Microsoft-Windows-Security-Kerberos
90 events across 3 channels
Event ID 3 —
Fields #
| Name | Description |
|---|---|
LogonSession UnicodeString | — |
ClientTime UnicodeString | — |
ServerTime UnicodeString | — |
ErrorCode UnicodeString | — |
ErrorMessage UnicodeString | — |
ExtendedError UnicodeString | — |
ClientRealm UnicodeString | — |
ClientName UnicodeString | — |
ServerRealm UnicodeString | — |
ServerName UnicodeString | — |
TargetName UnicodeString | — |
ErrorText UnicodeString | — |
File UnicodeString | — |
Line UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 3 —
Fields #
| Name | Description |
|---|---|
LogonSession | — |
ClientTime | — |
ServerTime | — |
ErrorCode | — |
ErrorMessage | — |
ExtendedError | — |
ClientRealm | — |
ClientName | — |
ServerRealm | — |
ServerName | — |
TargetName | — |
ErrorText | — |
File | — |
Line | — |
Binary | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Security-Kerberos",
"guid": "{98E6CFCB-EE0A-41E0-A57B-622D4E1B30B1}",
"event_source_name": "Kerberos",
"event_id": 3,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2026-03-13T23:04:02.620676+00:00",
"event_record_id": 12251,
"correlation": {},
"execution": {
"process_id": 0,
"thread_id": 0
},
"channel": "System",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": ""
}
},
"event_data": {
"LogonSession": "LUDUS.DOMAIN\\domainadmin",
"ClientTime": "",
"ServerTime": "23:4:2.0000 3/13/2026 Z",
"ErrorCode": "0x19",
"ErrorMessage": "KDC_ERR_PREAUTH_REQUIRED",
"ExtendedError": "",
"ClientRealm": "",
"ClientName": "",
"ServerRealm": "ludus",
"ServerName": "krbtgt/ludus",
"TargetName": "krbtgt/ludus@ludus",
"ErrorText": "",
"File": "onecore\\ds\\security\\protocols\\kerberos\\client2\\logonapi.cxx",
"Line": "e00",
"Binary": "30353012A103020113A20B040930073005A0030201173009A103020102A20204003009A103020110A20204003009A10302010FA2020400"
},
"message": ""
}
Event ID 4 —
Fields #
| Name | Description |
|---|---|
Server UnicodeString | — |
TargetRealm UnicodeString | — |
Targetname UnicodeString | — |
ClientRealm UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 4 —
Fields #
| Name | Description |
|---|---|
Server | — |
TargetRealm | — |
Targetname | — |
ClientRealm | — |
Binary | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Security-Kerberos",
"guid": "{98E6CFCB-EE0A-41E0-A57B-622D4E1B30B1}",
"event_source_name": "Kerberos",
"event_id": 4,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2026-03-14T20:59:54.579371+00:00",
"event_record_id": 12914,
"correlation": {},
"execution": {
"process_id": 0,
"thread_id": 0
},
"channel": "System",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": ""
}
},
"event_data": {
"Server": "domainadmin",
"TargetRealm": "LUDUS.DOMAIN",
"Targetname": "rpc/LAB-DC01",
"ClientRealm": "LUDUS.DOMAIN",
"Binary": ""
},
"message": ""
}
Event ID 5 —
Fields #
| Name | Description |
|---|---|
Error UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 5 —
Fields #
| Name | Description |
|---|---|
Server | — |
KDCRealm | — |
Binary | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Security-Kerberos",
"guid": "{98E6CFCB-EE0A-41E0-A57B-622D4E1B30B1}",
"event_source_name": "Kerberos",
"event_id": 5,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2026-02-10T01:12:10.274438+00:00",
"event_record_id": 984,
"correlation": {},
"execution": {
"process_id": 240,
"thread_id": 0
},
"channel": "System",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": ""
}
},
"event_data": {
"Server": "jd-win11-22h2-1$",
"KDCRealm": "LUDUS.DOMAIN",
"Binary": ""
},
"message": ""
}
Event ID 6 —
Fields #
| Name | Description |
|---|---|
Error UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 7 —
Fields #
| Name | Description |
|---|---|
Error UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 8 —
Fields #
| Name | Description |
|---|---|
Error UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 9 —
Fields #
| Name | Description |
|---|---|
Error UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 10 —
Fields #
| Name | Description |
|---|---|
Error UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 11 —
Fields #
| Name | Description |
|---|---|
Error UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 12 —
Fields #
| Name | Description |
|---|---|
Error UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 13 — An error occurred while initializing the smart card logon library: Error.
