Microsoft-Windows-Kerberos-Key-Distribution-Center
138 events across 6 channels
Event ID 3: Could not find principal
#Fields #
| Name | Description |
|---|---|
Principal UnicodeString | |
__binLength UInt32 | |
binary Binary |
Event ID 4: Domain Domain propagated to us but did not authenticate
#Fields #
| Name | Description |
|---|---|
Domain UnicodeString | |
__binLength UInt32 | |
binary Binary |
Event ID 5: The KDC failed to update policy class
#Fields #
| Name | Description |
|---|---|
Class UnicodeString | |
__binLength UInt32 | |
binary Binary |
Event ID 6: The KDC failed to update the trusted domain list
#Event ID 7: The Security Account Manager failed a KDC request in an unexpected way
#Fields #
| Name | Description |
|---|---|
AccountName UnicodeString | |
LookupType UnicodeString | |
__binLength UInt32 | |
binary Binary |
Event ID 8: The account AccountName did not have a suitable key for generating a Kerberos ticket
#Fields #
| Name | Description |
|---|---|
AccountName UnicodeString | |
__binLength UInt32 | |
binary Binary |
Event ID 9: The password on the KRBTGT account was changed.
#Description
The password on the KRBTGT account was changed.
Message #
Event ID 10: The attempt to change the password on the KRBTGT account failed
#Event ID 11: The KDC encountered duplicate names while processing a Kerberos authentication request
#Fields #
| Name | Description |
|---|---|
Name UnicodeString | |
Type UnicodeString | |
__binLength UInt32 | |
binary Binary |
Event ID 12: A request failed from client realm ClientRealm for a ticket in realm
#Fields #
| Name | Description |
|---|---|
ClientRealm UnicodeString | |
Realm UnicodeString | |
__binLength UInt32 | |
binary Binary |
Event ID 13: The account for Name has corrupt keys stored in the DS
#Fields #
| Name | Description |
|---|---|
Name UnicodeString | |
__binLength UInt32 | |
binary Binary |
Event ID 14: While processing an AS request for target service Target, the account Account did not have a suitable key for generating a Kerberos ticket (the missing key has an ID of ID)
#Fields #
| Name | Description |
|---|---|
Target UnicodeString | |
Account UnicodeString | |
ID UnicodeString | |
RequestedEtypes UnicodeString | |
AvailableEtypes UnicodeString | |
AccountToReset UnicodeString | |
__binLength UInt32 | |
binary Binary |
Event ID 15: The request for an AS ticket for client Client was forwarded to the PDC
#Fields #
| Name | Description |
|---|---|
Client UnicodeString | |
__binLength UInt32 | |
binary Binary |
Event ID 16: While processing a TGS request for the target server Target, the account Account did not have a suitable key for generating a Kerberos ticket (the missing key has an ID of ID)
#Fields #
| Name | Description |
|---|---|
Target UnicodeString | |
Account UnicodeString | |
ID UnicodeString | |
RequestedEtypes UnicodeString | |
AvailableEtypes UnicodeString | |
AccountToReset UnicodeString | |
__binLength UInt32 | |
binary Binary |
Event ID 17: When updating policy class Class, the KDC encountered invalid policy data and has failed to update the policy
#Fields #
| Name | Description |
|---|---|
Class UnicodeString | |
__binLength UInt32 | |
binary Binary |
Event ID 18: During TGS processing, the KDC was unable to verify the signature on the PAC from
#Fields #
| Name | Description |
|---|---|
Name UnicodeString | |
__binLength UInt32 | |
binary Binary |
Event ID 19: This event indicates an attempt was made to use smartcard logon, but the KDC is unable to use the PKINIT protocol because it is missing a suitable certificate
#Event ID 20: The currently selected KDC certificate was once valid, but now is invalid and no suitable replacement was found
#Event ID 21: The client certificate for the user Domain\Username is not valid, and resulted in a failed smartcard logon
#Fields #
| Name | Description |
|---|---|
Domain UnicodeString | |
Username UnicodeString | |
Status UnicodeString | NTSTATUS reference |
__binLength UInt32 | |
binary Binary |
Event ID 22: The KDC encountered a trust loop when building a list of trusted domains
#Fields #
| Name | Description |
|---|---|
Domain UnicodeString | |
__binLength UInt32 | |
binary Binary |
Event ID 23: The KDC received invalid messages of type
#Fields #
| Name | Description |
|---|---|
Type UnicodeString | |
__binLength UInt32 | |
binary Binary |
Event ID 24: A service ticket request by client Client for Server was rejected because User2User was required
#Fields #
| Name | Description |
|---|---|
Client UnicodeString | |
Server UnicodeString | |
__binLength UInt32 | |
binary Binary |
Event ID 25: The account Name from domain Domain is attempting to use S4USelf for the target client Target, but is not allowed to perform group expansion on this client's user object
#Fields #
| Name | Description |
|---|---|
Name UnicodeString | |
Domain UnicodeString | |
Target UnicodeString | |
__binLength UInt32 | |
binary Binary |
Event ID 26: While processing an AS request for target service Target, the account Name did not have a suitable key for generating a Kerberos ticket (the missing key has an ID of ID)
#Fields #
| Name | Description |
|---|---|
Target UnicodeString | |
Name UnicodeString | |
ID UnicodeString | |
RequestedEtypes UnicodeString | |
AvailableETypes UnicodeString | |
__binLength UInt32 | |
binary Binary |
Event ID 27: While processing a TGS request for the target server Target, the account Name did not have a suitable key for generating a Kerberos ticket (the missing key has an ID of ID)
#Fields #
| Name | Description |
|---|---|
Target UnicodeString | |
Name UnicodeString | |
ID UnicodeString | |
RequestedEtypes UnicodeString | |
AvailableETypes UnicodeString | |
__binLength UInt32 | |
binary Binary |
Event ID 28: When generating a cross realm referral from domain Domain the KDC was not able to find the suitable key to verify the ticket
#Fields #
| Name | Description |
|---|---|
Domain UnicodeString | |
RequestedKeyVersion UnicodeString | |
AvailableKeyVersion UnicodeString | |
__binLength UInt32 | |
binary Binary |
Event ID 29: The Key Distribution Center (KDC) cannot find a suitable certificate to use for smart card logons, or the KDC certificate could not be verified
#Event ID 30: The Kerberos Key Distribution Center failed to locate the forest or domain Forest to search
#Fields #
| Name | Description |
|---|---|
Forest UnicodeString | |
__binLength UInt32 | |
binary Binary |
Event ID 31: A ticket to the service Server is issued for account
#Fields #
| Name | Description |
|---|---|
Account UnicodeString | |
Server UnicodeString | |
EncryptedTicketSize UnicodeString | |
TicketSizeThreshold UnicodeString | |
__binLength UInt32 | |
binary Binary |
Event ID 32: The Key Distribution Center (KDC) uses a certificate without KDC Extended Key Usage (EKU) which can result in authentication failures for device certificate logon and smart card logon from non-doma...
