Forum Discussion
Kerberos Event ID 4771 (0x18) across multiple users while interactive logons succeed
Users are able to perform interactive/manual logons successfully with their current credentials.
The failures are also generated outside normal working hours.
The Client Address in the 4771 events corresponds to the workstation/IP of the respective user.
We have observed many different Client Addresses (at least 15 different source IPs), so the failures are not originating from a single host.
As an initial troubleshooting step, we executed:
klist purge
for one affected user. The Kerberos ticket cache was cleared successfully, but the Event ID 4771 failures continued afterward with no noticeable change.
Previous guidance suggested checking for stale/stored credentials, scheduled tasks, Windows services, Credential Manager entries, mapped resources, proxy authentication, or background applications that might be attempting authentication with outdated credentials.
Another recommendation was to use Sysmon on an affected workstation and correlate outbound Kerberos traffic on port 88 with the timestamp of the 4771 event in order to identify the process or executable generating the request.
Before making changes or deploying additional monitoring software in the client's environment, we would like to determine the safest and most appropriate troubleshooting approach.
Given that:
interactive logons work normally;
0x18 failures occur for many users;
each user's Client Address generally corresponds to their own workstation;
the issue occurs across many different workstations;
and clearing the Kerberos ticket cache did not change the behavior,
what would be the recommended Microsoft troubleshooting method to identify the exact process, service, application, or stored credential generating these failed Kerberos pre-authentication requests?
Thank you.