Microsoft-Windows-Security-Kerberos

EventTitleChannelSampleRule
3A Kerberos error message was received:OperationalYN
3A Kerberos error message was received:SystemYN
4The Kerberos client received a KRB_AP_ERR_MODIFIED error from the serverOperationalYN
4The Kerberos client received a KRB_AP_ERR_MODIFIED error from the serverSystemYN
5The Kerberos client received a KRB_AP_ERR_TKT_NYV error from the serverOperationalYN
5The Kerberos client received a KRB_AP_ERR_TKT_NYV error from the serverSystemYN
6The Kerberos SSPI package generated an output token of size Error bytes, which …OperationalNN
7The digitally signed Privilege Attribute Certificate (PAC) that contains the …OperationalNN
8The domain controller rejected the client certificate of user __binLength, used …OperationalNN
9The client has failed to validate the domain controller certificate forOperationalNN
10The Kerberos subsystem currently cannot retrieve tickets from your domain …OperationalNN
11The Distinguished Name in the subject field of your smart card logon certificate …OperationalNN
12While using your smart card over a VPN connection, the Kerberos subsystem …OperationalNN
13An error occurred while initializing the smart card logon library: Error.OperationalNN
14The password stored in Credential Manager is invalidOperationalNN
15The Kerberos SSPI package generated an output token of size Error bytes, which …OperationalNN
16The Kerberos SSPI package failed to find the smart card certificate in the …OperationalNN
17The Kerberos SSPI package failed to locate the forest or domain Error to searchOperationalNN
18The delegated TGT for the user (__binLength) has expiredOperationalNN
19The KDC certificate for the domain controller does not contain the KDC Extended …OperationalNN
20The KDC certificate for the domain controller does not have the DNS name of …OperationalNN
27Kerberos client event 27 (manifest stub).OperationalNN
100The service principal name (SPN) SPN is not registered, which caused Kerberos …OperationalYN
101The service principal name (SPN) SPN is registered on multiple accounts which …OperationalNN
102Trust validation of the certificate for the Kerberos Key Distribution Center …OperationalNN
103Trust validation of the client certificate for ClientUpn failed: ErrorCode on …OperationalNN
104The Kerberos Key Distribution Center (KDC) for the domain TargetDomain does not …OperationalNN
105The Kerberos client could not retrieve passwords for the group managed service …OperationalNN
106The Kerberos client received a KDC certificate that does not have KDC EKU (not …OperationalNN
107The Kerberos client received a KDC certificate that does not have a matched …OperationalNN
108The Kerberos client could not send a Kerberos proxy request.OperationalNN
109The Kerberos client could not find a suitable credential to use with the …OperationalNN
200The Kerberos client could not locate a domain controller for domain …OperationalYN
201Attempt to use Kerberos unconstrained delegation failed.OperationalYN
202Attempt to export TGT session key failed.OperationalYN
203When Credential Guard is enabled, Kerberos does not accept PKINIT KDC replies …OperationalNN
204Kerberos does not accept PKINIT KDC replies using public key encryption.OperationalNN
205The KDC used a hash algorithm for the PKINIT protocol that is being audited: …OperationalNN
206The Kerberos client used a hash algorithm for the PKINIT protocol that is being …OperationalNN
207The KDC used a hash algorithm for the PKINIT protocol that is not supported on …OperationalNN
208The Kerberos client and KDC could not agree on a policy compliant hash algorithm …OperationalNN
209The Kerberos client has an invalid hash algorithm configuration for PKINIT.OperationalNN
300The Kerberos client discovered domain controller DomainController for the domain …OperationalNN
301The Kerberos client used credentials from the Credential Manager for the target: …OperationalNN
302The Kerberos client was bound to domain controller DesiredFlags for the domain …OperationalNN
303The Kerberos client updated passwords for the group managed service account.OperationalNN
304The Kerberos client used the DES algorithm to encrypt data.OperationalNN
305Export of TGT attempted through call package.OperationalNN
306Export of supplemental credentials attempted.OperationalNN
307The Kerberos client has discovered a DMSA migration.OperationalNN
308Adding machine to the Principals Allowed Managed Password attribute of a DMSA.OperationalNN
309Fetching keys for a DMSA using the machine account.OperationalNN
310Machine password migrated from LSA to VBS Enforcement Mode.OperationalNN
311Machine Identity Isolation is currently in enforcement mode.OperationalNN
312Machine password change failed.OperationalNN
65541An error occurred while retrieving a digital certificate from the inserted smart …OperationalYN
65542An error occurred in while attempting to verify the inserted smart card: Error.OperationalNN
65543An error occurred while signing a message using the inserted smart card: Error.OperationalNN
65544An error occurred while verifying a signed message using the inserted smart …OperationalNN
65545An error occurred while verifying the digital certificate retrieved from the …OperationalNN
65546An error occurred while encrypting a message using the inserted smart card: …OperationalNN
65547An error occurred while decrypting a message using the inserted smart card: …OperationalNN
65548An error occurred while building a certificate context: Error.OperationalNN
65550An error occurred while signing a message: Error.OperationalNN
65551An error occurred while verifying a signed message: Error.OperationalNN
65552An error occurred while encrypting a message: Error.OperationalNN
65553An error occurred while decrypting a message: Error.OperationalNN
65554An error occurred while retrieving some provider parameter: Error.OperationalNN
65555An error occurred while generating a random number: Error.OperationalNN
1073741828The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server Server.OperationalYN
1073741829The Kerberos client received a KRB_AP_ERR_TKT_NYV error from the server Server.OperationalYN
2147483651A Kerberos error message was received.OperationalYN
2147483654The Kerberos SSPI package generated an output token of size NeededSize bytes, …OperationalNN
2147483658The Kerberos subsystem currently cannot retrieve tickets from your domain …OperationalNN
2147483660While using your smart card over a VPN connection, the Kerberos subsystem …OperationalNN
2147483661The smart card PIN stored in Credential Manager is missing or invalid.OperationalNN
2147483662The password stored in Credential Manager is invalid.OperationalNN
2147483663The Kerberos SSPI package generated an output token of size NeededSize bytes, …OperationalNN
2147483666The delegated TGT for the user has expired.OperationalNN
2147483667The KDC certificate for the domain controller does not contain the KDC Extended …OperationalNN
2147483668The KDC certificate for the domain controller does not have the DNS name of …OperationalNN
2147483669During Kerberos Network Ticket Logon, the service ticket for Account .OperationalNN
2147483670During Kerberos Network Ticket Logon, the service ticket for Account .OperationalNN
2147483671During Kerberos Network Ticket Logon, the service ticket for Account .OperationalNN
3221225479The digitally signed Privilege Attribute Certificate (PAC) that contains the …OperationalNN
3221225480The domain controller rejected the client certificate of user Message, used for …OperationalNN
3221225481The client has failed to validate the domain controller certificate for Message.OperationalNN
3221225483The Distinguished Name in the subject field of your smart card logon certificate …OperationalNN
3221225488The Kerberos SSPI package failed to find the smart card certificate in the …OperationalNN
3221225489The Kerberos SSPI package failed to locate the forest or domain Forest to …OperationalNN