#Event ID 33: The Key Distribution Center (KDC) encountered failures when updating the krbtgt account for the Dynamic Access Control and Kerberos armoring policy capability for the domain
#Event ID 34: The Key Distribution Center (KDC) has the Dynamic Access Control and Kerberos armoring policy configured for a level which requires a higher domain functional level
#Event ID 35: The Key Distribution Center (KDC) encountered a ticket-granting-ticket (TGT) from another KDC (IssuingKDC) that did not contain a PAC attributes field
#Fields #
| Name | Description |
|---|---|
IssuingKDC UnicodeString | |
__binLength UInt32 | |
binary Binary |
Detection Patterns #
Credential Access: Kerberoasting
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
Provider_Name | eq | Microsoft-Windows-Kerberos-Key-Distribution-Center | 1 rule | sigma |
Event ID 36: The Key Distribution Center (KDC) encountered a ticket that did not contain a PAC while processing a request for another ticket
#Fields #
| Name | Description |
|---|---|
ClientRealm UnicodeString | |
ClientName UnicodeString | |
ServerName UnicodeString | |
__binLength UInt32 | |
binary Binary |
Detection Patterns #
Credential Access: Kerberoasting
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
Provider_Name | eq | Microsoft-Windows-Kerberos-Key-Distribution-Center | 1 rule | sigma |
Event ID 37: The Key Distribution Center (KDC) encountered a ticket that did not contain information about the account that requested the ticket while processing a request for another ticket
#Fields #
| Name | Description |
|---|---|
IssuingKDC UnicodeString | |
ClientRealm UnicodeString | |
ClientName UnicodeString | |
ServerName UnicodeString | |
__binLength UInt32 | |
binary Binary |
Detection Patterns #
Credential Access: Kerberoasting
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
Provider_Name | eq | Microsoft-Windows-Kerberos-Key-Distribution-Center | 1 rule | sigma |
Event ID 37: The Key Distribution Center (KDC) encountered a ticket that did not contain information about the account that requested the ticket while processing a request for another ticket
#Fields #
| Name | Description |
|---|---|
IssuingKDC | |
ClientRealm | |
ClientName | |
ServerName | |
__binLength | |
binary |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Kerberos-Key-Distribution-Center",
"guid": "{3FD9DA1A-5A54-46C5-9A26-9BD7C0685056}",
"event_source_name": "KDC",
"event_id": 37,
"version": 0,
"level": 3,
"task": 0,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2026-03-13T17:05:19.030305+00:00",
"event_record_id": 10648,
"correlation": {},
"execution": {
"process_id": 0,
"thread_id": 0
},
"channel": "System",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": ""
}
},
"event_data": {
"IssuingKDC": "LAB-DC01",
"ClientRealm": "LUDUS.DOMAIN",
"ClientName": "domainadmin",
"ServerName": "krbtgt",
"Binary": ""
},
"message": ""
}
Detection Patterns #
Credential Access: Kerberoasting
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
Provider_Name | eq | Microsoft-Windows-Kerberos-Key-Distribution-Center | 1 rule | sigma |
Event ID 38: The Key Distribution Center (KDC) encountered a ticket that contained inconsistent information about the account that requested the ticket
#Fields #
| Name | Description |
|---|---|
IssuingKDC UnicodeString | |
ClientRealm UnicodeString | |
ClientName UnicodeString | |
ServerName UnicodeString | |
ActiveDirectorySID UnicodeString | |
TicketSID UnicodeString | |
__binLength UInt32 | |
binary Binary |
Detection Patterns #
Credential Access: Kerberoasting
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
Provider_Name | eq | Microsoft-Windows-Kerberos-Key-Distribution-Center | 1 rule | sigma |
Event ID 39: The Key Distribution Center (KDC) encountered a user certificate that was valid but could not be mapped to a user in a secure way (such as via explicit mapping, key trust mapping, or a SID)
#Fields #
| Name | Description |
|---|---|
AccountName UnicodeString | |
Subject UnicodeString | |
Issuer UnicodeString | |
SerialNumber UnicodeString | |
Thumbprint UnicodeString | |
IssuancePolicies UnicodeString | |
__binLength UInt32 | |
binary Binary |
Event ID 40: The Key Distribution Center (KDC) encountered a user certificate that was valid but could not be mapped to a user in a secure way (such as via explicit mapping, key trust mapping, or a SID)
#Fields #
| Name | Description |
|---|---|
AccountName UnicodeString | |
Subject UnicodeString | |
Issuer UnicodeString | |
SerialNumber UnicodeString | |
Thumbprint UnicodeString | |
IssuancePolicies UnicodeString | |
IssuanceTime UnicodeString | |
AccountCreationTime UnicodeString | |
__binLength UInt32 | |
binary Binary |
Event ID 41: The Key Distribution Center (KDC) encountered a user certificate that was valid but contained a different SID than the user to which it mapped
#Fields #
| Name | Description |
|---|---|
AccountName UnicodeString | |
AccountSid UnicodeString | |
Subject UnicodeString | |
Issuer UnicodeString | |
SerialNumber UnicodeString | |
Thumbprint UnicodeString | |
IssuancePolicies UnicodeString | |
CertificateSid UnicodeString | |
__binLength UInt32 | |
binary Binary |
Event ID 42: The Kerberos Key Distribution Center lacks strong keys for account
#Fields #
| Name | Description |
|---|---|
AccountName UnicodeString | |
__binLength UInt32 | |
binary Binary |
Event ID 43: The Key Distribution Center (KDC) encountered a ticket that it could not validate the full PAC Signature
#Fields #
| Name | Description |
|---|---|
ClientRealm UnicodeString | |
ClientName UnicodeString | |
__binLength UInt32 | |
binary Binary |
Event ID 44: The Key Distribution Center (KDC) encountered a ticket that did not contain the full PAC Signature
#Fields #
| Name | Description |
|---|---|
ClientRealm UnicodeString | |
ClientName UnicodeString | |
__binLength UInt32 | |
binary Binary |
Event ID 45: The Key Distribution Center (KDC) encountered a client certificate that was valid but did not chain to a root in the NTAuth store
#Fields #
| Name | Description |
|---|---|
AccountName UnicodeString | |
Subject UnicodeString | |
Issuer UnicodeString | |
SerialNumber UnicodeString | |
Thumbprint UnicodeString | |
__binLength UInt32 | |
binary Binary |
Event ID 100: AS exchange performance: AS-REQ processing begins
#Description
AS exchange performance: AS-REQ processing begins.
Event ID 100: AS exchange performance: AS-REQ processing begins
#Description
AS exchange performance: AS-REQ processing begins.
Message #
Event ID 101: AS exchange performance: AS-REP or KRB-ERROR returned:
#Description
AS exchange performance: AS-REP or KRB-ERROR returned.
Fields #
| Name | Description |
|---|---|
ClientDomain UnicodeString | |
ClientName UnicodeString | |
ServerDomain UnicodeString | |
ServerName UnicodeString | |
ErrorCode UInt32 | Known values
|
TimeSpent UInt32 |
References #
- RFC 4120 §7.5.9 Kerberos error codes https://datatracker.ietf.org/doc/html/rfc4120#section-7.5.9
- RFC 4556 §6 PKINIT error codes https://datatracker.ietf.org/doc/html/rfc4556#section-6
Event ID 101: AS exchange performance: AS-REP or KRB-ERROR returned.
#Description
AS exchange performance: AS-REP or KRB-ERROR returned.
Message #
Fields #
| Name | Description |
|---|---|
ClientDomain UnicodeString | |
ClientName UnicodeString | |
ServerDomain UnicodeString | |
ServerName UnicodeString | |
ErrorCode UInt32 | Known values
|
TimeSpent UInt32 |
Event ID 102: TGS exchange performance: TGS-REQ processing begins
#Description
TGS exchange performance: TGS-REQ processing begins.
Event ID 102: TGS exchange performance: TGS-REQ processing begins
#Description
TGS exchange performance: TGS-REQ processing begins.
Message #
Event ID 103: TGS exchange performance: TGS-REQ or KRB-ERROR returned:
#Description
TGS exchange performance: TGS-REQ or KRB-ERROR returned.
Fields #
| Name | Description |
|---|---|
ClientDomain UnicodeString | |
ClientName UnicodeString | |
ServerDomain UnicodeString | |
ServerName UnicodeString | |
ErrorCode UInt32 | Known values
|
TimeSpent UInt32 |
References #
- RFC 4120 §7.5.9 Kerberos error codes https://datatracker.ietf.org/doc/html/rfc4120#section-7.5.9
- RFC 4556 §6 PKINIT error codes https://datatracker.ietf.org/doc/html/rfc4556#section-6
Event ID 103: TGS exchange performance: TGS-REQ or KRB-ERROR returned.
#Description
TGS exchange performance: TGS-REQ or KRB-ERROR returned.
Message #
Fields #
| Name | Description |
|---|---|
ClientDomain UnicodeString | |
ClientName UnicodeString | |
ServerDomain UnicodeString | |
ServerName UnicodeString | |
ErrorCode UInt32 | Known values
|
TimeSpent UInt32 |
Event ID 104: Kerberos preauthentication by using DES or RC4 failed because the account was a member of the Protected User group.
#Description
Kerberos preauthentication by using DES or RC4 failed because the account was a member of the Protected User group.
Message #
Fields #
| Name | Description |
|---|---|
TargetUserName UnicodeString | Account name of the target. |
TargetSid SID | |
ServiceName UnicodeString | |
TicketOptions HexInt32 | Bitmask flags
|
Status HexInt32 | NTSTATUS reference |
PreAuthType UnicodeString | Known values
|
IpAddress UnicodeString | |
IpPort UnicodeString | |
CertIssuerName UnicodeString | |
CertSerialNumber UnicodeString | |
CertThumbprint UnicodeString |
Event ID 104: Kerberos preauthentication by using DES or RC4 failed because the account was a member of the Protected User group
#Description
Kerberos preauthentication by using DES or RC4 failed because the account was a member of the Protected User group.