Event ID 14 —
Fields #
| Name | Description |
|---|---|
Error UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 15 —
Fields #
| Name | Description |
|---|---|
Error UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 16 —
Fields #
| Name | Description |
|---|---|
Error UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 17 —
Fields #
| Name | Description |
|---|---|
Error UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 18 —
Fields #
| Name | Description |
|---|---|
Error UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 19 —
Fields #
| Name | Description |
|---|---|
Error UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 20 —
Fields #
| Name | Description |
|---|---|
DomainName UnicodeString | — |
ErrorCode UnicodeString | — |
Event ID 27 — Kerberos client event 27 (manifest stub).
Event ID 100 — The service principal name (SPN) SPN is not registered, which caused Kerberos authentication to fail: ErrorCode.
Description
The service principal name (SPN) SPN is not registered, which caused Kerberos authentication to fail: ErrorCode. Use the setspn command-line tool to register the SPN.
Message #
Fields #
| Name | Description |
|---|---|
SPN UnicodeString | — |
ErrorCode UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Security-Kerberos",
"guid": "98E6CFCB-EE0A-41E0-A57B-622D4E1B30B1",
"event_source_name": "",
"event_id": 100,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T20:17:40.189125+00:00",
"event_record_id": 1,
"correlation": {},
"execution": {
"process_id": 968,
"thread_id": 8880
},
"channel": "Microsoft-Windows-Kerberos/Operational",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"SPN": "HTTP/nonexistent.domain.local@LUDUS.DOMAIN",
"ErrorCode": 7
},
"message": ""
}
Event ID 101 — The service principal name (SPN) SPN is registered on multiple accounts which caused Kerberos authentication to fail: ErrorCode.
Event ID 102 — Trust validation of the certificate for the Kerberos Key Distribution Center (KDC) DomainController failed: ErrorCode.
Event ID 103 — Trust validation of the client certificate for ClientUpn failed: ErrorCode on KDC.
Event ID 104 — The Kerberos Key Distribution Center (KDC) for the domain TargetDomain does not have a certificate installed or does not support logon using certificates: ErrorCode.
Event ID 105 — The Kerberos client could not retrieve passwords for the group managed service account.
Description
The Kerberos client could not retrieve passwords for the group managed service account.
Message #
Fields #
| Name | Description |
|---|---|
LogonId | — |
DomainName UnicodeString | — |
UserName UnicodeString | — |
Refresh Boolean | — |
Current_File_Time | — |
Error_Code | — |
LuidHighPart UInt32 | — |
LuidLowPart UInt32 | — |
CurrentFileTime UnicodeString | — |
ErrorCode UInt32 | — |
Event ID 106 — The Kerberos client received a KDC certificate that does not have KDC EKU (not based on Kerberos Authentication Template).
Event ID 107 — The Kerberos client received a KDC certificate that does not have a matched domain name.
Event ID 108 — The Kerberos client could not send a Kerberos proxy request.
Description
The Kerberos client could not send a Kerberos proxy request.
