Emergency server help: get in touch

Event ID 4771: Kerberos Pre-Authentication Failed (Codes)

Event ID 4771 is a failed Kerberos pre-authentication on a domain controller. Decode failure codes 0x18, 0x12, 0x17, 0x25 and find the client IP behind lockouts.

Published 6 min read

Short answer: Event ID 4771 is logged on a domain controller when it refuses to issue a Kerberos ticket-granting ticket because pre-authentication failed. The Failure Code gives the reason: 0x18 wrong password, 0x12 account disabled, expired or locked out, 0x17 password expired, 0x25 clock skew. Client Address is the IP of the device that sent the bad credentials. Repeated 0x18 from one address for one user is the classic lockout source; feed that IP into your 4740 investigation.

Commands checked against the official documentation (linked below) on 7 October 2026; not yet run on our lab servers.

What event ID 4771 means

PropertyValue
LogSecurity
ProviderMicrosoft-Windows-Security-Auditing
Level / keywordInformation level, Audit Failure keyword
Audit subcategoryAudit Kerberos Authentication Service
Logged onDomain controllers only

The event title is “Kerberos pre-authentication failed.” Fields as Event Viewer shows them, with the XML name in brackets:

  • Account Information: Security ID (TargetSid), Account Name (TargetUserName). Computer accounts end in $.
  • Service Information: Service Name (ServiceName), normally krbtgt/CONTOSO or krbtgt/CONTOSO.LOCAL.
  • Network Information: Client Address (IpAddress, often in ::ffff:192.168.1.25 form) and Client Port (IpPort).
  • Additional Information: Ticket Options (TicketOptions), Failure Code (Status), Pre-Authentication Type (PreAuthType; 2 is a normal password logon, 15 a smart card).
  • Certificate Information: always empty for 4771.

Microsoft notes that 4771 is not generated for accounts with “Do not require Kerberos preauthentication” set.

Failure codes come from RFC 4120. Microsoft’s 4771 page lists the full set; these are the ones that matter in practice. Causes are from Microsoft’s 4771 and 4768 pages:

CodeNameMeaning / usual cause
0x18KDC_ERR_PREAUTH_FAILEDPre-authentication information was invalid: wrong password
0x12KDC_ERR_CLIENT_REVOKEDClient’s credentials revoked: account disabled, expired or locked out
0x17KDC_ERR_KEY_EXPIREDPassword has expired
0x25KRB_AP_ERR_SKEWClock skew too great between client and DC
0x10KDC_ERR_PADATA_TYPE_NOSUPPSmart card logon: the DC has no suitable certificate, or the CA cannot be reached
0xEKDC_ERR_ETYPE_NOSUPPKDC has no support for the encryption type requested
0x6KDC_ERR_C_PRINCIPAL_UNKNOWNClient not found in the Kerberos database (user name does not exist)
0x7KDC_ERR_S_PRINCIPAL_UNKNOWNServer not found in the Kerberos database

A note on 0x6: Microsoft’s 4768 page lists 0x6 among failed TGT request codes worth monitoring. If you are hunting unknown user names, look at 4768 failures as well as 4771.

Common causes

  • Stale password on a device (0x18): a phone, a mapped drive, a service, a scheduled task or a disconnected RDP session still using the old password.
  • Password guessing (0x18 across many accounts or at high volume).
  • Account state (0x12, 0x17): disabled, expired, locked out or password expired.
  • Time (0x25): the client clock is outside the Kerberos tolerance (five minutes by default).
  • Encryption or smart card configuration (0xE, 0x10).

How 4771 relates to 4625 and 4740: when bob types a wrong password on a member server, that server logs 4625 (Sub Status 0xC000006A). The DC logs 4771 with 0x18 and the client IP. DCs forward bad-password attempts to the PDC emulator, so the same failure can appear on more than one DC. Once the lockout threshold is reached, 4740 is logged with the Caller Computer Name. Later Kerberos attempts then fail with 0x12.

