# Event ID 4771: Kerberos Pre-Authentication Failed (Codes)

Source: https://srvscripts.com/guides/event-id-4771-kerberos-pre-authentication-failed/
Updated: 2026-10-07
Publisher: srvScripts (https://srvscripts.com/)

**Short answer:** Event ID 4771 is logged on a domain controller when it refuses to issue a Kerberos ticket-granting ticket because pre-authentication failed. The **Failure Code** gives the reason: 0x18 wrong password, 0x12 account disabled, expired or locked out, 0x17 password expired, 0x25 clock skew. **Client Address** is the IP of the device that sent the bad credentials. Repeated 0x18 from one address for one user is the classic lockout source; feed that IP into your 4740 investigation.

Commands checked against the official documentation (linked below) on 7 October 2026; not yet run on our lab servers.

## What event ID 4771 means

| Property | Value |
| --- | --- |
| Log | Security |
| Provider | Microsoft-Windows-Security-Auditing |
| Level / keyword | Information level, Audit Failure keyword |
| Audit subcategory | Audit Kerberos Authentication Service |
| Logged on | Domain controllers only |

The event title is **“Kerberos pre-authentication failed.”** Fields as Event Viewer shows them, with the XML name in brackets:

- **Account Information**: Security ID (TargetSid), Account Name (TargetUserName). Computer accounts end in $.

- **Service Information**: Service Name (ServiceName), normally `krbtgt/CONTOSO` or `krbtgt/CONTOSO.LOCAL`.

- **Network Information**: Client Address (IpAddress, often in `::ffff:192.168.1.25` form) and Client Port (IpPort).

- **Additional Information**: Ticket Options (TicketOptions), Failure Code (Status), Pre-Authentication Type (PreAuthType; 2 is a normal password logon, 15 a smart card).

- **Certificate Information**: always empty for 4771.

Microsoft notes that 4771 is not generated for accounts with “Do not require Kerberos preauthentication” set.

Failure codes come from RFC 4120. Microsoft’s 4771 page lists the full set; these are the ones that matter in practice. Causes are from Microsoft’s 4771 and 4768 pages:

| Code | Name | Meaning / usual cause |
| --- | --- | --- |
| 0x18 | KDC_ERR_PREAUTH_FAILED | Pre-authentication information was invalid: wrong password |
| 0x12 | KDC_ERR_CLIENT_REVOKED | Client’s credentials revoked: account disabled, expired or locked out |
| 0x17 | KDC_ERR_KEY_EXPIRED | Password has expired |
| 0x25 | KRB_AP_ERR_SKEW | Clock skew too great between client and DC |
| 0x10 | KDC_ERR_PADATA_TYPE_NOSUPP | Smart card logon: the DC has no suitable certificate, or the CA cannot be reached |
| 0xE | KDC_ERR_ETYPE_NOSUPP | KDC has no support for the encryption type requested |
| 0x6 | KDC_ERR_C_PRINCIPAL_UNKNOWN | Client not found in the Kerberos database (user name does not exist) |
| 0x7 | KDC_ERR_S_PRINCIPAL_UNKNOWN | Server not found in the Kerberos database |

A note on 0x6: Microsoft’s 4768 page lists 0x6 among failed TGT request codes worth monitoring. If you are hunting unknown user names, look at 4768 failures as well as 4771.

## Common causes

- **Stale password on a device** (0x18): a phone, a mapped drive, a service, a scheduled task or a disconnected RDP session still using the old password.

- **Password guessing** (0x18 across many accounts or at high volume).

- **Account state** (0x12, 0x17): disabled, expired, locked out or password expired.

- **Time** (0x25): the client clock is outside the Kerberos tolerance (five minutes by default).

- **Encryption or smart card configuration** (0xE, 0x10).

**How 4771 relates to 4625 and 4740:** when bob types a wrong password on a member server, that server logs 4625 (Sub Status 0xC000006A). The DC logs 4771 with 0x18 and the client IP. DCs forward bad-password attempts to the PDC emulator, so the same failure can appear on more than one DC. Once the lockout threshold is reached, 4740 is logged with the Caller Computer Name. Later Kerberos attempts then fail with 0x12.

## How to find the cause

Run this from a machine with the ActiveDirectory module, as an account that can read DC Security logs. It queries every DC for the last four hours and pulls the key fields:

```
$user  = 'bob'
$start = (Get-Date).AddHours(-4)
$rows = foreach ($dc in (Get-ADDomainController -Filter *).HostName) {
  Get-WinEvent -ComputerName $dc -FilterHashtable @{LogName='Security'; Id=4771; StartTime=$start} -ErrorAction SilentlyContinue |
    ForEach-Object {
      $d = @{}
      ([xml]$_.ToXml()).Event.EventData.Data | ForEach-Object { $d[$_.Name] = $_.'#text' }
      [pscustomobject]@{
        DC          = $dc
        Time        = $_.TimeCreated
        User        = $d.TargetUserName
        FailureCode = $d.Status
        ClientIP    = ($d.IpAddress -replace '^::ffff:', '')
        PreAuthType = $d.PreAuthType
      }
    }
}
$rows | Where-Object User -eq $user | Sort-Object Time | Format-Table -AutoSize
$rows | Where-Object User -eq $user | Group-Object ClientIP, FailureCode | Sort-Object Count -Descending | Format-Table Count, Name
```

Turn the top IP into a name with `Resolve-DnsName 192.168.1.25`, or check your DHCP leases. Drop the `Where-Object User` filter to see every account; many user names failing from one IP is password spraying.

