Emergency server help: get in touch

Event ID 4625: An Account Failed to Log On (Status Codes)

Event ID 4625 records a failed Windows logon. Decode Logon Type and Status/Sub Status codes, find the source IP and spot brute-force attacks with PowerShell.

Published 7 min read

Short answer: Event ID 4625 is the Security log record for a failed logon, written on the computer where the logon was attempted. Three fields tell you what happened: Logon Type (how), Status/Sub Status (why) and Workstation Name / Source Network Address (from where). 0xC000006A is a wrong password, 0xC0000064 an unknown user name and 0xC0000234 a locked-out account. Many 4625s from one IP across many user names is a brute-force or password-spray attack.

Commands checked against the official documentation (linked below) on 7 October 2026; not yet run on our lab servers.

What event ID 4625 means

PropertyValue
LogSecurity
ProviderMicrosoft-Windows-Security-Auditing
Level / keywordInformation level, Audit Failure keyword
Audit subcategoriesAudit Logon and Audit Account Lockout
Logged onThe computer where the logon was attempted (DC, member server or workstation)

The event title is “An account failed to log on.” The description is grouped into sections. Each field below is followed by its XML name, which is what you filter on in PowerShell:

  • Subject: the account that reported the failure (SubjectUserName).
  • Logon Type (LogonType).
  • Account For Which Logon Failed: Account Name and Account Domain (TargetUserName, TargetDomainName).
  • Failure Information: Failure Reason, Status, Sub Status (FailureReason, Status, SubStatus).
  • Process Information: Caller Process Name (ProcessName).
  • Network Information: Workstation Name, Source Network Address, Source Port (WorkstationName, IpAddress, IpPort).
  • Detailed Authentication Information: Logon Process, Authentication Package, Package Name (NTLM only).

Logon types you will see most:

Logon TypeNameTypical source
2InteractiveKeyboard at the console
3NetworkSMB shares, and RDP when Network Level Authentication checks the password first
4 / 5Batch / ServiceScheduled tasks and services with a stored password
7UnlockUnlocking a locked workstation
8NetworkCleartextBasic authentication, for example IIS
10RemoteInteractiveRemote Desktop
11CachedInteractiveLogon with cached domain credentials

Status is often the generic 0xC000006D. Sub Status then holds the specific reason. Descriptions below are from Microsoft’s 4625 and 4776 pages and the NTSTATUS reference:

CodeMeaningUsual cause
0xC000006DBad user name or authentication information (generic)Read Sub Status
0xC000006AMisspelled or bad passwordTypo, stale saved password, password guessing
0xC0000064User name does not existTypo, deleted account, attacker trying common names
0xC0000234Account locked outLockout threshold reached
0xC0000072Account disabledLeaver account or service still in use
0xC000006FLogon outside authorized hoursLogon Hours restriction
0xC0000070Logon from unauthorized workstation“Log On To” restriction
0xC0000193Account expiredAccount expiry date passed
0xC0000071Password expiredUser must change password
0xC0000224User must change password at next logonFlag set by an admin
0xC000015BLogon type not grantedMissing user right, e.g. RDP or “log on as a batch job”
0xC0000133Clock difference with the DC too largeTime sync problem

Common causes

  • Stale saved credentials after a password change: mapped drives, Credential Manager, services, scheduled tasks, phones.
  • Brute force or password spraying against RDP or SMB exposed to the internet, usually Logon Type 3 or 10 with names like administrator or admin.
  • Account state: disabled, expired or locked-out accounts still in use.
  • Restrictions: logon hours, allowed workstations or missing logon rights.

How to find the cause

Reading the Security log needs an elevated prompt. 4625 is only written if failure auditing is on; check with auditpol /get /subcategory:"Logon". This collects the last 24 hours into a table:

$events = Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625; StartTime=(Get-Date).AddHours(-24)} -ErrorAction SilentlyContinue
$rows = foreach ($e in $events) {
  $d = @{}
  ([xml]$e.ToXml()).Event.EventData.Data | ForEach-Object { $d[$_.Name] = $_.'#text' }
  [pscustomobject]@{
    Time        = $e.TimeCreated
    User        = "$($d.TargetDomainName)\$($d.TargetUserName)"
    LogonType   = $d.LogonType
    Status      = $d.Status
    SubStatus   = $d.SubStatus
    Workstation = $d.WorkstationName
    SourceIP    = $d.IpAddress
    Process     = $d.ProcessName
  }
}
$rows | Sort-Object Time -Descending | Format-Table -AutoSize

Spot brute force by grouping on source address:

$rows | Group-Object SourceIP | Sort-Object Count -Descending | Select-Object -First 10 Count, Name,
  @{n='Users'; e={ ($_.Group.User | Sort-Object -Unique | Select-Object -First 5) -join ', ' }}

Many attempts from one public IP spread across many names is spraying. Many attempts on one name from one internal IP is usually a device with an old password. A Source Network Address of -, ::1 or 127.0.0.1 means the attempt was local; use Process to find what made it.