Event ID 3: A Kerberos error message was received:

#
Channel
Operational

Fields #

NameDescription
LogonSession UnicodeString
ClientTime UnicodeString
ServerTime UnicodeString
ErrorCode UnicodeString
ErrorMessage UnicodeString
ExtendedError UnicodeString
ClientRealm UnicodeString
ClientName UnicodeString
ServerRealm UnicodeString
ServerName UnicodeString
TargetName UnicodeString
ErrorText UnicodeString
File UnicodeString
Line UnicodeString
__binLength UInt32
binary Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-Kerberos",
    "event_id": 3,
    "level": "Error",
    "task": null,
    "opcode": null,
    "time_created": "2026-03-13T23:09:23.8825311+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "System"
  },
  "event_data": {
    "ServerTime": "23:9:23.0000 3/13/2026 Z",
    "ErrorText": null,
    "ServerRealm": "LUDUS.DOMAIN",
    "Line": "e00",
    "TargetName": "krbtgt/LUDUS.DOMAIN@LUDUS.DOMAIN",
    "ServerName": "krbtgt/LUDUS.DOMAIN",
    "ErrorCode": "0x19",
    "File": "onecore\\ds\\security\\protocols\\kerberos\\client2\\logonapi.cxx",
    "ClientRealm": null,
    "ClientTime": null,
    "ErrorMessage": "KDC_ERR_PREAUTH_REQUIRED",
    "LogonSession": "LUDUS.DOMAIN\\domainadmin",
    "ExtendedError": null,
    "ClientName": null
  }
}

Event ID 3: A Kerberos error message was received:

#
Channel
System
Level
Error

Fields #

NameDescription
LogonSession
ClientTime
ServerTime
ErrorCode
ErrorMessage
ExtendedError
ClientRealm
ClientName
ServerRealm
ServerName
TargetName
ErrorText
File
Line
__binLength
binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-Kerberos",
    "guid": "{98E6CFCB-EE0A-41E0-A57B-622D4E1B30B1}",
    "event_source_name": "Kerberos",
    "event_id": 3,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-03-13T23:04:02.620676+00:00",
    "event_record_id": 12251,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "System",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "LogonSession": "LUDUS.DOMAIN\\domainadmin",
    "ClientTime": "",
    "ServerTime": "23:4:2.0000 3/13/2026 Z",
    "ErrorCode": "0x19",
    "ErrorMessage": "KDC_ERR_PREAUTH_REQUIRED",
    "ExtendedError": "",
    "ClientRealm": "",
    "ClientName": "",
    "ServerRealm": "ludus",
    "ServerName": "krbtgt/ludus",
    "TargetName": "krbtgt/ludus@ludus",
    "ErrorText": "",
    "File": "onecore\\ds\\security\\protocols\\kerberos\\client2\\logonapi.cxx",
    "Line": "e00",
    "Binary": "30353012A103020113A20B040930073005A0030201173009A103020102A20204003009A103020110A20204003009A10302010FA2020400"
  },
  "message": ""
}

