Hello SchwandtnerBoris-0763,
Thank you for your reply.
1.Please check whether the AD replication is OK.
2.Have you configured "Audit Logon Events – Success and Failure"?
GPO: Default Domain Controller Policy
Legacy audit policy:
Computer Configuration\Windows settings\security settings\local policies\audit policy
Audit Logon Events – Success and Failure
Or use advanced audit policies (advanced audit policies will overwrite all legacy audit policies by default):
Computer Configuration\Windows settings\security settings\Advanced Audit Policy Configuration
Logon/Logoff:
Audit Logon – Success and Failure
Audit Logoff – Success and Failure
Audit Account Lockout – Success and Failure
If so, you can try to log on the DC using one incorrect domain account and check if there is any event 4625.
Tip: There is only auditing Success result for the default Audit Logoff settings on DC.

Best Regards,
Daisy Zhou
============================================
If the Answer is helpful, please click "Accept Answer" and upvote it.