**In the console:** on a DC, Event Viewer > Windows Logs > Security > Filter Current Log, enter 4771. Read Failure Code and Client Address. Start with the PDC emulator (`(Get-ADDomain).PDCEmulator`).

## How to fix it

### 0x18: wrong password

Go to the device at Client Address. Update or remove the stale credential: Credential Manager, mapped drives, mail profiles on phones, services and scheduled tasks running as the user, and old RDP sessions (`quser /server:host`). If the IP is unknown or external-facing, treat it as an attack and block it.

### 0x12 and 0x17: account state

Check the account with `Get-ADUser bob -Properties Enabled, LockedOut, AccountExpirationDate, PasswordExpired`. Fix only what is intended: `Unlock-ADAccount`, `Enable-ADAccount`, `Clear-ADAccountExpiration`, or a password change by the user. Unlocking without removing the stale credential just locks the account again.

### 0x25: clock skew

Compare the client clock with the DC (`w32tm /stripchart /computer:dc01.contoso.local /samples:3`) and fix the time hierarchy. Our [PDC emulator NTP guide](/guides/pdc-emulator-ntp-time-sync/) covers the root of it.

### 0xE and 0x10: encryption type or smart card

0xE often appears while you remove RC4. Check the account’s supported encryption types; our [Kerberos RC4 removal guide](/guides/kerberos-rc4-removal-audit/) covers that. For 0x10, make sure each DC has a valid Domain Controller or Domain Controller Authentication certificate.

## Check that it worked

Rerun the query with `$start` set to the time of your fix. The user and IP you fixed should have no new 4771 events, and the account should stay unlocked (`(Get-ADUser bob -Properties LockedOut).LockedOut` returns False).

### Common problems

- **No 4771 at all:** Kerberos Authentication Service failure auditing is off on the DCs. Check with `auditpol /get /subcategory:"Kerberos Authentication Service"`.

- **Client Address is a server, not a PC:** look at that server’s own 4625 events, services and IIS application pools.

- **Client Address is a VPN, proxy or NAT address:** the real device is behind it; check the VPN or proxy logs.

- **Get-WinEvent -ComputerName is denied:** you need rights to read the remote Security log and access through the firewall.

## Related events

| Event ID | What it means |
| --- | --- |
| 4768 | A Kerberos authentication ticket (TGT) was requested. Failures here cover codes such as 0x6. |
| 4769 | A Kerberos service ticket was requested. |
| 4776 | NTLM credential validation on the DC (Error Code 0xC000006A = bad password). |
| 4625 | An account failed to log on, on the target machine. See our Event ID 4625 page. |
| 4740 | A user account was locked out. |
| 4767 | A user account was unlocked. |

**Official documentation:** [4771(F): Kerberos pre-authentication failed](https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4771) · [4768(S, F): A Kerberos authentication ticket (TGT) was requested](https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4768) · [Audit Kerberos Authentication Service](https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/audit-kerberos-authentication-service)

**Related:** [AD Account Lockout Source: Event 4740 Tracing](/guides/ad-account-lockout-source-event-4740/) · [Locked Out AD Users Report: PowerShell Script with Lockout Source](/scripts/ad-locked-out-users-report/) · [Kerberos RC4 Removal: Find and Fix RC4 Accounts (2026)](/guides/kerberos-rc4-removal-audit/) · [Active Directory Audit Policy: DC Settings and 35 Key Event IDs](/guides/active-directory-audit-policy/)

**See also:** [Event ID 4625: An Account Failed to Log On (Status Codes)](/guides/event-id-4625-failed-logon/) · [AD Account Lockout Source: Event 4740 Tracing](/guides/ad-account-lockout-source-event-4740/) · [Kerberos RC4 Removal: Find and Fix RC4 Accounts (2026)](/guides/kerberos-rc4-removal-audit/)

## Frequently asked questions

### What does failure code 0x18 mean in event 4771?

KDC_ERR_PREAUTH_FAILED: the password was wrong. Repeated 0x18 for one user from one Client Address is almost always a device with a stale password.

### Why do I see 4771 for computer accounts ending in $?

Usually the computer’s machine password no longer matches AD, for example after a snapshot revert. Repair the secure channel on that computer (see our Event ID 5805 page).

### Is event 4771 logged on workstations?

No. It is generated only on domain controllers. The workstation or server logs 4625 for the same failed logon.

### What is the difference between 4771 and 4776?

4771 is a failed Kerberos pre-authentication. 4776 is NTLM credential validation. A wrong password produces one or the other depending on which protocol the client used.
