#kerberos-authentication
6 articles
Windows Events6
Windows Event ID 4870 – Kerberos: TGT Renewal Failure
Event ID 4870 indicates a Kerberos Ticket Granting Ticket (TGT) renewal failure, typically occurring when domain authentication encounters issues with ticket refresh operations.
Windows Event ID 4869 – Kerberos: Certificate Services Client Operation Failed
Event ID 4869 indicates a Kerberos certificate services client operation has failed, typically during certificate enrollment or renewal processes in Active Directory environments.
Windows Event ID 4769 – Microsoft-Windows-Security-Auditing: Kerberos Service Ticket Requested
Event ID 4769 logs when a Kerberos service ticket is requested from a domain controller. This security audit event tracks authentication attempts to network services and resources.
Windows Event ID 4768 – Microsoft-Windows-Security-Auditing: Kerberos Authentication Ticket (TGT) Requested
Event ID 4768 logs when a user or service requests a Kerberos Ticket Granting Ticket (TGT) from a domain controller during authentication.
Windows Event ID 4112 – Kerberos: Kerberos Authentication Service (AS) Started
Event ID 4112 indicates the Kerberos Authentication Service (AS) has successfully started on a domain controller, enabling authentication ticket granting for domain users and services.

Windows Event ID 4771 – Microsoft-Windows-Security-Auditing: Kerberos Pre-authentication Failed
Event ID 4771 indicates a Kerberos pre-authentication failure, typically caused by incorrect passwords, expired accounts, or time synchronization issues between client and domain controller.