Short answer: Event ID 4625 is the Security log record for a failed logon, written on the computer where the logon was attempted. Three fields tell you what happened: Logon Type (how), Status/Sub Status (why) and Workstation Name / Source Network Address (from where). 0xC000006A is a wrong password, 0xC0000064 an unknown user name and 0xC0000234 a locked-out account. Many 4625s from one IP across many user names is a brute-force or password-spray attack.
Commands checked against the official documentation (linked below) on 7 October 2026; not yet run on our lab servers.
Table of Contents
What event ID 4625 means
| Property | Value |
|---|---|
| Log | Security |
| Provider | Microsoft-Windows-Security-Auditing |
| Level / keyword | Information level, Audit Failure keyword |
| Audit subcategories | Audit Logon and Audit Account Lockout |
| Logged on | The computer where the logon was attempted (DC, member server or workstation) |
The event title is “An account failed to log on.” The description is grouped into sections. Each field below is followed by its XML name, which is what you filter on in PowerShell:
- Subject: the account that reported the failure (SubjectUserName).
- Logon Type (LogonType).
- Account For Which Logon Failed: Account Name and Account Domain (TargetUserName, TargetDomainName).
- Failure Information: Failure Reason, Status, Sub Status (FailureReason, Status, SubStatus).
- Process Information: Caller Process Name (ProcessName).
- Network Information: Workstation Name, Source Network Address, Source Port (WorkstationName, IpAddress, IpPort).
- Detailed Authentication Information: Logon Process, Authentication Package, Package Name (NTLM only).
Logon types you will see most:
| Logon Type | Name | Typical source |
|---|---|---|
| 2 | Interactive | Keyboard at the console |
| 3 | Network | SMB shares, and RDP when Network Level Authentication checks the password first |
| 4 / 5 | Batch / Service | Scheduled tasks and services with a stored password |
| 7 | Unlock | Unlocking a locked workstation |
| 8 | NetworkCleartext | Basic authentication, for example IIS |
| 10 | RemoteInteractive | Remote Desktop |
| 11 | CachedInteractive | Logon with cached domain credentials |
Status is often the generic 0xC000006D. Sub Status then holds the specific reason. Descriptions below are from Microsoft’s 4625 and 4776 pages and the NTSTATUS reference:
| Code | Meaning | Usual cause |
|---|---|---|
| 0xC000006D | Bad user name or authentication information (generic) | Read Sub Status |
| 0xC000006A | Misspelled or bad password | Typo, stale saved password, password guessing |
| 0xC0000064 | User name does not exist | Typo, deleted account, attacker trying common names |
| 0xC0000234 | Account locked out | Lockout threshold reached |
| 0xC0000072 | Account disabled | Leaver account or service still in use |
| 0xC000006F | Logon outside authorized hours | Logon Hours restriction |
| 0xC0000070 | Logon from unauthorized workstation | “Log On To” restriction |
| 0xC0000193 | Account expired | Account expiry date passed |
| 0xC0000071 | Password expired | User must change password |
| 0xC0000224 | User must change password at next logon | Flag set by an admin |
| 0xC000015B | Logon type not granted | Missing user right, e.g. RDP or “log on as a batch job” |
| 0xC0000133 | Clock difference with the DC too large | Time sync problem |
Common causes
- Stale saved credentials after a password change: mapped drives, Credential Manager, services, scheduled tasks, phones.
- Brute force or password spraying against RDP or SMB exposed to the internet, usually Logon Type 3 or 10 with names like administrator or admin.
- Account state: disabled, expired or locked-out accounts still in use.
- Restrictions: logon hours, allowed workstations or missing logon rights.
How to find the cause
Reading the Security log needs an elevated prompt. 4625 is only written if failure auditing is on; check with auditpol /get /subcategory:"Logon". This collects the last 24 hours into a table:
$events = Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625; StartTime=(Get-Date).AddHours(-24)} -ErrorAction SilentlyContinue
$rows = foreach ($e in $events) {
$d = @{}
([xml]$e.ToXml()).Event.EventData.Data | ForEach-Object { $d[$_.Name] = $_.'#text' }
[pscustomobject]@{
Time = $e.TimeCreated
User = "$($d.TargetDomainName)\$($d.TargetUserName)"
LogonType = $d.LogonType
Status = $d.Status
SubStatus = $d.SubStatus
Workstation = $d.WorkstationName
SourceIP = $d.IpAddress
Process = $d.ProcessName
}
}
$rows | Sort-Object Time -Descending | Format-Table -AutoSize
Spot brute force by grouping on source address:
$rows | Group-Object SourceIP | Sort-Object Count -Descending | Select-Object -First 10 Count, Name,
@{n='Users'; e={ ($_.Group.User | Sort-Object -Unique | Select-Object -First 5) -join ', ' }}
Many attempts from one public IP spread across many names is spraying. Many attempts on one name from one internal IP is usually a device with an old password. A Source Network Address of -, ::1 or 127.0.0.1 means the attempt was local; use Process to find what made it.