Message #
Fields #
| Name | Description |
|---|---|
ServerName UnicodeString | [ProxyServer] ServerName. |
ServerPort UInt32 | [ProxyServer] ServerPort. |
ServerVdir UnicodeString | [ProxyServer] ServerVdir. |
Error_Code UInt32 | [ProxyServer] Error Code. |
Status_Code UInt32 | [ProxyServer] Status Code. |
ErrorCode UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 109 — The Kerberos client could not find a suitable credential to use with the authentication proxy.
Description
The Kerberos client could not find a suitable credential to use with the authentication proxy.
Message #
Fields #
| Name | Description |
|---|---|
Proxy UnicodeString | [AuthProxy] Proxy. |
ProxyBypass UnicodeString | [AuthProxy] ProxyBypass. |
Epoch UInt32 | [AuthProxy] Epoch. |
Supported_Schemes UInt32 | [AuthProxy] Supported Schemes. |
First_Scheme UInt32 | [AuthProxy] First Scheme. |
Initialized Boolean | [Digest Credential] Initialized. |
DomainAndUserName UnicodeString | [Digest Credential] DomainAndUserName. |
Epoch UInt32 | [Digest Credential] Epoch. |
Initialized Boolean | [Basic Credential] Initialized. |
DomainAndUserName UnicodeString | [Basic Credential] DomainAndUserName. |
Epoch UInt32 | [Basic Credential] Epoch. |
ProxyEpoch UInt32 | — |
SupportedSchemes UInt32 | — |
FirstScheme UInt32 | — |
DigestCredInitialized Boolean | — |
DigestCredDomainAndUserName UnicodeString | — |
DigestCredEpoch UInt32 | — |
BasicCredInitialized Boolean | — |
BasicCredDomainAndUserName UnicodeString | — |
BasicCredEpoch UInt32 | — |
Event ID 200 — The Kerberos client could not locate a domain controller for domain TargetDomain: ErrorCode.
Description
The Kerberos client could not locate a domain controller for domain TargetDomain: ErrorCode. Kerberos authentication requires communicating with a domain controller.
Message #
Fields #
| Name | Description |
|---|---|
TargetDomain UnicodeString | — |
ErrorCode UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Security-Kerberos",
"guid": "98E6CFCB-EE0A-41E0-A57B-622D4E1B30B1",
"event_source_name": "",
"event_id": 200,
"version": 0,
"level": 3,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T20:24:08.199756+00:00",
"event_record_id": 2,
"correlation": {},
"execution": {
"process_id": 968,
"thread_id": 10948
},
"channel": "Microsoft-Windows-Kerberos/Operational",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetDomain": "LUDUS.DOMAIN",
"ErrorCode": 3221225572
},
"message": ""
}
Event ID 201 — Attempt to use Kerberos unconstrained delegation failed.
Description
Attempt to use Kerberos unconstrained delegation failed.
Message #
Fields #
| Name | Description |
|---|---|
TargetName UnicodeString | — |
UserName UnicodeString | — |
DomainName UnicodeString | — |
CallerPID UInt32 | — |
ProcessName UnicodeString | — |
ClientLUID HexInt64 | — |
ClientUserName UnicodeString | — |
ClientDomainName UnicodeString | — |
MechanismOID UnicodeString | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Security-Kerberos",
"guid": "98E6CFCB-EE0A-41E0-A57B-622D4E1B30B1",
"event_source_name": "",
"event_id": 201,
"version": 0,
"level": 3,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T20:05:05.241896+00:00",
"event_record_id": 1,
"correlation": {
"ActivityID": "A5B814C5-B324-0003-DC14-B8A524B3DC01"
},
"execution": {
"process_id": 984,
"thread_id": 1072
},
"channel": "Microsoft-Windows-Kerberos/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetName": "cifs/LAB-DC01.ludus.domain",
"UserName": "NULL",
"DomainName": "NULL",
"CallerPID": 4,
"ProcessName": "",
"ClientLUID": "0x3e7",
"ClientUserName": "LAB-WIN11$",
"ClientDomainName": "ludus",
"MechanismOID": "1.2.840.48018.1.2.2"
},
"message": ""
}
Event ID 202 — Attempt to export TGT session key failed.