Example keys not documented in the fields table: Binary

Event ID 4: The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server

#
Channel
Operational

Fields #

NameDescription
Server UnicodeString
TargetRealm UnicodeString
Targetname UnicodeString
ClientRealm UnicodeString
__binLength UInt32
binary Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-Kerberos",
    "event_id": 4,
    "level": "Error",
    "task": null,
    "opcode": null,
    "time_created": "2026-03-17T18:20:50.9202849+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "System"
  },
  "event_data": {
    "TargetRealm": "LUDUS.DOMAIN",
    "Targetname": "rpc/JD-DC01-2022",
    "Server": "domainadmin",
    "ClientRealm": "LUDUS.DOMAIN"
  }
}

Event ID 4: The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server

#
Channel
System
Level
Error

Fields #

NameDescription
Server
TargetRealm
Targetname
ClientRealm
__binLength
binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-Kerberos",
    "guid": "{98E6CFCB-EE0A-41E0-A57B-622D4E1B30B1}",
    "event_source_name": "Kerberos",
    "event_id": 4,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-03-14T20:59:54.579371+00:00",
    "event_record_id": 12914,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "System",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Server": "domainadmin",
    "TargetRealm": "LUDUS.DOMAIN",
    "Targetname": "rpc/LAB-DC01",
    "ClientRealm": "LUDUS.DOMAIN",
    "Binary": ""
  },
  "message": ""
}

Example keys not documented in the fields table: Binary

Event ID 5: The Kerberos client received a KRB_AP_ERR_TKT_NYV error from the server

#
Channel
Operational
Level
2

Fields #

NameDescription
Error UnicodeString
__binLength UInt32
binary Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-Kerberos",
    "event_id": 5,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-04-20T19:20:46.7822967+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "System"
  },
  "event_data": {
    "Server": "desktop-ff3n5xk$",
    "KDCRealm": "LUDUS.DOMAIN"
  }
}

Example keys not documented in the fields table: KDCRealm, Server

Event ID 5: The Kerberos client received a KRB_AP_ERR_TKT_NYV error from the server

#
Channel
System
Level
Error

Fields #

NameDescription
Error
__binLength
binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-Kerberos",
    "guid": "{98E6CFCB-EE0A-41E0-A57B-622D4E1B30B1}",
    "event_source_name": "Kerberos",
    "event_id": 5,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-02-10T01:12:10.274438+00:00",
    "event_record_id": 984,
    "correlation": {},
    "execution": {
      "process_id": 240,
      "thread_id": 0
    },
    "channel": "System",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Server": "jd-win11-22h2-1$",
    "KDCRealm": "LUDUS.DOMAIN",
    "Binary": ""
  },
  "message": ""
}

Example keys not documented in the fields table: Binary, KDCRealm, Server

Event ID 6: The Kerberos SSPI package generated an output token of size Error bytes, which was too large to fit in the token buffer of size __binLength bytes, provided by process id

#
Channel
Operational

Fields #

NameDescription
Error UnicodeString
__binLength UInt32
binary Binary

Event ID 7: The digitally signed Privilege Attribute Certificate (PAC) that contains the authorization information for client Error in realm __binLength could not be validated

#
Channel
Operational

Fields #

NameDescription
Error UnicodeString
__binLength UInt32
binary Binary

Event ID 8: The domain controller rejected the client certificate of user __binLength, used for smart card logon

#
Channel
Operational

Fields #

NameDescription
Error UnicodeString
__binLength UInt32
binary Binary

Event ID 9: The client has failed to validate the domain controller certificate for

#
Channel
Operational

Fields #

NameDescription
Error UnicodeString
__binLength UInt32
binary Binary

Event ID 10: The Kerberos subsystem currently cannot retrieve tickets from your domain controller using the UDP network protocol

#
Channel
Operational

Fields #

NameDescription
Error UnicodeString
__binLength UInt32
binary Binary

Event ID 11: The Distinguished Name in the subject field of your smart card logon certificate does not contain enough information to identify the appropriate domain on an non-domain joined computer

#
Channel
Operational

Fields #

NameDescription
Error UnicodeString
__binLength UInt32
binary Binary

Event ID 12: While using your smart card over a VPN connection, the Kerberos subsystem encountered an error

#
Channel
Operational

Fields #

NameDescription
Error UnicodeString
__binLength UInt32
binary Binary

Event ID 13: An error occurred while initializing the smart card logon library: Error.

#
Channel
Operational

Message #

An error occurred while initializing the smart card logon library: %1

Fields #

NameDescription
Error UnicodeString
__binLength UInt32
binary Binary

Event ID 14: The password stored in Credential Manager is invalid

#
Channel
Operational

Fields #

NameDescription
Error UnicodeString
__binLength UInt32
binary Binary

Event ID 15: The Kerberos SSPI package generated an output token of size Error bytes, which was too large to fit in the token buffer of size __binLength bytes, provided by process id

#
Channel
Operational

Fields #

NameDescription
Error UnicodeString
__binLength UInt32
binary Binary

Event ID 16: The Kerberos SSPI package failed to find the smart card certificate in the certificate store

#
Channel
Operational

Fields #

NameDescription
Error UnicodeString
__binLength UInt32
binary Binary

Event ID 17: The Kerberos SSPI package failed to locate the forest or domain Error to search

#
Channel
Operational

Fields #

NameDescription
Error UnicodeString
__binLength UInt32
binary Binary

Event ID 18: The delegated TGT for the user (__binLength) has expired

#
Channel
Operational

Fields #

NameDescription
Error UnicodeString
__binLength UInt32
binary Binary

Event ID 19: The KDC certificate for the domain controller does not contain the KDC Extended Key Usage (EKU): 1

#
Channel
Operational

Fields #

NameDescription
Error UnicodeString
__binLength UInt32
binary Binary

Event ID 20: The KDC certificate for the domain controller does not have the DNS name of domain DomainName in the Subject Alternative Name (SAN) attribute: Error Code

#
Channel
Operational

Fields #

NameDescription
DomainName UnicodeString
ErrorCode UnicodeString

Event ID 27: Kerberos client event 27 (manifest stub).

