Microsoft-Windows-Kerberos-KdcProxy
Event ID 1: Service stopped with a failure: error code ErrorCode.
#Event ID 2: Failed to initialize Group Policy: error code ErrorCode.
#Event ID 3: Failed to read Group Policy: error code ErrorCode.
#Event ID 4: Failed to start the HTTP service: error code ErrorCode.
#Event ID 5: Service failed to register UrlPrefix UrlPrefix: error code ErrorCode.
#Event ID 6: Service failed to start because system is not domain-joined: error code ErrorCode.
#Event ID 100: HttpReceiveHttpRequest API failed to receive an HTTP request from the network: error code ErrorCode.
#Event ID 101: Service failed to create a new IO object to service an HTTP request from the network: error code ErrorCode.
#Event ID 102: Failed to unpack PduType: error code ErrorCode.
#Event ID 103: Failed to locate a domain controller in domain TargetDomain with locator flags Flags: error code ErrorCode.
#Event ID 200: Retry (RetryNumber) connection to KDC in TargetDomain.
#Event ID 300: Service started
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Kerberos-KdcProxy",
"guid": "D3F8787E-656F-4876-9EBD-6F5E3CB0A45B",
"event_source_name": "",
"event_id": 300,
"version": 0,
"level": 4,
"task": 1,
"opcode": 1,
"keywords": 9223372036854775808,
"time_created": "2026-07-19T19:13:08.750834+00:00",
"event_record_id": 1,
"correlation": {},
"execution": {
"process_id": 11780,
"thread_id": 12428
},
"channel": "Microsoft-Windows-Kerberos-KdcProxy/Operational",
"computer": "JD-DC01-2022.ludus.domain",
"security": {
"user_id": "S-1-5-20"
}
},
"event_data": {},
"message": ""
}
Event ID 301: Service stopped
#Event ID 302: Initialized Group Policy successfully
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Kerberos-KdcProxy",
"guid": "D3F8787E-656F-4876-9EBD-6F5E3CB0A45B",
"event_source_name": "",
"event_id": 302,
"version": 0,
"level": 4,
"task": 1,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-07-19T19:13:08.753042+00:00",
"event_record_id": 3,
"correlation": {},
"execution": {
"process_id": 11780,
"thread_id": 12428
},
"channel": "Microsoft-Windows-Kerberos-KdcProxy/Operational",
"computer": "JD-DC01-2022.ludus.domain",
"security": {
"user_id": "S-1-5-20"
}
},
"event_data": {},
"message": ""
}
Event ID 303: Read Group Policy successfully
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Kerberos-KdcProxy",
"guid": "D3F8787E-656F-4876-9EBD-6F5E3CB0A45B",
"event_source_name": "",
"event_id": 303,
"version": 0,
"level": 4,
"task": 1,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-07-19T19:13:08.753018+00:00",
"event_record_id": 2,
"correlation": {},
"execution": {
"process_id": 11780,
"thread_id": 12428
},
"channel": "Microsoft-Windows-Kerberos-KdcProxy/Operational",
"computer": "JD-DC01-2022.ludus.domain",
"security": {
"user_id": "S-1-5-20"
}
},
"event_data": {},
"message": ""
}
Event ID 304: HTTP service started successfully
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Kerberos-KdcProxy",
"guid": "D3F8787E-656F-4876-9EBD-6F5E3CB0A45B",
"event_source_name": "",
"event_id": 304,
"version": 0,
"level": 4,
"task": 1,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-07-19T19:13:08.759373+00:00",
"event_record_id": 4,
"correlation": {},
"execution": {
"process_id": 11780,
"thread_id": 12428
},
"channel": "Microsoft-Windows-Kerberos-KdcProxy/Operational",
"computer": "JD-DC01-2022.ludus.domain",
"security": {
"user_id": "S-1-5-20"
}
},
"event_data": {},
"message": ""
}
Event ID 305: HTTP service stopped
#Event ID 306: Rediscover KDC for domain TargetDomain.
#Event ID 307: Hash table was expanded from (BeginNonEmptyBuckets/BeginTotalBuckets buckets, BeginTotalEntries entries) to (NonEmptyBuckets/TotalBuckets buckets, TotalEntries entries) in TimeSpent milliseconds.
#Event ID 308: Hash table was contracted from (BeginNonEmptyBuckets/BeginTotalBuckets buckets, BeginTotalEntries entries) to (NonEmptyBuckets/TotalBuckets buckets, TotalEntries entries) in TimeSpent milliseconds.
#Event ID 309: Rediscovered KDC KDCAddress(KDCName) for domain TargetDomain.
#Event ID 400: An HTTP request was received
#Event ID 401: Client certificate is required to establish an HTTP connection
#Event ID 402: Client certificate is not valid to establish an HTTP connection: trust status TrustStatus.
#Event ID 403: The account (Domain: DomainName, User: UserName) has NumerOfFailures password failures.
#Provenance
ETW provider GUID d3f8787e-656f-4876-9ebd-6f5e3cb0a45b
Defined in kpssvc.dll, which carries the event manifest.
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.3807, captured 2026-06-02 — Manifest XML pack, 1.9 MB