Fields #
| Name | Description |
|---|---|
TargetUserName UnicodeString | Account name of the target. |
TargetSid SID | |
ServiceName UnicodeString | |
TicketOptions HexInt32 | Bitmask flags
|
Status HexInt32 | NTSTATUS reference |
PreAuthType UnicodeString | Known values
|
IpAddress UnicodeString | |
IpPort UnicodeString | |
CertIssuerName UnicodeString | |
CertSerialNumber UnicodeString | |
CertThumbprint UnicodeString |
Event ID 105: A Kerberos Ticket-granting-ticket (TGT) was denied because the device does not meet the access control restrictions.
#Description
A Kerberos Ticket-granting-ticket (TGT) was denied because the device does not meet the access control restrictions.
Message #
Fields #
| Name | Description |
|---|---|
TargetUserName UnicodeString | Account name of the target. |
TargetDomainName UnicodeString | Domain or machine name of the target account. |
TargetSid SID | |
DeviceName UnicodeString | |
ServiceName UnicodeString | |
ServiceSid SID | |
TicketOptions HexInt32 | Bitmask flags
|
Status HexInt32 | NTSTATUS reference |
TicketEncryptionType HexInt32 | Known values
|
PreAuthType UnicodeString | Known values
|
IpAddress UnicodeString | |
IpPort UnicodeString | |
CertIssuerName UnicodeString | |
CertSerialNumber UnicodeString | |
CertThumbprint UnicodeString | |
SiloName UnicodeString | |
PolicyName UnicodeString | |
TGTLifetime UInt32 |
Event ID 105: A Kerberos Ticket-granting-ticket (TGT) was denied because the device does not meet the access control restrictions
#Description
A Kerberos Ticket-granting-ticket (TGT) was denied because the device does not meet the access control restrictions.
Fields #
| Name | Description |
|---|---|
TargetUserName UnicodeString | Account name of the target. |
TargetDomainName UnicodeString | Domain or machine name of the target account. |
TargetSid SID | |
DeviceName UnicodeString | |
ServiceName UnicodeString | |
ServiceSid SID | |
TicketOptions HexInt32 | Bitmask flags
|
Status HexInt32 | NTSTATUS reference |
TicketEncryptionType HexInt32 | Known values
|
PreAuthType UnicodeString | Known values
|
IpAddress UnicodeString | |
IpPort UnicodeString | |
CertIssuerName UnicodeString | |
CertSerialNumber UnicodeString | |
CertThumbprint UnicodeString | |
SiloName UnicodeString | |
PolicyName UnicodeString | |
TGTLifetime UInt32 |
Event ID 106: A Kerberos service ticket was denied because the user, device, or both does not meet the access control restrictions.
#Description
A Kerberos service ticket was denied because the user, device, or both does not meet the access control restrictions.
Message #
Fields #
| Name | Description |
|---|---|
TargetUserName UnicodeString | Account name of the target. |
TargetDomainName UnicodeString | Domain or machine name of the target account. |
DeviceName UnicodeString | |
ServiceName UnicodeString | |
ServiceSid SID | |
TicketOptions HexInt32 | Bitmask flags
|
TicketEncryptionType HexInt32 | Known values
|
IpAddress UnicodeString | |
IpPort UnicodeString | |
Status HexInt32 | NTSTATUS reference |
LogonGuid GUID | |
TransitedServices UnicodeString | |
SiloName UnicodeString | |
PolicyName UnicodeString |
Event ID 106: A Kerberos service ticket was denied because the user, device, or both does not meet the access control restrictions
#Description
A Kerberos service ticket was denied because the user, device, or both does not meet the access control restrictions.
Fields #
| Name | Description |
|---|---|
TargetUserName UnicodeString | Account name of the target. |
TargetDomainName UnicodeString | Domain or machine name of the target account. |
DeviceName UnicodeString | |
ServiceName UnicodeString | |
ServiceSid SID | |
TicketOptions HexInt32 | Bitmask flags
|
TicketEncryptionType HexInt32 | Known values
|
IpAddress UnicodeString | |
IpPort UnicodeString | |
Status HexInt32 | NTSTATUS reference |
LogonGuid GUID | |
TransitedServices UnicodeString | |
SiloName UnicodeString | |
PolicyName UnicodeString |
Event ID 120: The Key Distribution Center (KDC) failed to validate its current KDC certificate.
#Description
The Key Distribution Center (KDC) failed to validate its current KDC certificate. This KDC might not be enabled for smart card or certificate authentication.
Message #
Fields #
| Name | Description |
|---|---|
Issuer UnicodeString | |
SerialNumber UnicodeString | |
Thumbprint UnicodeString | |
Template UnicodeString | |
KerbErr UInt32 | |
ErrorCode UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Kerberos-Key-Distribution-Center",
"event_id": 120,
"level": "Error",
"task": "KDC",
"opcode": "Info",
"time_created": "2026-05-24T20:29:18.8212381+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Microsoft-Windows-Kerberos-Key-Distribution-Center/Operational"
},
"event_data": {
"SerialNumber": "4A00000026B37CA59821F6C9F7000000000026",
"Issuer": "EvtGen-Root-CA",
"Thumbprint": "83875CFCBB86E1C80DB97B6881A03763C0ABEFF9",
"KerbErr": "74",
"ErrorCode": "2148081683",
"Template": "Kerberos Authentication"
}
}
Event ID 200: The Key Distribution Center (KDC) cannot find a suitable certificate to use.
#Description
The Key Distribution Center (KDC) cannot find a suitable certificate to use. This KDC is not enabled for smart card or certificate authentication.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Kerberos-Key-Distribution-Center",
"guid": "3FD9DA1A-5A54-46C5-9A26-9BD7C0685056",
"event_source_name": "",
"event_id": 200,
"version": 0,
"level": 3,
"task": 1,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T20:16:26.074299+00:00",
"event_record_id": 1,
"correlation": {},
"execution": {
"process_id": 968,
"thread_id": 7192
},
"channel": "Microsoft-Windows-Kerberos-Key-Distribution-Center/Operational",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": ""
}
Event ID 201: The Key Distribution Center (KDC) detected Cipher usage that will be unsupported in enforcement phase because service msds-SupportedEncryptionTypes is not defined and the client only supports insec...
#Description
The Key Distribution Center (KDC) detected usage that will be unsupported because service msds-SupportedEncryptionTypes is not defined and the client only supports insecure encryption types.
Fields #
| Name | Description |
|---|---|
AccountName UnicodeString | |
SuppliedRealm UnicodeString | |
AccountSET UnicodeString | |
AccountKeys UnicodeString | |
ServiceName UnicodeString | |
ServiceID SID | |
ServiceSET UnicodeString | |
ServiceKeys UnicodeString | |
DCSET UnicodeString | |
DDSET UnicodeString | |
DCKeys UnicodeString | |
IpAddress UnicodeString | |
Port UInt16 | |
AdvertizedEtypes UnicodeString | |
Cipher UnicodeString |
Event ID 201: The Key Distribution Center (KDC) detected Cipher usage that will be unsupported because service msds-SupportedEncryptionTypes is not defined and the ...
#Description
The Key Distribution Center (KDC) detected Cipher usage that will be unsupported because service msds-SupportedEncryptionTypes is not defined and the client only supports insecure encryption types.
Message #
Fields #
| Name | Description |
|---|---|
AccountName UnicodeString | |
SuppliedRealm UnicodeString | |
AccountSET UnicodeString | |
AccountKeys UnicodeString | |
ServiceName UnicodeString | |
ServiceID SID | |
ServiceSET UnicodeString | |
ServiceKeys UnicodeString | |
DCSET UnicodeString | |
DDSET UnicodeString | |
DCKeys UnicodeString | |
IpAddress UnicodeString | |
Port UInt16 | |
AdvertizedEtypes UnicodeString | |
Cipher UnicodeString |
Event ID 202: The Key Distribution Center (KDC) detected Cipher usage that will be unsupported in enforcement phase because the service msds-SupportedEncryptionTypes is not defined and the service account only h...