#
Channel
Operational

Event ID 100: The service principal name (SPN) SPN is not registered, which caused Kerberos authentication to fail: ErrorCode.

#
Channel
Operational
Also via
realtime ETW trace
Level
Error

Description

The service principal name (SPN) SPN is not registered, which caused Kerberos authentication to fail: ErrorCode. Use the setspn command-line tool to register the SPN.

Message #

The service principal name (SPN) %1 is not registered, which caused Kerberos authentication to fail: %2. Use the setspn command-line tool to register the SPN.

Fields #

NameDescription
SPN UnicodeString
ErrorCode UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-Kerberos",
    "guid": "98E6CFCB-EE0A-41E0-A57B-622D4E1B30B1",
    "event_source_name": "",
    "event_id": 100,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:17:40.189125+00:00",
    "event_record_id": 1,
    "correlation": {},
    "execution": {
      "process_id": 968,
      "thread_id": 8880
    },
    "channel": "Microsoft-Windows-Kerberos/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "SPN": "HTTP/nonexistent.domain.local@LUDUS.DOMAIN",
    "ErrorCode": 7
  },
  "message": ""
}

Event ID 101: The service principal name (SPN) SPN is registered on multiple accounts which caused Kerberos authentication to fail: ErrorCode.

#
Channel
Operational

Description

The service principal name (SPN) SPN is registered on multiple accounts which caused Kerberos authentication to fail: ErrorCode. Use the setspn command-line tool to identify the accounts and remove the duplicate registrations.

Message #

The service principal name (SPN) %1 is registered on multiple accounts which caused Kerberos authentication to fail: %2. Use the setspn command-line tool to identify the accounts and remove the duplicate registrations.

Fields #

NameDescription
SPN UnicodeString
ErrorCode UInt32

Event ID 102: Trust validation of the certificate for the Kerberos Key Distribution Center (KDC) DomainController failed: ErrorCode.

#
Channel
Operational

Description

Trust validation of the certificate for the Kerberos Key Distribution Center (KDC) DomainController failed: ErrorCode. Use the CAPI2 diagnostic traces to identify the reason for the validation failure.

Message #

Trust validation of the certificate for the Kerberos Key Distribution Center (KDC) %1 failed: %2. Use the CAPI2 diagnostic traces to identify the reason for the validation failure.

Fields #

NameDescription
DomainController UnicodeString
ErrorCode UInt32

Event ID 103: Trust validation of the client certificate for ClientUpn failed: ErrorCode on KDC.

#
Channel
Operational

Description

Trust validation of the client certificate for ClientUpn failed: ErrorCode on KDC. Use the CAPI2 diagnostic traces to identify the reason for the validation failure.

Message #

Trust validation of the client certificate for %1 failed: %2 on KDC. Use the CAPI2 diagnostic traces to identify the reason for the validation failure.

Fields #

NameDescription
ClientUpn UnicodeString
ErrorCode UInt32

Event ID 104: The Kerberos Key Distribution Center (KDC) for the domain TargetDomain does not have a certificate installed or does not support logon using certificates: ErrorCode.

#
Channel
Operational

Message #

The Kerberos Key Distribution Center (KDC) for the domain %1 does not have a certificate installed or does not support logon using certificates: %2

Fields #

NameDescription
TargetDomain UnicodeString
ErrorCode UInt32

Event ID 105: The Kerberos client could not retrieve passwords for the group managed service account.

#
Channel
Operational

Message #

The Kerberos client could not retrieve passwords for the group managed service account.

LogonId: %1:%2
DomainName: %3
UserName: %4
Refresh: %5
Current File Time: %6
Error Code: %7

Fields #

NameDescription
LuidHighPart UInt32
LuidLowPart UInt32
DomainName UnicodeString
UserName UnicodeString
Refresh Boolean
CurrentFileTime UnicodeString
ErrorCode UInt32

Event ID 106: The Kerberos client received a KDC certificate that does not have KDC EKU (not based on Kerberos Authentication Template).

#
Channel
Operational

Message #

The Kerberos client received a KDC certificate that does not have KDC EKU (not based on Kerberos Authentication Template).

Error Code: %1

Fields #

NameDescription
ErrorCode UInt32

Event ID 107: The Kerberos client received a KDC certificate that does not have a matched domain name.

#
Channel
Operational

Message #

The Kerberos client received a KDC certificate that does not have a matched domain name.

Expected Domain Name: %1
Error Code: %2

Fields #

NameDescription
ExpectedDomainName UnicodeString
ErrorCode UInt32

Event ID 108: The Kerberos client could not send a Kerberos proxy request.

#
Channel
Operational

Message #

The Kerberos client could not send a Kerberos proxy request.

