Kerberos pre-authentication failed after changing domain administrator password

Kamesh Patil 0 Reputation points
2025-04-08T07:24:21.3533333+00:00

Repeated event generation of Kerberos pre-authentication failed with event ID 4771 and failure code 0x18 and the event is generating from multiple instances targeting event source to domain controller.

The issue occurred after change the domain administrator password and unable to dig insides to find the root cause of generation. As since we already update the scheduler service in all member servers.

" Kerberos pre-authentication failed. Account Information: Security ID: S-1-5-21-16834707280-224241925-162353504729-500 Account Name: Administrator Service Information: Service Name: krbtgt/veeamsw.com Network Information: Client Address: ::ffff:172.16.36.3 Client Port: 65280 Additional Information: Ticket Options: 0x40810010 Failure Code: 0x18 Pre-Authentication Type: 2 Certificate Information: Certificate Issuer Name: Certificate Serial Number: Certificate Thumbprint: Certificate information is only provided if a certificate was used for pre-authentication. Pre-authentication types, ticket options and failure codes are defined in RFC 4120. If the ticket was malformed or damaged during transit and could not be decrypted, then many fields in this event might not be present."

Windows Small Business Server
Windows Small Business Server
A family of Microsoft server products with messaging and collaboration, security-enhanced internet access, protected data storage, reliable printing, faxing, and the ability to run line-of-business applications. Replaced by Windows Server Essentials.
47 questions
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.