To resolve this within your local authentication setup, you can rebuild the licensing cache by stopping the Software Protection service from an administrative prompt and renaming the tokens.dat file located in the C:\Windows\System32\spp\store\2.0 directory. Restarting the service afterward will generate a fresh, uncorrupted token store, which frequently resolves these false-negative display issues.
To build this infrastructure, you will need to deploy a Windows Server instance and install the Volume Activation Services role. Once you install your enterprise KMS host key on this server and allow it to publish its SRV records to your network's DNS, your LTSC clients will seamlessly transition to the server for authentication, permanently resolving the erratic watermark behavior.
Domic V.