← Event ID reference
4768

A Kerberos authentication ticket (TGT) was requested

  • Log: Security
  • Source: Microsoft-Windows-Security-Auditing
  • Kerberos & NTLM
  • Info

What it means

Logged on domain controllers when a user or computer first authenticates to the domain. A failure code is included when it fails.

Why it matters

The client IP address here helps trace where a sign-in really came from.

What to do

  • Filter on Result Code other than 0x0 to see failures.
  • Watch for requests using weak encryption (RC4, type 0x17).

Find it with PowerShell

Get-WinEvent -MaxEvents 20 -FilterHashtable @{
  LogName = 'Security'; Id = 4768
} | Select-Object TimeCreated, ProviderName, Message

Add -ComputerName SERVER to query another machine. Other event sources can reuse the same ID number, so check the ProviderName column.

Source

Seeing a lot of these? We can investigate, or alert you automatically through our monitoring.

Talk to us