Event Id | 4771 |
Source | Microsoft-Windows-Security-Auditing |
Description | Kerberos pre-authentication failed. Account Information: Security ID:<Security ID> Account Name:<Account Name> Service Information: Service Name:<Group Domain> Network Information: Client Address:<Client Address> Client Port:<Client Port> Additional Information: Ticket Options:<Ticket Options> Failure Code:<Failure Code> Pre-Authentication Type:<Pre-Authentication Type> Certificate Information: Certificate Issuer Name:<Certificate Issuer Name> Certificate Serial Number:<CertificateSerial Number> Certificate Thumbprint: <Certificate Thumbprint> |
Event Information | Cause : Windows logs other instances of event ID 4768 when a computer in the domain needs to authenticate to the DC typically when a workstation boots up or a server restarts. In these instances, you'll find a computer name in the User Name and fields. Computer generated kerberos events are always identifiable by the $ after the computer account's name. |
Reference Links | Kerberos error codes |
Catch threats immediately
We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.