#Description
The Key Distribution Center (KDC) detected usage that will be unsupported because the service msds-SupportedEncryptionTypes is not defined and the service account only has insecure keys.
Fields #
| Name | Description |
|---|---|
AccountName UnicodeString | |
SuppliedRealm UnicodeString | |
AccountSET UnicodeString | |
AccountKeys UnicodeString | |
ServiceName UnicodeString | |
ServiceID SID | |
ServiceSET UnicodeString | |
ServiceKeys UnicodeString | |
DCSET UnicodeString | |
DDSET UnicodeString | |
DCKeys UnicodeString | |
IpAddress UnicodeString | |
Port UInt16 | |
AdvertizedEtypes UnicodeString | |
Cipher UnicodeString |
Event ID 202: The Key Distribution Center (KDC) detected Cipher usage that will be unsupported because the service msds-SupportedEncryptionTypes is not defined and ...
#Description
The Key Distribution Center (KDC) detected Cipher usage that will be unsupported because the service msds-SupportedEncryptionTypes is not defined and the service account only has insecure keys.
Message #
Fields #
| Name | Description |
|---|---|
AccountName UnicodeString | |
SuppliedRealm UnicodeString | |
AccountSET UnicodeString | |
AccountKeys UnicodeString | |
ServiceName UnicodeString | |
ServiceID SID | |
ServiceSET UnicodeString | |
ServiceKeys UnicodeString | |
DCSET UnicodeString | |
DDSET UnicodeString | |
DCKeys UnicodeString | |
IpAddress UnicodeString | |
Port UInt16 | |
AdvertizedEtypes UnicodeString | |
Cipher UnicodeString |
Event ID 203: The Key Distribution Center (KDC) blocked cipher usage because service msds-SupportedEncryptionTypes is not defined and the client only supports insecure encryption types
#Description
The Key Distribution Center (KDC) blocked cipher usage because service msds-SupportedEncryptionTypes is not defined and the client only supports insecure encryption types.
Fields #
| Name | Description |
|---|---|
AccountName UnicodeString | |
SuppliedRealm UnicodeString | |
AccountSET UnicodeString | |
AccountKeys UnicodeString | |
ServiceName UnicodeString | |
ServiceID SID | |
ServiceSET UnicodeString | |
ServiceKeys UnicodeString | |
DCSET UnicodeString | |
DDSET UnicodeString | |
DCKeys UnicodeString | |
IpAddress UnicodeString | |
Port UInt16 | |
AdvertizedEtypes UnicodeString |
Event ID 203: The Key Distribution Center (KDC) blocked cipher usage because service msds-SupportedEncryptionTypes is not defined and the client only supports in...
#Description
The Key Distribution Center (KDC) blocked cipher usage because service msds-SupportedEncryptionTypes is not defined and the client only supports insecure encryption types.
Message #
Fields #
| Name | Description |
|---|---|
AccountName UnicodeString | |
SuppliedRealm UnicodeString | |
AccountSET UnicodeString | |
AccountKeys UnicodeString | |
ServiceName UnicodeString | |
ServiceID SID | |
ServiceSET UnicodeString | |
ServiceKeys UnicodeString | |
DCSET UnicodeString | |
DDSET UnicodeString | |
DCKeys UnicodeString | |
IpAddress UnicodeString | |
Port UInt16 | |
AdvertizedEtypes UnicodeString |
Event ID 204: The Key Distribution Center (KDC) blocked cipher usage because the service msds-SupportedEncryptionTypes is not defined and the service account only has insecure keys
#Description
The Key Distribution Center (KDC) blocked cipher usage because the service msds-SupportedEncryptionTypes is not defined and the service account only has insecure keys.
Fields #
| Name | Description |
|---|---|
AccountName UnicodeString | |
SuppliedRealm UnicodeString | |
AccountSET UnicodeString | |
AccountKeys UnicodeString | |
ServiceName UnicodeString | |
ServiceID SID | |
ServiceSET UnicodeString | |
ServiceKeys UnicodeString | |
DCSET UnicodeString | |
DDSET UnicodeString | |
DCKeys UnicodeString | |
IpAddress UnicodeString | |
Port UInt16 | |
AdvertizedEtypes UnicodeString |
Event ID 204: The Key Distribution Center (KDC) blocked cipher usage because the service msds-SupportedEncryptionTypes is not defined and the service account onl...
#Description
The Key Distribution Center (KDC) blocked cipher usage because the service msds-SupportedEncryptionTypes is not defined and the service account only has insecure keys.
Message #
Fields #
| Name | Description |
|---|---|
AccountName UnicodeString | |
SuppliedRealm UnicodeString | |
AccountSET UnicodeString | |
AccountKeys UnicodeString | |
ServiceName UnicodeString | |
ServiceID SID | |
ServiceSET UnicodeString | |
ServiceKeys UnicodeString | |
DCSET UnicodeString | |
DDSET UnicodeString | |
DCKeys UnicodeString | |
IpAddress UnicodeString | |
Port UInt16 | |
AdvertizedEtypes UnicodeString |
Event ID 205: The Key Distribution Center (KDC) detected explicit insecure cipher enablement in the Default Domain Supported Encryption Types policy configuration
#Description
The Key Distribution Center (KDC) detected explicit insecure cipher enablement in the Default Domain Supported Encryption Types policy configuration.
Fields #
| Name | Description |
|---|---|
CipherName UnicodeString | |
DDSET UnicodeString |
Event ID 205: The Key Distribution Center (KDC) detected explicit insecure cipher enablement in the Default Domain Supported Encryption Types policy configuration.
#Event ID 206: The Key Distribution Center (KDC) detected Cipher usage that will be unsupported in enforcement phase because service msds-SupportedEncryptionTypes is configured to only support AES-SHA1 but the cl...
#Description
The Key Distribution Center (KDC) detected Cipher usage that will be unsupported in enforcement phase because service msds-SupportedEncryptionTypes is configured to only support AES-SHA1 but the client does not advertize AES-SHA1.
Message #
Fields #
| Name | Description |
|---|---|
AccountName UnicodeString | |
SuppliedRealm UnicodeString | |
AccountSET UnicodeString | |
AccountKeys UnicodeString | |
ServiceName UnicodeString | |
ServiceID SID | |
ServiceSET UnicodeString | |
ServiceKeys UnicodeString | |
DCSET UnicodeString | |
DDSET UnicodeString | |
DCKeys UnicodeString | |
IpAddress UnicodeString | |
Port UInt16 | |
AdvertizedEtypes UnicodeString | |
Cipher UnicodeString |
Event ID 207: The Key Distribution Center (KDC) detected Cipher usage that will be unsupported in enforcement phase because the service msds-SupportedEncryptionTypes is configured to only support AES-SHA1 but th...
#Description
The Key Distribution Center (KDC) detected Cipher usage that will be unsupported in enforcement phase because the service msds-SupportedEncryptionTypes is configured to only support AES-SHA1 but the service account does not have AES-SHA1 keys.
Message #
Fields #
| Name | Description |
|---|---|
AccountName UnicodeString | |
SuppliedRealm UnicodeString | |
AccountSET UnicodeString | |
AccountKeys UnicodeString | |
ServiceName UnicodeString | |
ServiceID SID | |
ServiceSET UnicodeString | |
ServiceKeys UnicodeString | |
DCSET UnicodeString | |
DDSET UnicodeString | |
DCKeys UnicodeString | |
IpAddress UnicodeString | |
Port UInt16 | |
AdvertizedEtypes UnicodeString | |
Cipher UnicodeString |
Event ID 208: The Key Distribution Center (KDC) blocked cipher usage because service msds-SupportedEncryptionTypes is configured to only support AES-SHA1 but the client does not advertize AES-SHA1
#Description
The Key Distribution Center (KDC) blocked cipher usage because service msds-SupportedEncryptionTypes is configured to only support AES-SHA1 but the client does not advertize AES-SHA1.
Message #
Fields #
| Name | Description |
|---|---|
AccountName UnicodeString | |
SuppliedRealm UnicodeString | |
AccountSET UnicodeString | |
AccountKeys UnicodeString | |
ServiceName UnicodeString | |
ServiceID SID | |
ServiceSET UnicodeString | |
ServiceKeys UnicodeString | |
DCSET UnicodeString | |
DDSET UnicodeString | |
DCKeys UnicodeString | |
IpAddress UnicodeString | |
Port UInt16 | |
AdvertizedEtypes UnicodeString |
Event ID 209: The Key Distribution Center (KDC) blocked cipher usage because the service msds-SupportedEncryptionTypes is configured to only support AES-SHA1 but the service account does not have AES-SHA1 keys
#Description
The Key Distribution Center (KDC) blocked cipher usage because the service msds-SupportedEncryptionTypes is configured to only support AES-SHA1 but the service account does not have AES-SHA1 keys.
