Microsoft-Windows-Kerberos-KdcProxy

EventTitleChannelSampleRule
1Service stopped with a failure: error code ErrorCode.OperationalNN
2Failed to initialize Group Policy: error code ErrorCode.OperationalNN
3Failed to read Group Policy: error code ErrorCode.OperationalNN
4Failed to start the HTTP service: error code ErrorCode.OperationalNN
5Service failed to register UrlPrefix UrlPrefix: error code ErrorCode.OperationalNN
6Service failed to start because system is not domain-joined: error code …OperationalNN
100HttpReceiveHttpRequest API failed to receive an HTTP request from the network: …OperationalNN
101Service failed to create a new IO object to service an HTTP request from the …OperationalNN
102Failed to unpack PduType: error code ErrorCode.OperationalNN
103Failed to locate a domain controller in domain TargetDomain with locator flags …OperationalNN
200Retry (RetryNumber) connection to KDC in TargetDomain.OperationalNN
300Service startedOperationalYN
301Service stoppedOperationalNN
302Initialized Group Policy successfullyOperationalYN
303Read Group Policy successfullyOperationalYN
304HTTP service started successfullyOperationalYN
305HTTP service stoppedOperationalNN
306Rediscover KDC for domain TargetDomain.OperationalNN
307Hash table was expanded from (BeginNonEmptyBuckets/BeginTotalBuckets buckets, …OperationalNN
308Hash table was contracted from (BeginNonEmptyBuckets/BeginTotalBuckets buckets, …OperationalNN
309Rediscovered KDC KDCAddress(KDCName) for domain TargetDomain.OperationalNN
400An HTTP request was receivedOperationalNN
401Client certificate is required to establish an HTTP connectionOperationalNN
402Client certificate is not valid to establish an HTTP connection: trust status …OperationalNN
403The account (Domain: DomainName, User: UserName) has NumerOfFailures password …OperationalNN
404The account (Domain: DomainName, User: UserName) is rejected due to the usage of …OperationalNN

Event ID 1: Service stopped with a failure: error code ErrorCode.

#
Channel
Operational
Task
TASK_SERVICE

Message #

Service stopped with a failure: error code %1

Fields #

NameDescription
ErrorCode UInt32

Event ID 2: Failed to initialize Group Policy: error code ErrorCode.

#
Channel
Operational
Task
TASK_SERVICE

Message #

Failed to initialize Group Policy: error code %1

Fields #

NameDescription
ErrorCode UInt32

Event ID 3: Failed to read Group Policy: error code ErrorCode.

#
Channel
Operational
Task
TASK_SERVICE

Message #

Failed to read Group Policy: error code %1

Fields #

NameDescription
ErrorCode UInt32

Event ID 4: Failed to start the HTTP service: error code ErrorCode.

#
Channel
Operational
Task
TASK_SERVICE

Message #

Failed to start the HTTP service: error code %1

Fields #

NameDescription
ErrorCode UInt32

Event ID 5: Service failed to register UrlPrefix UrlPrefix: error code ErrorCode.

#
Channel
Operational
Task
TASK_SERVICE

Description

Service failed to register UrlPrefix UrlPrefix: error code ErrorCode. Contact your administrator to make sure UrlPrefix is properly reserved.

Message #

Service failed to register UrlPrefix %1: error code %2. Contact your administrator to make sure %1 is properly reserved.

Fields #

NameDescription
UrlPrefix UnicodeString
ErrorCode UInt32

Event ID 6: Service failed to start because system is not domain-joined: error code ErrorCode.

#
Channel
Operational
Task
TASK_SERVICE

Message #

Service failed to start because system is not domain-joined: error code %1.

Fields #

NameDescription
ErrorCode UInt32

Event ID 100: HttpReceiveHttpRequest API failed to receive an HTTP request from the network: error code ErrorCode.