Description
Attempt to export TGT session key failed.
Message #
Fields #
| Name | Description |
|---|---|
TargetName UnicodeString | — |
UserName UnicodeString | — |
DomainName UnicodeString | — |
CallerPID UInt32 | — |
ProcessName UnicodeString | — |
ClientLUID HexInt64 | — |
ClientUserName UnicodeString | — |
ClientDomainName UnicodeString | — |
MechanismOID UnicodeString | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Security-Kerberos",
"guid": "98E6CFCB-EE0A-41E0-A57B-622D4E1B30B1",
"event_source_name": "",
"event_id": 202,
"version": 0,
"level": 3,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-15T05:16:41.040416+00:00",
"event_record_id": 44,
"correlation": {},
"execution": {
"process_id": 940,
"thread_id": 2768
},
"channel": "Microsoft-Windows-Kerberos/Operational",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetName": "krbtgt/LUDUS.DOMAIN",
"UserName": "domainadmin",
"DomainName": "NULL",
"CallerPID": 3788,
"ProcessName": "C:\\Windows\\System32\\klist.exe",
"ClientLUID": "0x4aa840e",
"ClientUserName": "domainadmin",
"ClientDomainName": "ludus",
"MechanismOID": "NULL"
},
"message": ""
}
Event ID 203 — When Credential Guard is enabled, Kerberos does not accept PKINIT KDC replies using public key encryption to ensure Kerberos tickets cannot be expo...
Message #
Event ID 204 — Kerberos does not accept PKINIT KDC replies using public key encryption.
Description
Kerberos does not accept PKINIT KDC replies using public key encryption.
Message #
Event ID 205 — The KDC used a hash algorithm for the PKINIT protocol that is being audited: Algorithm.
Event ID 206 — The Kerberos client used a hash algorithm for the PKINIT protocol that is being audited: Algorithm.
Event ID 207 — The KDC used a hash algorithm for the PKINIT protocol that is not supported on the client: Algorithm.
Event ID 208 — The Kerberos client and KDC could not agree on a policy compliant hash algorithm for PKINIT.
Event ID 209 — The Kerberos client has an invalid hash algorithm configuration for PKINIT.
Description
The Kerberos client has an invalid hash algorithm configuration for PKINIT. This might result in PKINIT failures.
Message #
Event ID 300 — The Kerberos client discovered domain controller DomainController for the domain TargetDomain.
Event ID 301 — The Kerberos client used credentials from the Credential Manager for the target: 'Target'.
Event ID 302 — The Kerberos client was bound to domain controller DesiredFlags for the domain CacheFlags but could not access this domain controller at the time.
Description
The Kerberos client was bound to domain controller DesiredFlags for the domain CacheFlags but could not access this domain controller at the time.
Message #
Fields #
| Name | Description |
|---|---|
DesiredFlags UInt32 | — |
CacheFlags UInt32 | — |
ErrorCode UInt32 | DesiredFlags. |
DomainController UnicodeString | — |
TargetDomain UnicodeString | — |
Event ID 303 — The Kerberos client updated passwords for the group managed service account.
Description
The Kerberos client updated passwords for the group managed service account.
Message #
Fields #
| Name | Description |
|---|---|
LogonId | — |
DomainName UnicodeString | — |
UserName UnicodeString | — |
Update_Current_Passwords | — |
Update_Old_Passwords | — |
Refresh Boolean | — |
Previous_File_Time | — |
Current_File_Time | — |
LuidHighPart UInt32 | — |
LuidLowPart UInt32 | — |
UpdateCurrent Boolean | — |
UpdateOld Boolean | — |
LastFileTime UnicodeString | — |
CurrentFileTime UnicodeString | — |
Event ID 304 — The Kerberos client used the DES algorithm to encrypt data.