Message #
Fields #
| Name | Description |
|---|---|
AccountName UnicodeString | |
SuppliedRealm UnicodeString | |
AccountSET UnicodeString | |
AccountKeys UnicodeString | |
ServiceName UnicodeString | |
ServiceID SID | |
ServiceSET UnicodeString | |
ServiceKeys UnicodeString | |
DCSET UnicodeString | |
DDSET UnicodeString | |
DCKeys UnicodeString | |
IpAddress UnicodeString | |
Port UInt16 | |
AdvertizedEtypes UnicodeString |
Event ID 300: The Key Distribution Center (KDC) is being started.
#Description
The Key Distribution Center (KDC) is being started.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Kerberos-Key-Distribution-Center",
"guid": "3FD9DA1A-5A54-46C5-9A26-9BD7C0685056",
"event_source_name": "",
"event_id": 300,
"version": 0,
"level": 4,
"task": 1,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T21:48:07.889406+00:00",
"event_record_id": 21,
"correlation": {},
"execution": {
"process_id": 936,
"thread_id": 2856
},
"channel": "Microsoft-Windows-Kerberos-Key-Distribution-Center/Operational",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": ""
}
Event ID 301: The Key Distribution Center (KDC) has stopped with error code: ErrorCode.
#Event ID 302: The Key Distribution Center (KDC) uses the below KDC certificate for smart card or certificate authentication.
#Description
The Key Distribution Center (KDC) uses the below KDC certificate for smart card or certificate authentication.
Message #
Fields #
| Name | Description |
|---|---|
Issuer UnicodeString | |
SerialNumber UnicodeString | |
Thumbprint UnicodeString | |
Template UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Kerberos-Key-Distribution-Center",
"guid": "3FD9DA1A-5A54-46C5-9A26-9BD7C0685056",
"event_source_name": "",
"event_id": 302,
"version": 0,
"level": 4,
"task": 1,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T20:17:39.777902+00:00",
"event_record_id": 15,
"correlation": {},
"execution": {
"process_id": 968,
"thread_id": 9364
},
"channel": "Microsoft-Windows-Kerberos-Key-Distribution-Center/Operational",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Issuer": "EvtGen-Root-CA",
"SerialNumber": "4A000000035FD5C8BB1377E3DC000000000003",
"Thumbprint": "DB0FEA9B641F3814FC5168AE83EF7839AF1BB012",
"Template": "DomainController"
},
"message": ""
}
Event ID 303: A Kerberos ticket-granting-ticket (TGT) was issued for a member of the Protected User group.
#Description
A Kerberos ticket-granting-ticket (TGT) was issued for a member of the Protected User group.
Message #
Fields #
| Name | Description |
|---|---|
TargetUserName UnicodeString | Account name of the target. |
TargetDomainName UnicodeString | Domain or machine name of the target account. |
TargetSid SID | |
DeviceName UnicodeString | |
ServiceName UnicodeString | |
ServiceSid SID | |
TicketOptions HexInt32 | Bitmask flags
|
Status HexInt32 | NTSTATUS reference |
TicketEncryptionType HexInt32 | Known values
|
PreAuthType UnicodeString | Known values
|
IpAddress UnicodeString | |
IpPort UnicodeString | |
CertIssuerName UnicodeString | |
CertSerialNumber UnicodeString | |
CertThumbprint UnicodeString | |
SiloName UnicodeString | |
PolicyName UnicodeString | |
TGTLifetime UInt32 |
Event ID 303: A Kerberos ticket-granting-ticket (TGT) was issued for a member of the Protected User group
#Description
A Kerberos ticket-granting-ticket (TGT) was issued for a member of the Protected User group.
Fields #
| Name | Description |
|---|---|
TargetUserName UnicodeString | Account name of the target. |
TargetDomainName UnicodeString | Domain or machine name of the target account. |
TargetSid SID | |
DeviceName UnicodeString | |
ServiceName UnicodeString | |
ServiceSid SID | |
TicketOptions HexInt32 | Bitmask flags
|
Status HexInt32 | NTSTATUS reference |
TicketEncryptionType HexInt32 | Known values
|
PreAuthType UnicodeString | Known values
|
IpAddress UnicodeString | |
IpPort UnicodeString | |
CertIssuerName UnicodeString | |
CertSerialNumber UnicodeString | |
CertThumbprint UnicodeString | |
SiloName UnicodeString | |
PolicyName UnicodeString | |
TGTLifetime UInt32 |
Event ID 304: A Kerberos service ticket was issued for a member of the Protected User group.
#Description
A Kerberos service ticket was issued for a member of the Protected User group.
Message #
Fields #
| Name | Description |
|---|---|
TargetUserName UnicodeString | Account name of the target. |
TargetDomainName UnicodeString | Domain or machine name of the target account. |
DeviceName UnicodeString | |
ServiceName UnicodeString | |
ServiceSid SID | |
TicketOptions HexInt32 | Bitmask flags
|
TicketEncryptionType HexInt32 | Known values
|
IpAddress UnicodeString | |
IpPort UnicodeString | |
Status HexInt32 | NTSTATUS reference |
LogonGuid GUID | |
TransitedServices UnicodeString | |
SiloName UnicodeString | |
PolicyName UnicodeString |
Event ID 304: A Kerberos service ticket was issued for a member of the Protected User group
#Description
A Kerberos service ticket was issued for a member of the Protected User group.
Fields #
| Name | Description |
|---|---|
TargetUserName UnicodeString | Account name of the target. |
TargetDomainName UnicodeString | Domain or machine name of the target account. |
DeviceName UnicodeString | |
ServiceName UnicodeString | |
ServiceSid SID | |
TicketOptions HexInt32 | Bitmask flags
|
TicketEncryptionType HexInt32 | Known values
|
IpAddress UnicodeString | |
IpPort UnicodeString | |
Status HexInt32 | NTSTATUS reference |
LogonGuid GUID | |
TransitedServices UnicodeString | |
SiloName UnicodeString | |
PolicyName UnicodeString |
Event ID 305: A Kerberos ticket-granting-ticket (TGT) was issued, but it will be denied when Authentication Policy is enforced because the device does not meet t...
#Description
A Kerberos ticket-granting-ticket (TGT) was issued, but it will be denied when Authentication Policy is enforced because the device does not meet the access control restrictions.
Message #
Fields #
| Name | Description |
|---|---|
TargetUserName UnicodeString | Account name of the target. |
TargetDomainName UnicodeString | Domain or machine name of the target account. |
TargetSid SID | |
DeviceName UnicodeString | |
ServiceName UnicodeString | |
ServiceSid SID | |
TicketOptions HexInt32 | Bitmask flags
|
Status HexInt32 | NTSTATUS reference |
TicketEncryptionType HexInt32 | Known values
|
PreAuthType UnicodeString | Known values
|
IpAddress UnicodeString | |
IpPort UnicodeString | |
CertIssuerName UnicodeString | |
CertSerialNumber UnicodeString | |
CertThumbprint UnicodeString | |
SiloName UnicodeString | |
PolicyName UnicodeString | |
TGTLifetime UInt32 |
References #
- RFC 4120 §7.5.9 Kerberos error codes https://datatracker.ietf.org/doc/html/rfc4120#section-7.5.9
Event ID 305: A Kerberos ticket-granting-ticket (TGT) was issued, but it will be denied when Authentication Policy is enforced because the device does not meet the access control restrictions
#Description
A Kerberos ticket-granting-ticket (TGT) was issued, but it will be denied when Authentication Policy is enforced because the device does not meet the access control restrictions.
