change is run from Antivirus. The process name usally is C:\Windows\Temp\SIDCHG64_.exe rsp C:\Windows\Temp\SIDCHGL64_.exe for SIDCHGL, but can also be the .EXE from which SIDCHG is called (see above section).
Note if SID change takes long time
Before acting, please let it run for at least 15 minutes. Then check if progress message with progress number shown in image above changes. Press OK button in progress message screen and then click on login screen to have progress message display show up again with new progress. If progress message and progress number BOTH stay unchanged for 5 minutes, it can be assumed that the program is no longer running and terminated abnormally. If only progress message stays unchanged but progress number changes, the SID change is still actively being worked on.
Note if SID change has been interrupted and SID change message remains at login screen
If running SIDCHG has been interrupted, use SIDCHG /CLEARMSG to remove SID change message at login.

SIDCHG recognizes interrupted SID change and will continue interrupted SID change if called again. There are also options /REPEAT or /REVERT to repeat or revert (undo) SID change.
Repeat or undo of an interrupted SID change are best done from a local Account with Administrator rights, which is created in advance (before performing the initial SID change), and which is used explicitely for that purpose (an account where it doesn't hurt if it gets damaged). After an interrupted SID change which is to be continued or to be reverted, do not log in with a user account which is actively in use. Do not interrupt revert or repeat SID changeopration.

Please be careful to not interrupt SIDCHG while it is doing SID change, before waiting lengthy time and being sure it is not working correctly.

Please also check for a file with name SIDCHGxxx.dmp (xxx any characters) in folder C:\Windows\Temp. If such a file exists after unsuccessful SID change, please send the file to support@stratesave.com , Thank you. This will help with analyzing the problem and working on a fix.
Note if SID change has been interrupted and modern Apps are not starting correctly
Use following command, run from Administrator Powershell, to repair your system (ignore error messages):
Get-AppXPackage -AllUsers | Foreach {Add-AppxPackage -DisableDevelopmentMode -Register "$($_.InstallLocation)\AppXManifest.xml"}
Note about Windows Licensing, KMS et al
SIDCHG does not affect Windows licensing. Use slmgr -rearm to reset licensing information of imaged clones, in addition to calling SIDCHG(64).
Note about SID change from Windows PE
SIDCHG supports SID change from Windows PE, with SIDCHG commandline option /OS:C:\Windows, pointing at the System to be changed. The Windows version of the PE should be the same or greater than the system to be changed. To change the SID of a Windows 10 System from PE, for best results use Windows 10 PE.
Note about SID change of domain computers
After the SID change computers on a domain possibly loose domain membership and need to rejoin. In addition, SID of a domain controller server cannot be changed. To change the SID of a domain controller, it needs to be demoted first, and promoted again after SID change.
Note about EFS encrypted files
SIDCHG supports preservation of encrypted information, including NTFS encrypted files. Please note that EFS encrypted files cannot always be preserved. If it is necessary to preserve encrypted files, best to save the EFS certificate in advance, for example with rekeywiz-command.
Note about preservation of credentials stored in Windows Vault
To preserve stored credentials after SID change, create a backup of the Vault before the SID change using Credential Manager's backup functionality. The backup needs to be stored in user's TEMP-directory with the name SIDCHG.crd. The password of the vault is SIDCHG. User's TEMP-directory can be determined with command echo %TEMP% from command prompt. Often it is C:\Users\username\AppData\Local\Temp. After the SID change and recovery of the Vault credentials, the SIDCHG.crd file will be deleted. To prevent the deletion, assign READ-only attribute to the file. For increased security, the file can optionally be stored NTFS-encrypted.
Note about SID change with BitLocker
SIDCHG must not be run with BitLocker Volume encryption enabled. This leads to complete data loss. BitLocker needs to be turned off and drives being decrypted. If desired, BitLocker can be reenabled after the SID change.
Note about storing key with /SK and /RMK options
The /SK option stores the Registration Key in Windows registry without doing the SID change while the /RMK option removes the Key from registry while also doing the SID change. The usual usage is to store the key in the base image with SIDCHG /SK. On the clones the SID can then be changed without specifying the key. If you prefer the key to be removed after the SID change, use /RMK option when changing the SID.
Note on ANY.RUN "Malicious Activity" report
An online report can be found from ANY.RUN which assigns to SIDCHG the verdict "Malicious Activity" and tags it as adware. SIDCHG's activity is for the purpose of implementing best possible quality and complete SID change. The malicious activity reported is "Application was dropped or rewritten from another process". SIDCHG copies itself to Windows Temp directory, for it to run in background, which cannot be done from user's download directory. This copy operation can be avoided if desired following the section How to further improve acceptance by Anti-virus above. SIDCHG also copies itself to local users' Temp directories, to be run by user once at first login after the SID change. This is to migrate encrypted files and other encrypted stored information like Windows Action Center Settings to the new SID, which needs to be done individually by the logged in user. This copy of itself and run once can be avoided with SIDCHG option /NPP but then encrypted information will be lost after the SID change. The report also labels as suspicious "Modifies files in Chrome extension folder". SIDCHG changes the SID within browser's (Edge, Chrome) configurations files. This can be avoided using SIDCHGL instead of SIDCHG, where configured browser settings like Homepage and Bookmarks are lost after the SID change. The report further mentions suspicious activity "Executable content was dropped or overwritten". SIDCHG does not modify any executable .exe or .dll file's content. But it checks permissions and ownership of all files and modifies these if necessary to adjust to the new SID. The reason for the Tag "adware" could not be found elaborated in the report. SIDCHG does not show any ads, does not connect to any ad server and does not make any network connections.
How to be alerted about updates of SIDCHG
To be informed when an update of SIDCHG becomes available, use service webalert.email. After registering and signin in, Add a New Web Alert for Url https://www.stratesave.com with keyword SIDCHG, or possibly with key word New! which will inform you about any new or updated Stratesave Software.
Home |  Products |  Tech Info |  Downloads |  Purchase |  Support |  Partners |  Company          1996-2022 Stratesave Systems