#
Channel
Operational
Task
TASK_HTTP

Description

HttpReceiveHttpRequest API failed to receive an HTTP request from the network: error code ErrorCode. This may indicate a failure where no future HTTP requests can be received by the service.

Message #

HttpReceiveHttpRequest API failed to receive an HTTP request from the network: error code %1. This may indicate a failure where no future HTTP requests can be received by the service.

Fields #

NameDescription
ErrorCode UInt32

Event ID 101: Service failed to create a new IO object to service an HTTP request from the network: error code ErrorCode.

#
Channel
Operational
Task
TASK_HTTP

Description

Service failed to create a new IO object to service an HTTP request from the network: error code ErrorCode. This may indicate a failure where no future HTTP requests can be received by the service.

Message #

Service failed to create a new IO object to service an HTTP request from the network: error code %1. This may indicate a failure where no future HTTP requests can be received by the service.

Fields #

NameDescription
ErrorCode UInt32

Event ID 102: Failed to unpack PduType: error code ErrorCode.

#
Channel
Operational
Task
TASK_HTTP

Message #

Failed to unpack %1: error code %2

Fields #

NameDescription
PduType UnicodeString
ErrorCode UInt32

Event ID 103: Failed to locate a domain controller in domain TargetDomain with locator flags Flags: error code ErrorCode.

#
Channel
Operational
Task
TASK_HTTP

Message #

Failed to locate a domain controller in domain %1 with locator flags %2: error code %3.

Fields #

NameDescription
TargetDomain UnicodeString
Flags UInt32
ErrorCode UInt32

Event ID 200: Retry (RetryNumber) connection to KDC in TargetDomain.

#
Channel
Operational
Task
TASK_SERVICE

Message #

Retry (%1) connection to KDC in %2

Fields #

NameDescription
RetryNumber UInt32
TargetDomain UnicodeString

Event ID 300: Service started

#
Channel
Operational
Level
Informational
Task
TASK_SERVICE
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kerberos-KdcProxy",
    "guid": "D3F8787E-656F-4876-9EBD-6F5E3CB0A45B",
    "event_source_name": "",
    "event_id": 300,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 1,
    "keywords": 9223372036854775808,
    "time_created": "2026-07-19T19:13:08.750834+00:00",
    "event_record_id": 1,
    "correlation": {},
    "execution": {
      "process_id": 11780,
      "thread_id": 12428
    },
    "channel": "Microsoft-Windows-Kerberos-KdcProxy/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 301: Service stopped

#
Channel
Operational
Task
TASK_SERVICE
Opcode
Stop

Event ID 302: Initialized Group Policy successfully

#
Channel
Operational
Level
Informational
Task
TASK_SERVICE

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kerberos-KdcProxy",
    "guid": "D3F8787E-656F-4876-9EBD-6F5E3CB0A45B",
    "event_source_name": "",
    "event_id": 302,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-07-19T19:13:08.753042+00:00",
    "event_record_id": 3,
    "correlation": {},
    "execution": {
      "process_id": 11780,
      "thread_id": 12428
    },
    "channel": "Microsoft-Windows-Kerberos-KdcProxy/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 303: Read Group Policy successfully

#
Channel
Operational
Level
Informational
Task
TASK_SERVICE

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kerberos-KdcProxy",
    "guid": "D3F8787E-656F-4876-9EBD-6F5E3CB0A45B",
    "event_source_name": "",
    "event_id": 303,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-07-19T19:13:08.753018+00:00",
    "event_record_id": 2,
    "correlation": {},
    "execution": {
      "process_id": 11780,
      "thread_id": 12428
    },
    "channel": "Microsoft-Windows-Kerberos-KdcProxy/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 304: HTTP service started successfully

#
Channel
Operational
Level
Informational
Task
TASK_SERVICE

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kerberos-KdcProxy",
    "guid": "D3F8787E-656F-4876-9EBD-6F5E3CB0A45B",
    "event_source_name": "",
    "event_id": 304,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-07-19T19:13:08.759373+00:00",
    "event_record_id": 4,
    "correlation": {},
    "execution": {
      "process_id": 11780,
      "thread_id": 12428
    },
    "channel": "Microsoft-Windows-Kerberos-KdcProxy/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 305: HTTP service stopped

#
Channel
Operational
Task
TASK_SERVICE

Event ID 306: Rediscover KDC for domain TargetDomain.