Fields #
| Name | Description |
|---|---|
TargetUserName UnicodeString | Account name of the target. |
TargetDomainName UnicodeString | Domain or machine name of the target account. |
TargetSid SID | |
DeviceName UnicodeString | |
ServiceName UnicodeString | |
ServiceSid SID | |
TicketOptions HexInt32 | Bitmask flags
|
Status HexInt32 | NTSTATUS reference |
TicketEncryptionType HexInt32 | Known values
|
PreAuthType UnicodeString | Known values
|
IpAddress UnicodeString | |
IpPort UnicodeString | |
CertIssuerName UnicodeString | |
CertSerialNumber UnicodeString | |
CertThumbprint UnicodeString | |
SiloName UnicodeString | |
PolicyName UnicodeString | |
TGTLifetime UInt32 |
Event ID 306: A Kerberos service ticket was issued, but it will be denied when Authentication Policy is enforced for a member of the Protected User group because...
#Description
A Kerberos service ticket was issued, but it will be denied when Authentication Policy is enforced for a member of the Protected User group because the user, device, or both does not meet the access control restrictions. Account Information: Account Name: TargetUserName Account Domain: TargetDomainName Logon GUID: LogonGuid Authentication Policy Information: Silo Name: SiloName Policy Name: PolicyName Device Information: Device Name: DeviceName Service Information: Service Name: ServiceName Service ID: ServiceSid Network Information: Client Address: IpAddress Client Port: IpPort Additional Information: Ticket Options: TicketOptions Ticket Encryption Type: TicketEncryptionType Failure Code: Status Transited Services: TransitedServices This event is generated every time access is requested to a resource such as a computer or a Windows service. The service name indicates the resource to which access was requested. This event can be correlated with Windows logon events by comparing the Logon GUID fields in each event. The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket. Ticket options, encryption types, and failure codes are defined in RFC 4120.
Message #
Fields #
| Name | Description |
|---|---|
TargetUserName UnicodeString | Account name of the target. |
TargetDomainName UnicodeString | Domain or machine name of the target account. |
DeviceName UnicodeString | |
ServiceName UnicodeString | |
ServiceSid SID | |
TicketOptions HexInt32 | Bitmask flags
|
TicketEncryptionType HexInt32 | Known values
|
IpAddress UnicodeString | |
IpPort UnicodeString | |
Status HexInt32 | NTSTATUS reference |
LogonGuid GUID | |
TransitedServices UnicodeString | |
SiloName UnicodeString | |
PolicyName UnicodeString |
References #
- RFC 4120 §7.5.9 Kerberos error codes https://datatracker.ietf.org/doc/html/rfc4120#section-7.5.9
Event ID 306: A Kerberos service ticket was issued, but it will be denied when Authentication Policy is enforced for a member of the Protected User group because the user, device, or both does not meet the acces...
#Fields #
| Name | Description |
|---|---|
TargetUserName UnicodeString | Account name of the target. |
TargetDomainName UnicodeString | Domain or machine name of the target account. |
DeviceName UnicodeString | |
ServiceName UnicodeString | |
ServiceSid SID | |
TicketOptions HexInt32 | Bitmask flags
|
TicketEncryptionType HexInt32 | Known values
|
IpAddress UnicodeString | |
IpPort UnicodeString | |
Status HexInt32 | NTSTATUS reference |
LogonGuid GUID | |
TransitedServices UnicodeString | |
SiloName UnicodeString | |
PolicyName UnicodeString |
Event ID 307: The Key Distribution Center (KDC) used the PKINIT protocol with encryption mode for the client ClientName.
#Event ID 308: The Key Distribution Center (KDC) is unable to use the PKINIT protocol because the client ClientName requested encryption mode and the KDC does not support...
#Event ID 309: The kerberos client used a hash algorithm for the PKINIT protocol that is being audited: Algorithm.
#Event ID 310: The kerberos client used a hash algorithm for the PKINIT protocol that is not suppported: Algorithm.
#Event ID 311: The Kerberos client did not supply a supported encryption type for use with the PKINIT protocol using encryption mode.
#Event ID 312: The Key Distribution Center (KDC) has an invalid hash algorithm configuration for PKINIT.
#Description
The Key Distribution Center (KDC) has an invalid hash algorithm configuration for PKINIT. This might result in PKINIT failures.
Message #
Event ID 313: The Key Distribution Center (KDC) encountered invalid certificate strong name match policy.
#Event ID 314: An unauthorized Kerberos client attempted to fetch DMSA keys.
#Event ID 315: A Kerberos client attempted to fetch DMSA keys.
#Event ID 400: A Kerberos authentication ticket (TGT) was requested.
#Description
A Kerberos authentication ticket (TGT) was requested.
Message #
Fields #
| Name | Description |
|---|---|
TargetUserName UnicodeString | Account name of the target. |
TargetDomainName UnicodeString | Domain or machine name of the target account. |
TargetSid SID | |
ServiceName UnicodeString | |
ServiceSid SID | |
TicketOptions UInt32 | Bitmask flags
|
Status UInt32 | NTSTATUS reference |
TicketEncryptionType UInt32 | Known values
|
PreAuthType UInt32 | Known values
|
IpAddressLength UInt32 | |
IpAddress Binary | |
CertIssuerName UnicodeString | |
CertSerialNumber UnicodeString | |
CertThumbprint UnicodeString | |
ResponseTicket UnicodeString | |
ClientNetbiosName UnicodeString | |
ResponseExtendedNtStatusCode UInt32 | |
ResponseTicketLength UInt32 | |
ResponseTicketStartTime FILETIME | |
ResponseTicketEndTime FILETIME | |
RequestSupportedEncryptionTypes UnicodeString | |
RequestFullServiceName UnicodeString | |
RequestFullServiceNameType UInt32 | Known values
|
RequestClientName UnicodeString | |
RequestClientNameType UInt32 | Known values
|
RequestRealm UnicodeString | |
ResponseTicketFullServiceName UnicodeString | |
ResponseTicketFullServiceNameType UInt32 | Known values
|
ResponseTicketRealm UnicodeString | |
ResponseTicketKeyVersion UInt32 | |
ResponseEncryptedDataEncryptionType UInt32 | Known values
|
ArmorKeyEncryptionType UInt32 | Known values
|
ClientPreAuthEncryptionType UInt32 | Known values
|
PacRequestType UInt32 | |
CertNotBefore FILETIME | |
CertNotAfter FILETIME | |
CertSubjectName UnicodeString | |
PreAuthNonce UInt32 | |
LogonStatus UInt32 | |
PreAuthSupportedEncryptionTypes UnicodeString | |
ClientCertificateContextLength UInt32 | |
ClientCertificateContext Binary | |
UsedOldPassword Boolean | |
UserObjectGuid GUID |
Event ID 401: A Kerberos service ticket was requested.
#Description
A Kerberos service ticket was requested.
