Manual certificate rotation with disabled automatic rollover can leave stale records in the WID database while valid keys persist in Machine DPAPI. This drift creates a 'ghost' entry that hides the true signing key from common extraction paths but remains exploitable by privileged actors.