ProxyServer:
  ServerName: %1
  ServerPort: %2
  ServerVdir: %3
Error Code: %4
Status Code: %5

Fields #

NameDescription
ServerName UnicodeString[ProxyServer] ServerName.
ServerPort UInt32[ProxyServer] ServerPort.
ServerVdir UnicodeString[ProxyServer] ServerVdir.
ErrorCode UInt32
Status UInt32NTSTATUS reference

Event ID 109: The Kerberos client could not find a suitable credential to use with the authentication proxy.

#
Channel
Operational

Message #

The Kerberos client could not find a suitable credential to use with the authentication proxy:

AuthProxy:
  Proxy: %1
  ProxyBypass: %2
  Epoch: %3
  Supported Schemes: %4
  First Scheme: %5
Digest Credential:
  Initialized: %6
  DomainAndUserName: %7
  Epoch: %8
Basic Credential:
  Initialized: %9
  DomainAndUserName: %10
  Epoch: %11

Fields #

NameDescription
Proxy UnicodeString[AuthProxy] Proxy.
ProxyBypass UnicodeString[AuthProxy] ProxyBypass.
ProxyEpoch UInt32
SupportedSchemes UInt32
FirstScheme UInt32
DigestCredInitialized Boolean
DigestCredDomainAndUserName UnicodeString
DigestCredEpoch UInt32
BasicCredInitialized Boolean
BasicCredDomainAndUserName UnicodeString
BasicCredEpoch UInt32

Event ID 200: The Kerberos client could not locate a domain controller for domain TargetDomain: ErrorCode.

#
Channel
Operational
Level
Warning

Description

The Kerberos client could not locate a domain controller for domain TargetDomain: ErrorCode. Kerberos authentication requires communicating with a domain controller.

Message #

The Kerberos client could not locate a domain controller for domain %1: %2. Kerberos authentication requires communicating with a domain controller.

Fields #

NameDescription
TargetDomain UnicodeString
ErrorCode UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-Kerberos",
    "guid": "98E6CFCB-EE0A-41E0-A57B-622D4E1B30B1",
    "event_source_name": "",
    "event_id": 200,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:24:08.199756+00:00",
    "event_record_id": 2,
    "correlation": {},
    "execution": {
      "process_id": 968,
      "thread_id": 10948
    },
    "channel": "Microsoft-Windows-Kerberos/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "TargetDomain": "LUDUS.DOMAIN",
    "ErrorCode": 3221225572
  },
  "message": ""
}

Event ID 201: Attempt to use Kerberos unconstrained delegation failed.

#
Channel
Operational
Level
Warning

Message #

Attempt to use Kerberos unconstrained delegation failed.

Target server: %1
Supplied user: %2
Supplied domain: %3
PID of client process: %4
Name of client process: %5
LUID of client process: %6
User identity of client process: %7
Domain name of user identity of client process: %8
Mechanism OID: %9

Kerberos unconstrained delegation is not allowed for this user. For more information, see https://go.microsoft.com/fwlink/?linkid=856824.

Fields #

NameDescription
TargetName UnicodeString
UserName UnicodeString
DomainName UnicodeString
CallerPID UInt32
ProcessName UnicodeString
ClientLUID HexInt64
ClientUserName UnicodeString
ClientDomainName UnicodeString
MechanismOID UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-Kerberos",
    "guid": "98E6CFCB-EE0A-41E0-A57B-622D4E1B30B1",
    "event_source_name": "",
    "event_id": 201,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:05:05.241896+00:00",
    "event_record_id": 1,
    "correlation": {
      "ActivityID": "A5B814C5-B324-0003-DC14-B8A524B3DC01"
    },
    "execution": {
      "process_id": 984,
      "thread_id": 1072
    },
    "channel": "Microsoft-Windows-Kerberos/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "TargetName": "cifs/LAB-DC01.ludus.domain",
    "UserName": "NULL",
    "DomainName": "NULL",
    "CallerPID": 4,
    "ProcessName": "",
    "ClientLUID": "0x3e7",
    "ClientUserName": "LAB-WIN11$",
    "ClientDomainName": "ludus",
    "MechanismOID": "1.2.840.48018.1.2.2"
  },
  "message": ""
}

Event ID 202: Attempt to export TGT session key failed.

#
Channel
Operational
Level
Warning

Message #

Attempt to export TGT session key failed.

Target server: %1
Supplied user: %2
Supplied domain: %3
PID of client process: %4
Name of client process: %5
LUID of client process: %6
User identity of client process: %7
Domain name of user identity of client process: %8
Mechanism OID: %9

This device does not allow exporting TGT session keys. For more information, see https://go.microsoft.com/fwlink/?linkid=856825.