Message #
Fields #
| Name | Description |
|---|---|
TargetUserName UnicodeString | Account name of the target. |
TargetDomainName UnicodeString | Domain or machine name of the target account. |
ServiceName UnicodeString | |
ServiceSid SID | |
TicketOptions UInt32 | Bitmask flags
|
TicketEncryptionType UInt32 | Known values
|
IpAddressLength UInt32 | |
IpAddress Binary | |
Status UInt32 | NTSTATUS reference |
LogonGuid GUID | |
TransmittedServices UnicodeString | |
RequestTicketHash UnicodeString | |
ResponseTicketHash UnicodeString | |
ClientNetbiosName UnicodeString | |
ResponseExtendedNtStatusCode UInt32 | |
PacOptions UInt32 | Bitmask flags
|
RequestTicketLength UInt32 | |
ResponseTicketLength UInt32 | |
RequestTicketAuthTime FILETIME | |
RequestTicketFlags UInt32 | Bitmask flags
|
RequestTicketRenewUntil FILETIME | |
RequestTicketStartTime FILETIME | |
RequestTicketEndTime FILETIME | |
ResponseTicketStartTime FILETIME | |
ResponseTicketEndTime FILETIME | |
RequestSupportedEncryptionTypes UnicodeString | |
RequestAuthDataEncryptionType UInt32 | Known values
|
RequestAuthDataLength UInt32 | |
RequestNonce UInt32 | |
RequestFullServiceName UnicodeString | |
RequestFullServiceNameType UInt32 | Known values
|
RequestRealm UnicodeString | |
RequestTicketFullServiceName UnicodeString | |
RequestTicketFullServiceNameType UInt32 | Known values
|
RequestTicketRealm UnicodeString | |
RequestTicketClientName UnicodeString | |
RequestTicketClientNameType UInt32 | Known values
|
RequestTicketClientRealm UnicodeString | |
ResponseTicketFullServiceName UnicodeString | |
ResponseTicketFullServiceNameType UInt32 | Known values
|
ResponseTicketRealm UnicodeString | |
RequestTicketKeyVersion UInt32 | |
ResponseTicketKeyVersion UInt32 | |
RequestTicketEncryptionType UInt32 | Known values
|
ArmorKeyEncryptionType UInt32 | Known values
|
U2UTgtAccountName UnicodeString | |
U2UTgtCRealm UnicodeString | |
U2UTgtCName UnicodeString | |
U2UTicketLength UInt32 | |
U2UTicketEncryptionType UInt32 | Known values
|
U2UTicketHash UnicodeString | |
U2UTicketKeyVersion UInt32 | |
U2UTicketFullServiceName UnicodeString | |
U2UTicketFullServiceNameType UInt32 | Known values
|
S4UAccountName UnicodeString | |
S4UPACClientName UnicodeString | |
S4UPACClientRealm UnicodeString | |
S4UTargetName UnicodeString | |
S4UNonce UInt32 | |
S4URequestorSid SID | |
S4UAdditionalTicketKeyVersion UInt32 | |
S4URequestorServiceName UnicodeString | |
S4URequestorServiceRealm UnicodeString | |
S4UAdditionalTicketLength UInt32 | |
S4UAdditionalTicketEncryptionType UInt32 | Known values
|
S4UAdditionalTicketHash UnicodeString | |
S4UAdditionalTicketFullServiceName UnicodeString | |
S4UAdditionalTicketFullServiceNameType UInt32 | Known values
|
ServiceObjectGuid GUID | |
RequestTicketPacLogonInfoLength UInt32 | |
RequestTicketPacLogonInfo Binary | |
RequestTicketPacUpnDnsInfoLength UInt32 | |
RequestTicketPacUpnDnsInfo Binary | |
RequestTicketPacRequestorSid SID | |
RequestTicketPacLogonServer UnicodeString | |
RequestTicketPacLogonDomainName UnicodeString | |
RequestTicketPacFullName UnicodeString | |
RequestTicketPacHomeDirectory UnicodeString | |
RequestTicketPacGroupIds UnicodeString | |
RequestTicketPacUserId UInt32 | |
RequestTicketPacPrimaryGroupId UInt32 | |
RequestTicketPacGroupCount UInt32 | |
RequestTicketPacBadPasswordCount UInt32 | |
RequestTicketPacLogonCount UInt32 | |
RequestTicketPacUserAccountControlFlags UInt32 | |
RequestTicketPacUserFlags UInt32 | |
RequestTicketPacLogonTime FILETIME | |
RequestTicketPacLogoffTime FILETIME | |
RequestTicketPacKickOffTime FILETIME | |
RequestTicketPacPasswordLastSet FILETIME | |
RequestTicketPacLastSuccessfulLogon FILETIME | |
RequestTicketPacLastFailedLogon FILETIME | |
RequestTicketPacFailedAttemptCountSinceSuccessfulLogon UInt32 |
Event ID 2147483651: Could not find principal Principal.
#Event ID 2147483652: Domain Domain propagated to us but did not authenticate.
#Event ID 2147483660: A request failed from client realm ClientRealm for a ticket in realm Realm.
#Event ID 2147483667: This event indicates an attempt was made to use smartcard logon, but the KDC is unable to use the PKINIT protocol because it is missing a suitable ...
#Description
This event indicates an attempt was made to use smartcard logon, but the KDC is unable to use the PKINIT protocol because it is missing a suitable certificate.
Message #
Event ID 2147483668: The currently selected KDC certificate was once valid, but now is invalid and no suitable replacement was found.
#Description
The currently selected KDC certificate was once valid, but now is invalid and no suitable replacement was found. Smartcard logon may not function correctly if this problem is not remedied. Have the system administrator check on the state of the domain's public key infrastructure. The chain status is in the error data.
Message #
Event ID 2147483669: The client certificate for the user Domain\Username is not valid, and resulted in a failed smartcard logon.
#Description
The client certificate for the user Domain\Username is not valid, and resulted in a failed smartcard logon. Please contact the user for more information about the certificate they're attempting to use for smartcard logon. The chain status was : Status
Message #
Fields #
| Name | Description |
|---|---|
Domain | |
Username | |
Status | |
__binLength | |
binary |
Event ID 2147483670: The KDC encountered a trust loop when building a list of trusted domains.
#Event ID 2147483671: The KDC received invalid messages of type Type.
#Event ID 2147483672: A service ticket request by client Client for Server was rejected because User2User was required.
#Description
A service ticket request by client Client for Server was rejected because User2User was required. The KDC responds with this error when a client requests a service ticket for a user principal (a security risk). The client must support User2User in order to obtain a service ticket for the requested service principal
Message #
Fields #
| Name | Description |
|---|---|
Client | |
Server | |
__binLength | |
binary |
Event ID 2147483673: The account Name from domain Domain is attempting to use S4USelf for the target client Target, but is not allowed to perform group expansion on this client's...
#Description
The account Name from domain Domain is attempting to use S4USelf for the target client Target, but is not allowed to perform group expansion on this client's user object. It may be necessary to adjust the ACL on the TokenGroupsGlobalAndUniversal attribute on the target client's user object to allow S4USelf to function correctly. This can also be accomplished by adding Name to the Windows Authorization Access Group.
Message #
Fields #
| Name | Description |
|---|---|
Name | |
Domain | |
Target | |
__binLength | |
binary |
Event ID 2147483676: When generating a cross realm referral from domain Domain the KDC was not able to find the suitable key to verify the ticket.
#Description
When generating a cross realm referral from domain Domain the KDC was not able to find the suitable key to verify the ticket. The ticket key version in the request was RequestedKeyVersion and the available key version was AvailableKeyVersion. This most common reason for this error is a delay in replicating the keys. In order to remove this problem try forcing replication or wait for the replication of keys to occur.
Message #
Fields #
| Name | Description |
|---|---|
Domain | |
RequestedKeyVersion | |
AvailableKeyVersion | |
__binLength | |
binary |
Event ID 2147483677: The Key Distribution Center (KDC) cannot find a suitable certificate to use for smart card logons, or the KDC certificate could not be verified.
#Description
The Key Distribution Center (KDC) cannot find a suitable certificate to use for smart card logons, or the KDC certificate could not be verified. Smart card logon may not function correctly if this problem is not resolved. To correct this problem, either verify the existing KDC certificate using certutil.exe or enroll for a new KDC certificate.
Message #
Event ID 2147483678: The Kerberos Key Distribution Center failed to locate the forest or domain Forest to search.
#Event ID 2147483679: A ticket to the service Server is issued for account Account.
#Description
A ticket to the service Server is issued for account Account. The size of the encrypted part of this ticket is EncryptedTicketSize bytes, which is close or greater than the configured ticket size threshold (TicketSizeThreshold bytes). This ticket or any additional tickets issued from this ticket might result in authentication failures if the client or server application allocates SSPI token buffers bounded by a value that is close to the threshold value. The size of ticket is largely determined by the size of authorization data it carries. The size of authorization data is determined by the groups the account is member of, the claims data the account is setup for, and the resource groups resolved in the resource domain.
Message #
Fields #
| Name | Description |
|---|---|
Account | |
Server | |
EncryptedTicketSize | |
TicketSizeThreshold | |
__binLength | |
binary |
Event ID 2147483680: The Key Distribution Center (KDC) uses a certificate without KDC Extended Key Usage (EKU) which can result in authentication failures for device ce...
#Description
The Key Distribution Center (KDC) uses a certificate without KDC Extended Key Usage (EKU) which can result in authentication failures for device certificate logon and smart card logon from non-domain-joined devices. Enrollment of a KDC certificate with KDC EKU (Kerberos Authentication template) is required to remove this warning.
Message #
Event ID 2147483681: The Key Distribution Center (KDC) encountered failures when updating the krbtgt account for the Dynamic Access Control and Kerberos armoring policy...
#Description
The Key Distribution Center (KDC) encountered failures when updating the krbtgt account for the Dynamic Access Control and Kerberos armoring policy capability for the domain. This update was performed so that all the domain controllers including read-only domain controllers (RODCs) in this domain could advertise support for Dynamic Access Control and Kerberos armoring. This failure indicates that there could be domain controllers that have not received updated krbtgt account values. If the update to the krbtgt account is in transit, then you can run Gpupdate /force as a possible workaround to this failure. More information about this update: Object Rid: %1 Update bits: %2 Bitmask: %3 Error Code: %4
Message #
Event ID 2147483682: The Key Distribution Center (KDC) has the Dynamic Access Control and Kerberos armoring policy configured for a level which requires a higher domain...
