Question on Advanced Threat Analytics

Yao Lu 40 Reputation points
2024-01-02T21:03:52.8+00:00

We're using SSO inside the org and still using on-premise ATA to monitor the alert of on-premise AD.

I logged into a server before in the office, and didn't log out. Today I worked from home and connected with our VPN, then I received an alert from ATA as following:

User's image

The error report indicates PreauthenticationRequired for krbtgt/(domain name). I wonder what the possible reason is.

Thank you.

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
5,771 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,939 questions
0 comments No comments
{count} votes

Accepted answer
  1. Thameur-BOURBITA 36,251 Reputation points
    2024-01-02T23:47:09.1266667+00:00

    Hi @Yao Lu

    I think you get this alert because the option "Do not require Kerberos preauthentication" is set on your account and when you connected without logout before, you used the kerberos ticket in the cache instead new kerberos ticket to preauthenticate to your domain.

    Try to logout and logon and if you don't get the same error your can neglect it.


    Please don't forget to accept helpful answer


1 additional answer

Sort by: Most helpful
  1. Daisy Zhou 32,421 Reputation points Microsoft External Staff
    2024-01-03T03:33:10.2533333+00:00

    Hello Yao Lu,

    Thank you for posting in Q&A forum.

    Please check if you can see event ID 4771 on one of the Domain Controllers with the same timestamp as the alert above.

    4771(F): Kerberos pre-authentication failed.

    This event (event ID 4771) is not generated if "Do not require Kerberos preauthentication" option is set for the account.

    You can check if your account set this option.
    Untitled

    4771(F): Kerberos pre-authentication failed.

    https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4771

    If you have any question or concern, please feel free to let us know.

    Best Regards,

    Daisy Zhou

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.