ANAVEM
Languagefr

#kerberos-authentication

6 articles

Windows Events6

Windows domain controller monitoring dashboard displaying Kerberos authentication events and security logs
Event 4870
Kerberos
Windows EventWarning

Windows Event ID 4870 – Kerberos: TGT Renewal Failure

Event ID 4870 indicates a Kerberos Ticket Granting Ticket (TGT) renewal failure, typically occurring when domain authentication encounters issues with ticket refresh operations.

March 1812 min
Windows security monitoring dashboard showing certificate services and Event Viewer security logs
Event 4869
Kerberos
Windows EventError

Windows Event ID 4869 – Kerberos: Certificate Services Client Operation Failed

Event ID 4869 indicates a Kerberos certificate services client operation has failed, typically during certificate enrollment or renewal processes in Active Directory environments.

March 1812 min
Windows security monitoring dashboard displaying Kerberos authentication events in Event Viewer
Event 4769
Microsoft-Windows-Security-Auditing
Windows EventInformation

Windows Event ID 4769 – Microsoft-Windows-Security-Auditing: Kerberos Service Ticket Requested

Event ID 4769 logs when a Kerberos service ticket is requested from a domain controller. This security audit event tracks authentication attempts to network services and resources.

March 1812 min
Windows Event Viewer displaying Kerberos authentication security logs on a domain controller monitoring station
Event 4768
Microsoft-Windows-Security-Auditing
Windows EventInformation

Windows Event ID 4768 – Microsoft-Windows-Security-Auditing: Kerberos Authentication Ticket (TGT) Requested

Event ID 4768 logs when a user or service requests a Kerberos Ticket Granting Ticket (TGT) from a domain controller during authentication.

March 1812 min
Windows Server domain controller displaying Kerberos authentication service logs in a data center environment
Event 4112
Microsoft-Windows-Security-Kerberos
Windows EventInformation

Windows Event ID 4112 – Kerberos: Kerberos Authentication Service (AS) Started

Event ID 4112 indicates the Kerberos Authentication Service (AS) has successfully started on a domain controller, enabling authentication ticket granting for domain users and services.

March 189 min
Windows Event ID 4771 – Microsoft-Windows-Security-Auditing: Kerberos Pre-authentication Failed
Event 4771
Microsoft-Windows-Security-Auditing
Windows EventWarning

Windows Event ID 4771 – Microsoft-Windows-Security-Auditing: Kerberos Pre-authentication Failed

Event ID 4771 indicates a Kerberos pre-authentication failure, typically caused by incorrect passwords, expired accounts, or time synchronization issues between client and domain controller.

March 1812 min