Fields #

NameDescription
TargetName UnicodeString
UserName UnicodeString
DomainName UnicodeString
CallerPID UInt32
ProcessName UnicodeString
ClientLUID HexInt64
ClientUserName UnicodeString
ClientDomainName UnicodeString
MechanismOID UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-Kerberos",
    "guid": "98E6CFCB-EE0A-41E0-A57B-622D4E1B30B1",
    "event_source_name": "",
    "event_id": 202,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-15T05:16:41.040416+00:00",
    "event_record_id": 44,
    "correlation": {},
    "execution": {
      "process_id": 940,
      "thread_id": 2768
    },
    "channel": "Microsoft-Windows-Kerberos/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "TargetName": "krbtgt/LUDUS.DOMAIN",
    "UserName": "domainadmin",
    "DomainName": "NULL",
    "CallerPID": 3788,
    "ProcessName": "C:\\Windows\\System32\\klist.exe",
    "ClientLUID": "0x4aa840e",
    "ClientUserName": "domainadmin",
    "ClientDomainName": "ludus",
    "MechanismOID": "NULL"
  },
  "message": ""
}

Event ID 203: When Credential Guard is enabled, Kerberos does not accept PKINIT KDC replies using public key encryption to ensure Kerberos tickets cannot be expo...

#
Channel
Operational

Description

When Credential Guard is enabled, Kerberos does not accept PKINIT KDC replies using public key encryption to ensure Kerberos tickets cannot be exported from the device. For more information, see https://go.microsoft.com/fwlink/?linkid=856823.

Message #

When Credential Guard is enabled, Kerberos does not accept PKINIT KDC replies using public key encryption to ensure Kerberos tickets cannot be exported from the device. For more information, see https://go.microsoft.com/fwlink/?linkid=856823.

Event ID 204: Kerberos does not accept PKINIT KDC replies using public key encryption.

#
Channel
Operational

Event ID 205: The KDC used a hash algorithm for the PKINIT protocol that is being audited: Algorithm.

#
Channel
Operational

Message #

The KDC used a hash algorithm for the PKINIT protocol that is being audited: %1.

Fields #

NameDescription
Algorithm UnicodeString

Event ID 206: The Kerberos client used a hash algorithm for the PKINIT protocol that is being audited: Algorithm.

#
Channel
Operational

Message #

The Kerberos client used a hash algorithm for the PKINIT protocol that is being audited: %1.

Fields #

NameDescription
Algorithm UnicodeString

Event ID 207: The KDC used a hash algorithm for the PKINIT protocol that is not supported on the client: Algorithm.

#
Channel
Operational

Message #

The KDC used a hash algorithm for the PKINIT protocol that is not supported on the client: %1.

Fields #

NameDescription
Algorithm UnicodeString

Event ID 208: The Kerberos client and KDC could not agree on a policy compliant hash algorithm for PKINIT.

#
Channel
Operational

Message #

The Kerberos client and KDC could not agree on a policy compliant hash algorithm for PKINIT. 

Client supported algorithms: { %1 }
KDC supported algorithms: { %2 }

Fields #

NameDescription
ClientAlgorithms UnicodeString
KdcAlgorithms UnicodeString

Event ID 209: The Kerberos client has an invalid hash algorithm configuration for PKINIT.

#
Channel
Operational

Description

The Kerberos client has an invalid hash algorithm configuration for PKINIT. This might result in PKINIT failures.

Message #

The Kerberos client has an invalid hash algorithm configuration for PKINIT. This might result in PKINIT failures.

Event ID 300: The Kerberos client discovered domain controller DomainController for the domain TargetDomain.

#
Channel
Operational

Message #

The Kerberos client discovered domain controller %1 for the domain %2.

Fields #

NameDescription
DomainController UnicodeString
TargetDomain UnicodeString

Event ID 301: The Kerberos client used credentials from the Credential Manager for the target: 'Target'.

#
Channel
Operational

Message #

The Kerberos client used credentials from the Credential Manager for the target: '%1'.

Fields #

NameDescription
Target UnicodeString

Event ID 302: The Kerberos client was bound to domain controller DesiredFlags for the domain CacheFlags but could not access this domain controller at the time.

#
Channel
Operational

Message #

The Kerberos client was bound to domain controller %1 for the domain %2 but could not access this domain controller at the time.

    DesiredFlags: %3
    CacheFlags: %4
    ErrorCode: %5

Fields #

NameDescription
DomainController UnicodeString
TargetDomain UnicodeString
DesiredFlags UInt32
CacheFlags UInt32
ErrorCode UInt32DesiredFlags.

Event ID 303: The Kerberos client updated passwords for the group managed service account.

#
Channel
Operational

Message #

The Kerberos client updated passwords for the group managed service account.

LogonId: %1:%2
DomainName: %3
UserName: %4
Update Current Passwords: %5
Update Old Passwords: %6
Refresh: %7
Previous File Time: %8
Current File Time: %9

Fields #

NameDescription
LuidHighPart UInt32
LuidLowPart UInt32
DomainName UnicodeString
UserName UnicodeString
UpdateCurrent Boolean
UpdateOld Boolean
Refresh Boolean
LastFileTime UnicodeString
CurrentFileTime UnicodeString

Event ID 304: The Kerberos client used the DES algorithm to encrypt data.

#
Channel
Operational

Description

The Kerberos client used the DES algorithm to encrypt data. This is unsupported with Credential Guard.

Message #

The Kerberos client used the DES algorithm to encrypt data. This is unsupported with Credential Guard.

Event ID 305: Export of TGT attempted through call package.

#
Channel
Operational

Description

Export of TGT attempted through call package. This is unsupported with Credential Guard.

Message #

Export of TGT attempted through call package. This is unsupported with Credential Guard.