On domain controllers, a domain account failing on a member server shows up as 4771 (Kerberos) or 4776 (NTLM), not 4625. 4625 stays on the machine where the logon was attempted.

In the console: Event Viewer > Windows Logs > Security > Filter Current Log, enter 4625. Open an event and read Failure Information and Network Information.

How to fix it

Wrong password from a known device (0xC000006A)

Find the device by Workstation Name or Source Network Address and update the saved password. Check Credential Manager, mapped drives and phones. List services and tasks running as the account with Get-CimInstance Win32_Service | Where-Object StartName -like '*bob*' and Get-ScheduledTask | Where-Object { $_.Principal.UserId -like '*bob*' }.

Brute force from the internet

Do not leave RDP open to the internet. Put it behind a VPN or RD Gateway, keep NLA on and set an account lockout policy. Our guide to blocking RDP brute force on Windows Server covers this step by step. Our RDP brute force blocker script reads 4625 and adds firewall blocks.

Account state (0xC0000072, 0xC0000193, 0xC0000234, 0xC0000071, 0xC0000224)

Confirm the account should be active, then fix it with the AD module: Enable-ADAccount bob, Clear-ADAccountExpiration bob or Unlock-ADAccount bob. Have the user set a new password for 0xC0000071 and 0xC0000224. For lockouts, find the source first; see our event 4740 lockout source guide.

Restrictions (0xC000006F, 0xC0000070, 0xC000015B)

Check Logon Hours and Log On To on the account. For 0xC000015B, review User Rights Assignment (for example “Allow log on through Remote Desktop Services” and the matching “Deny” rights) with gpresult /h on the target server.

Check that it worked

Rerun the collection with StartTime set to the time of your fix. The user or IP you fixed should drop out. For attack traffic, count failures per hour and confirm the curve falls after blocking:

$rows | Group-Object { $_.Time.ToString('yyyy-MM-dd HH:00') } | Sort-Object Name | Format-Table Count, Name

Common problems

  • No 4625 events at all: failure auditing is off. Enable it with auditpol /set /subcategory:"Logon" /failure:enable or, better, through an audit policy GPO.
  • Workstation Name is empty: common with network logons. Use Source Network Address and Source Port instead.
  • Get-WinEvent says “No events were found”: that is an error, not empty output; -ErrorAction SilentlyContinue handles it.
Event IDWhat it means
4624An account was successfully logged on.
4740A user account was locked out (Caller Computer Name shows the source).
4767A user account was unlocked.
4771Kerberos pre-authentication failed (DC only). See our Event ID 4771 page.
4776The computer attempted to validate the credentials for an account (NTLM).
4648A logon was attempted using explicit credentials.

Official documentation: 4625(F): An account failed to log on · 4776(S, F): credential validation (NTLM) error codes · NTSTATUS values

Related: Block RDP Brute Force on Windows Server: Detect and Stop It · Block RDP Brute Force on Windows Server: PowerShell Script · AD Account Lockout Source: Event 4740 Tracing · RDP Connection Logs: 14 Event IDs to Track Who Connected and From Where · Active Directory Audit Policy: DC Settings and 35 Key Event IDs

See also: Event ID 4771: Kerberos Pre-Authentication Failed (Codes) · AD Account Lockout Source: Event 4740 Tracing

Frequently asked questions

What is the difference between Status and Sub Status in event 4625?

Status is the main failure code, often the generic 0xC000006D. Sub Status gives the specific reason, such as 0xC000006A (bad password) or 0xC0000064 (unknown user).

Which logon type is RDP in event 4625?

Remote Desktop is type 10 (RemoteInteractive). With Network Level Authentication the password is checked before the session starts, so failed RDP attempts often appear as type 3.

How many 4625 events mean a brute-force attack?

There is no fixed number. Dozens per minute from one external IP, or one IP trying many user names, is an attack. A few per hour for one user from an internal IP is usually a stale password.

Why is the source IP missing in event 4625?

Local logons show 127.0.0.1, ::1 or a dash. Some network logons do not record an address. Use Workstation Name, Process Name and the matching DC events (4771, 4776).

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.