Audit Failure 4771

Tanju Demir 21 Reputation points
2022-09-29T08:28:53.787+00:00

hi
I changed the domain controller administrator password,
4771 kerberos pre-authentication failed warning dc appears continuously from the exchange server ip, which is a member.

There is no scheduled task on the exchange server, no credentials

Exchange Server 2019
xxxx\administrator
krbtgt/xxxx.local
192. 168.100.200 (exchange ip)

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,327 questions
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,714 questions
0 comments No comments
{count} votes

Accepted answer
  1. LilyLi2-MSFT 1,981 Reputation points
    2022-09-30T07:47:27.633+00:00

    Hi @Tanju Demir

    Welcome to our forum.

    This error can be caused when the user's password has expired or is incorrect.
    Here are some of my troubleshooting:

    1.Make sure that your other backup software updates your password. In this thread, the problem is caused by not updating the password in the backup software after changing the password.

    2.Domain administrator credentials are not updated on DHCP.
    Please open Start -> Type "DHCP" and hit enter -> expand the tree to show IPv4 -> right click and go to Properties -> switch to the Advanced tab -> click the Credentials button -> update domain admin credentials.

    The following threads are expected to be helpful to you:
    1652152-domain-administrator-lock-outs-after-password-change
    578579-audit-failure-event-id-4771-for-domain-admin


    If an Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

3 additional answers

Sort by: Most helpful
  1. JimmySalian-2011 41,916 Reputation points
    2022-09-29T08:41:49.17+00:00

    Hi Tanjur,

    This event is not generated if “Do not require Kerberos preauthentication” option is set for the account. 4771 is basically a Kerberos pre-authentication failed. As you know the source you can implement additional Security monitoring event-4771

    So I suggest you investigate why that account is sending pre-auth errors and By default the KDC requires all accounts to use pre-authentication. This is a security feature which offers protection against password-guessing attacks.

    event-4771

    Hope this helps.

    ==
    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    0 comments No comments

  2. Tanju Demir 21 Reputation points
    2022-09-29T08:46:21.82+00:00

    4771 I know it has to do with kerberos authentication, after changing the password in dc, this event error comes from my exchange server.
    It happens because of heart mailboxes or because the password is outdated somewhere else between exchange-dc

    0 comments No comments

  3. Tanju Demir 1 Reputation point
    2022-09-30T00:37:29.35+00:00

    the source of the problem is acronis exchange agent service, domain is configured with admin while backing up exchange database

    0 comments No comments