Credential Validation Audit Failure -Event ID 4776 - MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 - Error Code: 0xc000006a/0xC0000234

Andrew Saliba 20 Reputation points
2024-04-03T18:58:29.9233333+00:00

Hello all, thanks for reading and attempting to help,

I have been having an ongoing issue for the past month or so with having my account get locked multiple times throughout the day due to error listed in the title. Every time it happens I go check event viewer for my DC but it isn't very helpful, it doesn't even list a workstation where the failed credentials is coming from. I've read similar posts and have tried removing all cached credentials (on all devices), making sure I have no scheduled/startup tasks using my account, etc. I also haven't mapped any new drives or anything. Nothing has worked.

I'm thinking some service or something is using outdated password but I cannot for the life of me figure this out. Any suggestions or ideas would be greatly appreciated. Thanks.

Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,727 questions
0 comments No comments
{count} votes

Accepted answer
  1. Daisy Zhou 18,706 Reputation points Microsoft Vendor
    2024-04-05T02:07:01.14+00:00

    Hello Andrew Saliba,

    Thank you for posting in Q&A forum.

    Do you have more than one Domain Controller in this domain? If so, maybe the account was locked on multiple DCs, we can check the security log (event ID 4776 and event ID 4740) about this account on non-PDC.

    Please check the "Account Lockout threshold" value, and if "Account Lockout threshold" value is 5, you will see 5 entries event IDs of 4776 and then you will see the event ID of 4740, 4740 means the account is locked out.

    Please check if you can see "caller computer name" through event 4776 or event ID 4740.

    The first thing we should check is: which machine the account is locked on, then we can check which app/program is using the wrong credential of this account, at last, we can delete/remove the wrong credential on specific app/program.

    I hope the information above is helpful.

    If you have any questions or concerns, please feel free to let us know.

    Best Regards,

    Daisy Zhou

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.


0 additional answers

Sort by: Most helpful