← Event ID reference
4771

Kerberos pre-authentication failed

  • Log: Security
  • Source: Microsoft-Windows-Security-Auditing
  • Kerberos & NTLM
  • Warning

What it means

A Kerberos sign-in failed on a domain controller. Failure code 0x18 means a wrong password. Includes the client IP address.

Why it matters

The best way to find lockout sources when 4740 doesn’t name a computer.

What to do

  • Use Client Address to find the device.
  • Many 0x18 failures across accounts suggest password spraying.

Find it with PowerShell

Get-WinEvent -MaxEvents 20 -FilterHashtable @{
  LogName = 'Security'; Id = 4771
} | Select-Object TimeCreated, ProviderName, Message

Add -ComputerName SERVER to query another machine. Other event sources can reuse the same ID number, so check the ProviderName column.

Step-by-step guide

Find the source of Active Directory account lockouts

Source

Seeing a lot of these? We can investigate, or alert you automatically through our monitoring.

Talk to us