Microsoft confirmed that running Sysprep under the Local System account is an unsupported scenario. This includes launching Sysprep through mechanisms such as Task Scheduler running as SYSTEM, PsExec as SYSTEM, or other service-based contexts.
I raised the question of what Microsoft considers the supported approach for a fully unattended image build pipeline on Windows Server 2025, since many image automation platforms operate under a service or SYSTEM context. Microsoft was unable to provide a documented supported method for performing a fully unattended Sysprep workflow under these conditions.
Their final position was:
- Running Sysprep as SYSTEM is unsupported.
- They currently do not have a documented, supported alternative that enables a completely unattended image creation workflow when automation runs under a service/SYSTEM account.
- The observed behavior is considered by support to align with current product design and documented limitations rather than a product malfunction.
- Any request for a supported unattended alternative would need to be pursued as a Design Change Request (DCR) through Unified/Premier Support for product group review.
What remains unclear is how Microsoft expects organizations to implement secure, non-interactive image creation pipelines for Windows Server 2025 when Sysprep must be executed from an elevated administrator context rather than a service context. That question was not answered during the case.