#
Channel
Operational
Task
TASK_SERVICE

Message #

Rediscover KDC for domain %1

Fields #

NameDescription
TargetDomain UnicodeString

Event ID 307: Hash table was expanded from (BeginNonEmptyBuckets/BeginTotalBuckets buckets, BeginTotalEntries entries) to (NonEmptyBuckets/TotalBuckets buckets, TotalEntries entries) in TimeSpent milliseconds.

#
Channel
Operational
Task
TASK_SERVICE

Message #

Hash table was expanded from (%1/%2 buckets, %3 entries) to (%4/%5 buckets, %6 entries) in %7 milliseconds

Fields #

NameDescription
BeginNonEmptyBuckets UInt32
BeginTotalBuckets UInt32
BeginTotalEntries UInt32
NonEmptyBuckets UInt32
TotalBuckets UInt32
TotalEntries UInt32
TimeSpent UInt32

Event ID 308: Hash table was contracted from (BeginNonEmptyBuckets/BeginTotalBuckets buckets, BeginTotalEntries entries) to (NonEmptyBuckets/TotalBuckets buckets, TotalEntries entries) in TimeSpent milliseconds.

#
Channel
Operational
Task
TASK_SERVICE

Message #

Hash table was contracted from (%1/%2 buckets, %3 entries) to (%4/%5 buckets, %6 entries) in %7 milliseconds

Fields #

NameDescription
BeginNonEmptyBuckets UInt32
BeginTotalBuckets UInt32
BeginTotalEntries UInt32
NonEmptyBuckets UInt32
TotalBuckets UInt32
TotalEntries UInt32
TimeSpent UInt32

Event ID 309: Rediscovered KDC KDCAddress(KDCName) for domain TargetDomain.

#
Channel
Operational
Task
TASK_SERVICE

Message #

Rediscovered KDC %3(%2) for domain %1

Fields #

NameDescription
TargetDomain UnicodeString
KDCName UnicodeString
KDCAddress UnicodeString

Event ID 400: An HTTP request was received

#
Channel
Operational
Task
TASK_HTTP

Event ID 401: Client certificate is required to establish an HTTP connection

#
Channel
Operational
Task
TASK_HTTP

Event ID 402: Client certificate is not valid to establish an HTTP connection: trust status TrustStatus.

#
Channel
Operational
Task
TASK_HTTP

Message #

Client certificate is not valid to establish an HTTP connection: trust status %1

Fields #

NameDescription
TrustStatus UInt32

Event ID 403: The account (Domain: DomainName, User: UserName) has NumerOfFailures password failures.

#
Channel
Operational
Task
TASK_HTTP

Description

The account (Domain: DomainName, User: UserName) has NumerOfFailures password failures. It is locked out for the next LockedOutPeriod seconds.

Message #

The account (Domain: %1, User: %2) has %3 password failures. It is locked out for the next %4 seconds

Fields #

NameDescription
DomainName UnicodeString
UserName UnicodeString
NumerOfFailures UInt32
LockedOutPeriod UInt32

Event ID 404: The account (Domain: DomainName, User: UserName) is rejected due to the usage of an unarmored Kerberos message.

#
Channel
Operational
Task
TASK_HTTP

Message #

The account (Domain: %1, User: %2) is rejected due to the usage of an unarmored Kerberos message

Fields #

NameDescription
DomainName UnicodeString
UserName UnicodeString

Provenance

ETW provider GUID d3f8787e-656f-4876-9ebd-6f5e3cb0a45b

Defined in kpssvc.dll, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.3807, captured 2026-06-02 — Manifest XML pack, 1.9 MB