On domain controllers, a domain account failing on a member server shows up as 4771 (Kerberos) or 4776 (NTLM), not 4625. 4625 stays on the machine where the logon was attempted.
In the console: Event Viewer > Windows Logs > Security > Filter Current Log, enter 4625. Open an event and read Failure Information and Network Information.
How to fix it
Wrong password from a known device (0xC000006A)
Find the device by Workstation Name or Source Network Address and update the saved password. Check Credential Manager, mapped drives and phones. List services and tasks running as the account with Get-CimInstance Win32_Service | Where-Object StartName -like '*bob*' and Get-ScheduledTask | Where-Object { $_.Principal.UserId -like '*bob*' }.
Brute force from the internet
Do not leave RDP open to the internet. Put it behind a VPN or RD Gateway, keep NLA on and set an account lockout policy. Our guide to blocking RDP brute force on Windows Server covers this step by step. Our RDP brute force blocker script reads 4625 and adds firewall blocks.
Account state (0xC0000072, 0xC0000193, 0xC0000234, 0xC0000071, 0xC0000224)
Confirm the account should be active, then fix it with the AD module: Enable-ADAccount bob, Clear-ADAccountExpiration bob or Unlock-ADAccount bob. Have the user set a new password for 0xC0000071 and 0xC0000224. For lockouts, find the source first; see our event 4740 lockout source guide.
Restrictions (0xC000006F, 0xC0000070, 0xC000015B)
Check Logon Hours and Log On To on the account. For 0xC000015B, review User Rights Assignment (for example “Allow log on through Remote Desktop Services” and the matching “Deny” rights) with gpresult /h on the target server.
Check that it worked
Rerun the collection with StartTime set to the time of your fix. The user or IP you fixed should drop out. For attack traffic, count failures per hour and confirm the curve falls after blocking:
$rows | Group-Object { $_.Time.ToString('yyyy-MM-dd HH:00') } | Sort-Object Name | Format-Table Count, Name
Common problems
- No 4625 events at all: failure auditing is off. Enable it with
auditpol /set /subcategory:"Logon" /failure:enableor, better, through an audit policy GPO. - Workstation Name is empty: common with network logons. Use Source Network Address and Source Port instead.
- Get-WinEvent says “No events were found”: that is an error, not empty output;
-ErrorAction SilentlyContinuehandles it.
Related events
| Event ID | What it means |
|---|---|
| 4624 | An account was successfully logged on. |
| 4740 | A user account was locked out (Caller Computer Name shows the source). |
| 4767 | A user account was unlocked. |
| 4771 | Kerberos pre-authentication failed (DC only). See our Event ID 4771 page. |
| 4776 | The computer attempted to validate the credentials for an account (NTLM). |
| 4648 | A logon was attempted using explicit credentials. |
Official documentation: 4625(F): An account failed to log on · 4776(S, F): credential validation (NTLM) error codes · NTSTATUS values
Related: Block RDP Brute Force on Windows Server: Detect and Stop It · Block RDP Brute Force on Windows Server: PowerShell Script · AD Account Lockout Source: Event 4740 Tracing · RDP Connection Logs: 14 Event IDs to Track Who Connected and From Where · Active Directory Audit Policy: DC Settings and 35 Key Event IDs
See also: Event ID 4771: Kerberos Pre-Authentication Failed (Codes) · AD Account Lockout Source: Event 4740 Tracing
Frequently asked questions
What is the difference between Status and Sub Status in event 4625?
Status is the main failure code, often the generic 0xC000006D. Sub Status gives the specific reason, such as 0xC000006A (bad password) or 0xC0000064 (unknown user).
Which logon type is RDP in event 4625?
Remote Desktop is type 10 (RemoteInteractive). With Network Level Authentication the password is checked before the session starts, so failed RDP attempts often appear as type 3.
How many 4625 events mean a brute-force attack?
There is no fixed number. Dozens per minute from one external IP, or one IP trying many user names, is an attack. A few per hour for one user from an internal IP is usually a stale password.
Why is the source IP missing in event 4625?
Local logons show 127.0.0.1, ::1 or a dash. Some network logons do not record an address. Use Workstation Name, Process Name and the matching DC events (4771, 4776).