Process Name:%1
Service Host Tag:%2

Fields #

NameDescription
ProcessName UnicodeString
SvchostTag UnicodeString

Event ID 306: Export of supplemental credentials attempted.

#
Channel
Operational

Description

Export of supplemental credentials attempted. This is unsupported with Credential Guard.

Message #

Export of supplemental credentials attempted. This is unsupported with Credential Guard.

Process Name:%1
Service Host Tag:%2

Fields #

NameDescription
ProcessName UnicodeString
SvchostTag UnicodeString

Event ID 307: The Kerberos client has discovered a DMSA migration.

#
Channel
Operational

Message #

The Kerberos client has discovered a DMSA migration
Old Account Name: %1
New Account Name: %2
Domain Name: %3
Status: %4
Migration Complete: %5

Fields #

NameDescription
OldAccount UnicodeString
NewAccount UnicodeString
DomainName UnicodeString
Status UInt32NTSTATUS reference
MigrationComplete Boolean

Event ID 308: Adding machine to the Principals Allowed Managed Password attribute of a DMSA.

#
Channel
Operational

Message #

Adding machine to the Principals Allowed Managed Password attribute of a DMSA
DC Used: %1
DMSA Distinguished Name: %2
Linked Account: %3
Domain Name: %4
Previously Authorized: %5
Status: %6

Fields #

NameDescription
DC UnicodeString
DN UnicodeString
Account UnicodeString
Domain UnicodeString
PreviouslyAuthorized Boolean
Status UInt32NTSTATUS reference

Event ID 309: Fetching keys for a DMSA using the machine account.

#
Channel
Operational

Message #

Fetching keys for a DMSA using the machine account
KDC Used: %1
Domain Name: %2
Account Name: %3
Fetch Time: %4
Expiration Time: %5
Keys Updated: %6
Ntlm Updated: %7
Status: %8

Fields #

NameDescription
KDC UnicodeString
Domain UnicodeString
Account UnicodeString
Fetch UnicodeString
Expiration UnicodeString
KeyUpdate Boolean
NtlmUpdate Boolean
Status UInt32NTSTATUS reference

Event ID 310: Machine password migrated from LSA to VBS Enforcement Mode.

#
Channel
Operational

Description

Machine password migrated from LSA to VBS.

Message #

Machine password migrated from LSA to VBS
Enforcement Mode: %1

Fields #

NameDescription
EnforcementMode UInt32

Event ID 311: Machine Identity Isolation is currently in enforcement mode.

#
Channel
Operational

Description

Machine Identity Isolation is currently in enforcement mode. To go back to disabled/audit mode, you must manually unjoin and rejoin the domain.

Message #

Machine Identity Isolation is currently in enforcement mode. To go back to disabled/audit mode, you must manually unjoin and rejoin the domain.

Event ID 312: Machine password change failed.

#
Channel
Operational

Message #

Machine password change failed
Status: %1
Migration Needed: %2
Policy: %3
Exit Reason: %4

Fields #

NameDescription
Status UInt32NTSTATUS reference
MigrationNeeded Boolean
EnforcementMode UInt32
ExitReason UInt32

Event ID 65541: An error occurred while retrieving a digital certificate from the inserted smart card.

#
Channel
Operational

Description

An error occurred while retrieving a digital certificate from the inserted smart card. Error.

Message #

An error occurred while retrieving a digital certificate from the inserted smart card. %1

Fields #

NameDescription
Error UnicodeString
binary Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-Kerberos",
    "event_id": 5,
    "level": "Error",
    "task": null,
    "opcode": null,
    "time_created": "2026-03-15T23:59:20.7606759+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "System"
  },
  "event_data": {
    "Server": "jd-win11-22h2-1$",
    "KDCRealm": "LUDUS.DOMAIN"
  }
}

Example keys not documented in the fields table: KDCRealm, Server

Event ID 65542: An error occurred in while attempting to verify the inserted smart card: Error.

#
Channel
Operational

Message #

An error occurred in while attempting to verify the inserted smart card: %1

Fields #

NameDescription
Error UnicodeString
binary Binary

Event ID 65543: An error occurred while signing a message using the inserted smart card: Error.

#
Channel
Operational

Message #

An error occurred while signing a message using the inserted smart card: %1

Fields #

NameDescription
Error UnicodeString
binary Binary

Event ID 65544: An error occurred while verifying a signed message using the inserted smart card: Error.

#
Channel
Operational

Message #

An error occurred while verifying a signed message using the inserted smart card: %1

Fields #

NameDescription
Error UnicodeString
binary Binary

Event ID 65545: An error occurred while verifying the digital certificate retrieved from the inserted smart card: Error.

#
Channel
Operational

Message #

An error occurred while verifying the digital certificate retrieved from the inserted smart card: %1

Fields #

NameDescription
Error UnicodeString
binary Binary

Event ID 65546: An error occurred while encrypting a message using the inserted smart card: Error.

#
Channel
Operational

Message #

An error occurred while encrypting a message using the inserted smart card: %1

Fields #

NameDescription
Error UnicodeString
binary Binary

Event ID 65547: An error occurred while decrypting a message using the inserted smart card: Error.

