Event logs - The domain controller attempted to validate the credentials for an account

Paul 1 Reputation point
2022-05-17T09:35:35.68+00:00

ello,

Can you explain that event log why this is happening? user changed password by himself and there is many logs like this:

how can i fix it? Many thanks

Kerberos pre-authentication failed

The domain controller attempted to validate the credentials for an account

Kerberos pre-authentication failed

The domain controller attempted to validate the credentials for an account

Kerberos pre-authentication failed

The domain controller attempted to validate the credentials for an account

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,753 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Limitless Technology 39,351 Reputation points
    2022-05-18T07:41:24.203+00:00

    Hi there,

    What is the Event code that you get? If the credentials were successfully validated, the authenticating computer logs this event ID with the Result-Code field equal to “0x0”.

    If the authenticating computer fails to validate the credentials, the same event ID 4776 is logged but with the Result-Code field not equal to “0x0”

    This event generates every time that a credential validation occurs using NTLM authentication. The main advantage of this event is that on domain controllers you can see all authentication attempts for domain accounts when NTLM authentication was used.

    You can read more about this in the below article. Problems with Kerberos authentication when a user belongs to many groups https://learn.microsoft.com/en-us/troubleshoot/windows-server/windows-security/kerberos-authentication-problems-if-user-belongs-to-groups

    4776(S, F): The computer attempted to validate the credentials for an account. https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4776

    -----------------------------------------------------------------------------------------------------------------------------------------------

    --If the reply is helpful, please Upvote and Accept it as an answer–


  2. Paul 1 Reputation point
    2022-05-19T10:33:08.333+00:00

    I am wondering if that could be because user is using network drive?

    I found intresting video on YT and could it be worth flush cache?

    klist purge

    https://www.youtube.com/watch?v=wNSfFBhLywk&ab_channel=SMBitSimplified

    0 comments No comments