How to find the cause

Run this from a machine with the ActiveDirectory module, as an account that can read DC Security logs. It queries every DC for the last four hours and pulls the key fields:

$user  = 'bob'
$start = (Get-Date).AddHours(-4)
$rows = foreach ($dc in (Get-ADDomainController -Filter *).HostName) {
  Get-WinEvent -ComputerName $dc -FilterHashtable @{LogName='Security'; Id=4771; StartTime=$start} -ErrorAction SilentlyContinue |
    ForEach-Object {
      $d = @{}
      ([xml]$_.ToXml()).Event.EventData.Data | ForEach-Object { $d[$_.Name] = $_.'#text' }
      [pscustomobject]@{
        DC          = $dc
        Time        = $_.TimeCreated
        User        = $d.TargetUserName
        FailureCode = $d.Status
        ClientIP    = ($d.IpAddress -replace '^::ffff:', '')
        PreAuthType = $d.PreAuthType
      }
    }
}
$rows | Where-Object User -eq $user | Sort-Object Time | Format-Table -AutoSize
$rows | Where-Object User -eq $user | Group-Object ClientIP, FailureCode | Sort-Object Count -Descending | Format-Table Count, Name

Turn the top IP into a name with Resolve-DnsName 192.168.1.25, or check your DHCP leases. Drop the Where-Object User filter to see every account; many user names failing from one IP is password spraying.

In the console: on a DC, Event Viewer > Windows Logs > Security > Filter Current Log, enter 4771. Read Failure Code and Client Address. Start with the PDC emulator ((Get-ADDomain).PDCEmulator).

How to fix it

0x18: wrong password

Go to the device at Client Address. Update or remove the stale credential: Credential Manager, mapped drives, mail profiles on phones, services and scheduled tasks running as the user, and old RDP sessions (quser /server:host). If the IP is unknown or external-facing, treat it as an attack and block it.

0x12 and 0x17: account state

Check the account with Get-ADUser bob -Properties Enabled, LockedOut, AccountExpirationDate, PasswordExpired. Fix only what is intended: Unlock-ADAccount, Enable-ADAccount, Clear-ADAccountExpiration, or a password change by the user. Unlocking without removing the stale credential just locks the account again.

0x25: clock skew

Compare the client clock with the DC (w32tm /stripchart /computer:dc01.contoso.local /samples:3) and fix the time hierarchy. Our PDC emulator NTP guide covers the root of it.

0xE and 0x10: encryption type or smart card

0xE often appears while you remove RC4. Check the account’s supported encryption types; our Kerberos RC4 removal guide covers that. For 0x10, make sure each DC has a valid Domain Controller or Domain Controller Authentication certificate.

Check that it worked

Rerun the query with $start set to the time of your fix. The user and IP you fixed should have no new 4771 events, and the account should stay unlocked ((Get-ADUser bob -Properties LockedOut).LockedOut returns False).

Common problems

  • No 4771 at all: Kerberos Authentication Service failure auditing is off on the DCs. Check with auditpol /get /subcategory:"Kerberos Authentication Service".
  • Client Address is a server, not a PC: look at that server’s own 4625 events, services and IIS application pools.
  • Client Address is a VPN, proxy or NAT address: the real device is behind it; check the VPN or proxy logs.
  • Get-WinEvent -ComputerName is denied: you need rights to read the remote Security log and access through the firewall.
Event IDWhat it means
4768A Kerberos authentication ticket (TGT) was requested. Failures here cover codes such as 0x6.
4769A Kerberos service ticket was requested.
4776NTLM credential validation on the DC (Error Code 0xC000006A = bad password).
4625An account failed to log on, on the target machine. See our Event ID 4625 page.
4740A user account was locked out.
4767A user account was unlocked.

Official documentation: 4771(F): Kerberos pre-authentication failed · 4768(S, F): A Kerberos authentication ticket (TGT) was requested · Audit Kerberos Authentication Service

Related: AD Account Lockout Source: Event 4740 Tracing · Locked Out AD Users Report: PowerShell Script with Lockout Source · Kerberos RC4 Removal: Find and Fix RC4 Accounts (2026) · Active Directory Audit Policy: DC Settings and 35 Key Event IDs

See also: Event ID 4625: An Account Failed to Log On (Status Codes) · AD Account Lockout Source: Event 4740 Tracing · Kerberos RC4 Removal: Find and Fix RC4 Accounts (2026)

Frequently asked questions

What does failure code 0x18 mean in event 4771?

KDC_ERR_PREAUTH_FAILED: the password was wrong. Repeated 0x18 for one user from one Client Address is almost always a device with a stale password.

Why do I see 4771 for computer accounts ending in $?

Usually the computer’s machine password no longer matches AD, for example after a snapshot revert. Repair the secure channel on that computer (see our Event ID 5805 page).

Is event 4771 logged on workstations?

No. It is generated only on domain controllers. The workstation or server logs 4625 for the same failed logon.

What is the difference between 4771 and 4776?

4771 is a failed Kerberos pre-authentication. 4776 is NTLM credential validation. A wrong password produces one or the other depending on which protocol the client used.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.