#Description
The Key Distribution Center (KDC) has the Dynamic Access Control and Kerberos armoring policy configured for a level which requires a higher domain functional level. Until the domain functional level is raised, the KDC will only support the level configured as Supported.
Message #
Event ID 2147483683: The Key Distribution Center (KDC) encountered a ticket-granting-ticket (TGT) from another KDC that did not contain a PAC attributes field.
#Event ID 2147483684: The Key Distribution Center (KDC) encountered a ticket that did not contain a PAC while processing a request for another ticket.
#Description
The Key Distribution Center (KDC) encountered a ticket that did not contain a PAC while processing a request for another ticket. This prevented security checks from running and could open security vulnerabilities. See https://go.microsoft.com/fwlink/?linkid=2173051 to learn more. Client: ClientRealm\\ClientName Ticket for: ServerName
Message #
Fields #
| Name | Description |
|---|---|
ClientRealm | |
ClientName | |
ServerName | |
__binLength | |
binary |
Event ID 2147483685: The Key Distribution Center (KDC) encountered a ticket that did not contain information about the account that requested the ticket while processin...
#Description
The Key Distribution Center (KDC) encountered a ticket that did not contain information about the account that requested the ticket while processing a request for another ticket. This prevented security checks from running and could open security vulnerabilities. See https://go.microsoft.com/fwlink/?linkid=2173051 to learn more. Ticket PAC constructed by: IssuingKDC Client: ClientRealm\\ClientName Ticket for: ServerName
Message #
Fields #
| Name | Description |
|---|---|
IssuingKDC | |
ClientRealm | |
ClientName | |
ServerName | |
__binLength | |
binary |
Event ID 2147483686: The Key Distribution Center (KDC) encountered a ticket that contained inconsistent information about the account that requested the ticket.
#Description
The Key Distribution Center (KDC) encountered a ticket that contained inconsistent information about the account that requested the ticket. This could mean that the account has been renamed since the ticket was issued, which may have been part of an attempted exploit. See https://go.microsoft.com/fwlink/?linkid=2173051 to learn more. Ticket PAC constructed by: IssuingKDC Client: ClientRealm\\ClientName Ticket for: ServerName Requesting Account SID from Active Directory: ActiveDirectorySID Requesting Account SID from Ticket: TicketSID
Message #
Fields #
| Name | Description |
|---|---|
IssuingKDC | |
ClientRealm | |
ClientName | |
ServerName | |
ActiveDirectorySID | |
TicketSID | |
__binLength | |
binary |
Event ID 2147483687: The Key Distribution Center (KDC) encountered a user certificate that was valid but could not be mapped to a user in a secure way.
#Message #
Event ID 2147483688: The Key Distribution Center (KDC) encountered a user certificate that was valid but could not be mapped to a user in a secure way.
#Message #
Event ID 2147483689: The Key Distribution Center (KDC) encountered a user certificate that was valid but contained a different SID than the user to which it mapped.
#Message #
Event ID 2147483690: The Kerberos Key Distribution Center lacks strong keys for account %1.
#Description
The Kerberos Key Distribution Center lacks strong keys for account .
Message #
Event ID 2147483691: The Key Distribution Center (KDC) encountered a ticket that it could not validate the full PAC Signature.
#Description
The Key Distribution Center (KDC) encountered a ticket that it could not validate the full PAC Signature. See https://go.microsoft.com/fwlink/?linkid=2210019 to learn more.
Message #
Event ID 2147483692: The Key Distribution Center (KDC) encountered a ticket that did not contained the full PAC Signature.
#Description
The Key Distribution Center (KDC) encountered a ticket that did not contained the full PAC Signature. See https://go.microsoft.com/fwlink/?linkid=2210019 to learn more.
Message #
Event ID 2147483693: The Key Distribution Center (KDC) encountered a client certificate that was valid but did not chain to a root in the NTAuth store.
#Message #
Event ID 3221225477: The KDC failed to update policy class Class.
#Event ID 3221225478: The KDC failed to update the trusted domain list.
#Description
The KDC failed to update the trusted domain list. The error is in the data.
Message #
Event ID 3221225479: The Security Account Manager failed a KDC request in an unexpected way.
#Event ID 3221225480: The account AccountName did not have a suitable key for generating a Kerberos ticket.
#Description
The account AccountName did not have a suitable key for generating a Kerberos ticket. If the encryption type is supported, changing or setting the password will generate a proper key. The missing key type may be in the data field.
Message #
Fields #
| Name | Description |
|---|---|
AccountName | |
__binLength | |
binary |
Event ID 3221225482: The attempt to change the password on the KRBTGT account failed.
#Description
The attempt to change the password on the KRBTGT account failed. The error code is in the data field.
Message #
Event ID 3221225483: The KDC encountered duplicate names while processing a Kerberos authentication request.
#Description
The KDC encountered duplicate names while processing a Kerberos authentication request. The duplicate name is Name (of type Type). This may result in authentication failures or downgrades to NTLM. In order to prevent this from occurring remove the duplicate entries for Name in Active Directory.
Message #
Fields #
| Name | Description |
|---|---|
Name | |
Type | |
__binLength | |
binary |
Event ID 3221225485: The account for Name has corrupt keys stored in the DS.
#Event ID 3221225486: While processing an AS request for target service Target, the account Account did not have a suitable key for generating a Kerberos ticket.
#Description
While processing an AS request for target service Target, the account Account did not have a suitable key for generating a Kerberos ticket (the missing key has an ID of ID). The requested etypes : RequestedEtypes. The accounts available etypes : AvailableEtypes. Changing or resetting the password of AccountToReset will generate a proper key.
Message #
Fields #
| Name | Description |
|---|---|
Target | |
Account | |
ID | |
RequestedEtypes | |
AvailableEtypes | |
AccountToReset | |
__binLength | |
binary |
Event ID 3221225487: The request for an AS ticket for client Client was forwarded to the PDC.
#Description
The request for an AS ticket for client Client was forwarded to the PDC. An invalid response to this forwarded request was detected and could indicate an attempt to spoof your PDC. There may be additional information in the data field.
Message #
Fields #
| Name | Description |
|---|---|
Client | |
__binLength | |
binary |
Event ID 3221225488: While processing a TGS request for the target server Target, the account Account did not have a suitable key for generating a Kerberos ticket.
#Description
While processing a TGS request for the target server Target, the account Account did not have a suitable key for generating a Kerberos ticket (the missing key has an ID of ID). The requested etypes were RequestedEtypes. The accounts available etypes were AvailableEtypes. Changing or resetting the password of AccountToReset will generate a proper key.
Message #
Fields #
| Name | Description |
|---|---|
Target | |
Account | |
ID | |
RequestedEtypes | |
AvailableEtypes | |
AccountToReset | |
__binLength | |
binary |
Event ID 3221225489: When updating policy class Class, the KDC encountered invalid policy data and has failed to update the policy.
#Event ID 3221225490: During TGS processing, the KDC was unable to verify the signature on the PAC from Name.
#Event ID 3221225498: While processing an AS request for target service Target, the account Name did not have a suitable key for generating a Kerberos ticket.
#Description
While processing an AS request for target service Target, the account Name did not have a suitable key for generating a Kerberos ticket (the missing key has an ID of ID). The requested etypes were RequestedEtypes. The accounts available etypes were AvailableETypes.
Message #
Fields #
| Name | Description |
|---|---|
Target | |
Name | |
ID | |
RequestedEtypes | |
AvailableETypes | |
__binLength | |
binary |
Event ID 3221225499: While processing a TGS request for the target server Target, the account Name did not have a suitable key for generating a Kerberos ticket.
#Description
While processing a TGS request for the target server Target, the account Name did not have a suitable key for generating a Kerberos ticket (the missing key has an ID of ID). The requested etypes were RequestedEtypes. The accounts available etypes were AvailableETypes.
Message #
Fields #
| Name | Description |
|---|---|
Target | |
Name | |
ID | |
RequestedEtypes | |
AvailableETypes | |
__binLength | |
binary |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 3fd9da1a-5a54-46c5-9a26-9bd7c0685056
Defined in kdcsvc.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.4893, captured 2026-06-02