Description
The Kerberos client used the DES algorithm to encrypt data. This is unsupported with Credential Guard.
Message #
Event ID 305 — Export of TGT attempted through call package.
Event ID 306 — Export of supplemental credentials attempted.
Event ID 307 — The Kerberos client has discovered a DMSA migration.
Description
The Kerberos client has discovered a DMSA migration.
Message #
Fields #
| Name | Description |
|---|---|
OldAccount UnicodeString | — |
NewAccount UnicodeString | — |
DomainName UnicodeString | — |
Status UInt32 | — NTSTATUS reference |
MigrationComplete Boolean | — |
Event ID 308 — Adding machine to the Principals Allowed Managed Password attribute of a DMSA.
Description
Adding machine to the Principals Allowed Managed Password attribute of a DMSA.
Message #
Fields #
| Name | Description |
|---|---|
DC UnicodeString | — |
DN UnicodeString | — |
Account UnicodeString | — |
Domain UnicodeString | — |
PreviouslyAuthorized Boolean | — |
Status UInt32 | — NTSTATUS reference |
Event ID 309 — Fetching keys for a DMSA using the machine account.
Description
Fetching keys for a DMSA using the machine account.
Message #
Fields #
| Name | Description |
|---|---|
KDC UnicodeString | — |
Domain UnicodeString | — |
Account UnicodeString | — |
Fetch UnicodeString | — |
Expiration UnicodeString | — |
KeyUpdate Boolean | — |
NtlmUpdate Boolean | — |
Status UInt32 | — NTSTATUS reference |
Event ID 310 — Machine password migrated from LSA to VBS Enforcement Mode.
Event ID 311 — Machine Identity Isolation is currently in enforcement mode.
Description
Machine Identity Isolation is currently in enforcement mode. To go back to disabled/audit mode, you must manually unjoin and rejoin the domain.
Message #
Event ID 312 — Machine password change failed.
Description
Machine password change failed.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | — NTSTATUS reference |
MigrationNeeded Boolean | — |
EnforcementMode UInt32 | — |
ExitReason UInt32 | — |
Event ID 65541 — An error occurred while retrieving a digital certificate from the inserted smart card.
Event ID 65542 — An error occurred in while attempting to verify the inserted smart card: Error.
Event ID 65543 — An error occurred while signing a message using the inserted smart card: Error.
Event ID 65544 — An error occurred while verifying a signed message using the inserted smart card: Error.
Event ID 65545 — An error occurred while verifying the digital certificate retrieved from the inserted smart card: Error.
Event ID 65546 — An error occurred while encrypting a message using the inserted smart card: Error.
Event ID 65547 — An error occurred while decrypting a message using the inserted smart card: Error.
Event ID 65548 — An error occurred while building a certificate context: Error.
Event ID 65550 — An error occurred while signing a message: Error.
Event ID 65551 — An error occurred while verifying a signed message: Error.
Event ID 65552 — An error occurred while encrypting a message: Error.
Event ID 65553 — An error occurred while decrypting a message: Error.
Event ID 65554 — An error occurred while retrieving some provider parameter: Error.
Event ID 65555 — An error occurred while generating a random number: Error.
Event ID 1073741828 — The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server Server.
Event ID 1073741829 — The Kerberos client received a KRB_AP_ERR_TKT_NYV error from the server Server.
Event ID 2147483651 — A Kerberos error message was received.
Description
A Kerberos error message was received.
