Event id 4625(An account failed to logon)

Shabana Thasneem 1 Reputation point
2022-07-18T09:55:55.94+00:00

I have been getting this event 4625 regularly after a particular account's password has changed with failure code as unknown username or bad password from a single machine, the same user has been successfully logging from other machines in domain controller.
I have checked for any services were running using previous credentials and also whether any cached credentials stored there, but nothing worked.

Does anyone have any suggestion on this?

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Client for IT Pros | User experience | Other
{count} votes

1 answer

Sort by: Most helpful
  1. rr-4098 2,051 Reputation points
    2022-07-19T15:13:24.17+00:00

    It sounds like there are cached credentials on the workstation / server. Have you checked credential manager or run klist as "system" using psexec to check for any user session as well?

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.