4771
Kerberos pre-authentication failed
- Log: Security
- Source: Microsoft-Windows-Security-Auditing
- Kerberos & NTLM
- Warning
What it means
A Kerberos sign-in failed on a domain controller. Failure code 0x18 means a wrong password. Includes the client IP address.
Why it matters
The best way to find lockout sources when 4740 doesn’t name a computer.
What to do
- Use Client Address to find the device.
- Many 0x18 failures across accounts suggest password spraying.
Find it with PowerShell
Get-WinEvent -MaxEvents 20 -FilterHashtable @{
LogName = 'Security'; Id = 4771
} | Select-Object TimeCreated, ProviderName, MessageAdd -ComputerName SERVER to query another machine. Other event sources can reuse the same ID number, so check the ProviderName column.
Step-by-step guide
Source
Seeing a lot of these? We can investigate, or alert you automatically through our monitoring.
Talk to us