Message #
Fields #
| Name | Description |
|---|---|
Client_Time | — |
Server_Time | [A Kerberos error message was received] Client Time. |
Error_Code | [A Kerberos error message was received] Server Time. |
Extended_Error | [A Kerberos error message was received] Error Code. |
Client_Realm | — |
Client_Name | [A Kerberos error message was received] Extended Error. |
Server_Realm | [A Kerberos error message was received] Client Realm. |
Server_Name | [A Kerberos error message was received] Client Name. |
Target_Name | [A Kerberos error message was received] Server Realm. |
Error_Text | [A Kerberos error message was received] Server Name. |
File UnicodeString | [A Kerberos error message was received] Target Name. |
Line UnicodeString | [A Kerberos error message was received] Error Text. |
LogonSession UnicodeString | — |
ClientTime UnicodeString | — |
ServerTime UnicodeString | — |
ErrorCode UnicodeString | — |
ErrorMessage UnicodeString | — |
ExtendedError UnicodeString | — |
ClientRealm UnicodeString | — |
ClientName UnicodeString | — |
ServerRealm UnicodeString | — |
ServerName UnicodeString | — |
TargetName UnicodeString | — |
ErrorText UnicodeString | — |
binary Binary | — |
Event ID 2147483654 — The Kerberos SSPI package generated an output token of size NeededSize bytes, which was too large to fit in the token buffer of size ActualSize bytes, provided by ...
Description
The Kerberos SSPI package generated an output token of size NeededSize bytes, which was too large to fit in the token buffer of size ActualSize bytes, provided by process id ClientProcessID.
Message #
Fields #
| Name | Description |
|---|---|
NeededSize UnicodeString | — |
ActualSize UnicodeString | — |
ClientProcessID UnicodeString | — |
ClientName UnicodeString | — |
binary Binary | — |
Event ID 2147483658 — The Kerberos subsystem currently cannot retrieve tickets from your domain controller using the UDP network protocol.
Description
The Kerberos subsystem currently cannot retrieve tickets from your domain controller using the UDP network protocol. This is typically due to network problems. Contact your system administrator.
Message #
Event ID 2147483660 — While using your smart card over a VPN connection, the Kerberos subsystem encountered an error.
Message #
Event ID 2147483661 — The smart card PIN stored in Credential Manager is missing or invalid.
Event ID 2147483662 — The password stored in Credential Manager is invalid.
Event ID 2147483663 — The Kerberos SSPI package generated an output token of size NeededSize bytes, which was too large to fit in the token buffer of size ActualSize bytes, provided by ...
Description
The Kerberos SSPI package generated an output token of size NeededSize bytes, which was too large to fit in the token buffer of size ActualSize bytes, provided by process id ClientProcessID.
Message #
Fields #
| Name | Description |
|---|---|
NeededSize UnicodeString | — |
ActualSize UnicodeString | — |
ClientProcessID UnicodeString | — |
RequiredSize UnicodeString | — |
binary Binary | — |
Event ID 2147483666 — The delegated TGT for the user has expired.
Message #
Fields #
| Name | Description |
|---|---|
Client | — |
Server | [TGT Details] Client. |
Flags | [TGT Details] Server. |
Start_Time | [TGT Details] Flags. |
End_Time | — |
Renew_Until | — |
Luid UnicodeString | — |
ClientPrincipalName UnicodeString | — |
ServicePrincipalName UnicodeString | — |
TicketFlags UnicodeString | — |
StartTime UnicodeString | — |
EndTime UnicodeString | — |
RenewUntil UnicodeString | — |
ErrorCode UnicodeString | — |
Event ID 2147483667 — The KDC certificate for the domain controller does not contain the KDC Extended Key Usage (EKU): 1.
Event ID 2147483668 — The KDC certificate for the domain controller does not have the DNS name of domain DomainName in the Subject Alternative Name (SAN) attribute: Error Code ErrorCode.
Event ID 2147483669 — During Kerberos Network Ticket Logon, the service ticket for Account .
Fields #
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 2147483670 — During Kerberos Network Ticket Logon, the service ticket for Account .
Fields #
| Name | Description |
|---|---|
Reason | — |
ErrorCode | — |
Event ID 2147483671 — During Kerberos Network Ticket Logon, the service ticket for Account .
Fields #
| Name | Description |
|---|---|
param1 | — |
param2 | — |