#
Channel
Operational

Message #

An error occurred while decrypting a message using the inserted smart card: %1

Fields #

NameDescription
Error UnicodeString
binary Binary

Event ID 65548: An error occurred while building a certificate context: Error.

#
Channel
Operational

Message #

An error occurred while building a certificate context: %1

Fields #

NameDescription
Error UnicodeString
binary Binary

Event ID 65550: An error occurred while signing a message: Error.

#
Channel
Operational

Message #

An error occurred while signing a message: %1

Fields #

NameDescription
Error UnicodeString
binary Binary

Event ID 65551: An error occurred while verifying a signed message: Error.

#
Channel
Operational

Message #

An error occurred while verifying a signed message: %1

Fields #

NameDescription
Error UnicodeString
binary Binary

Event ID 65552: An error occurred while encrypting a message: Error.

#
Channel
Operational

Message #

An error occurred while encrypting a message: %1

Fields #

NameDescription
Error UnicodeString
binary Binary

Event ID 65553: An error occurred while decrypting a message: Error.

#
Channel
Operational

Message #

An error occurred while decrypting a message: %1

Fields #

NameDescription
Error UnicodeString
binary Binary

Event ID 65554: An error occurred while retrieving some provider parameter: Error.

#
Channel
Operational

Message #

An error occurred while retrieving some provider parameter: %1

Fields #

NameDescription
Error UnicodeString
binary Binary

Event ID 65555: An error occurred while generating a random number: Error.

#
Channel
Operational

Message #

An error occurred while generating a random number: %1

Fields #

NameDescription
Error UnicodeString
binary Binary

Event ID 1073741828: The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server Server.

#
Channel
Operational

Description

The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server Server. The target name used was Targetname. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Ensure that the target SPN is only registered on the account used by the server. This error can also happen if the target service account password is different than what is configured on the Kerberos Key Distribution Center for that target service. Ensure that the service on the server and the KDC are both configured to use the same password. If the server name is not fully qualified, and the target domain (TargetRealm) is different from the client domain (ClientRealm), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server.

Message #

The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server %1. The target name used was %3. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Ensure that the target SPN is only registered on the account used by the server. This error can also happen if the target service account password is different than what is configured on the Kerberos Key Distribution Center for that target service. Ensure that the service on the server and the KDC are both configured to use the same password. If the server name is not fully qualified, and the target domain (%2) is different from the client domain (%4), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server.

Fields #

NameDescription
Server UnicodeString
TargetRealm UnicodeString
Targetname UnicodeString
ClientRealm UnicodeString
binary Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-Kerberos",
    "event_id": 4,
    "level": "Error",
    "task": null,
    "opcode": null,
    "time_created": "2026-03-17T18:20:50.9202849+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "System"
  },
  "event_data": {
    "TargetRealm": "LUDUS.DOMAIN",
    "Targetname": "rpc/JD-DC01-2022",
    "Server": "domainadmin",
    "ClientRealm": "LUDUS.DOMAIN"
  }
}

Event ID 1073741829: The Kerberos client received a KRB_AP_ERR_TKT_NYV error from the server Server.

#
Channel
Operational

Description

The Kerberos client received a KRB_AP_ERR_TKT_NYV error from the server Server. This indicates that the ticket presented to that server is not yet valid (due to a discrepancy between ticket and server time. Contact your system administrator to make sure the client and server times are synchronized, and that the time for the Key Distribution Center Service (KDC) in realm KDCRealm is synchronized with the KDC in the client realm.

Message #

The Kerberos client received a KRB_AP_ERR_TKT_NYV error from the server %1. This indicates that the ticket presented to that server is not yet valid (due to a discrepancy between ticket and server time. Contact your system administrator to make sure the client and server times are synchronized, and that the time for the Key Distribution Center Service (KDC) in realm %2 is synchronized with the KDC in the client realm.

Fields #

NameDescription
Server UnicodeString
KDCRealm UnicodeString
binary Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-Kerberos",
    "event_id": 5,
    "level": "Error",
    "task": null,
    "opcode": null,
    "time_created": "2026-03-15T23:59:20.7606759+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "System"
  },
  "event_data": {
    "Server": "jd-win11-22h2-1$",
    "KDCRealm": "LUDUS.DOMAIN"
  }
}

Event ID 2147483651: A Kerberos error message was received.

#
Channel
Operational

Message #

A Kerberos error message was received:
 on logon session %1
 Client Time: %2
 Server Time: %3
 Error Code: %4 %5
 Extended Error: %6
 Client Realm: %7
 Client Name: %8
 Server Realm: %9
 Server Name: %10
 Target Name: %11
 Error Text: %12
 File: %13
 Line: %14
 Error Data is in record data.

Fields #

NameDescription
Client_Time
Server_Time[A Kerberos error message was received] Client Time.
Error_Code[A Kerberos error message was received] Server Time.
Extended_Error[A Kerberos error message was received] Error Code.
Client_Realm
Client_Name[A Kerberos error message was received] Extended Error.
Server_Realm[A Kerberos error message was received] Client Realm.
Server_Name[A Kerberos error message was received] Client Name.
Target_Name[A Kerberos error message was received] Server Realm.
Error_Text[A Kerberos error message was received] Server Name.
File UnicodeString[A Kerberos error message was received] Target Name.
Line UnicodeString[A Kerberos error message was received] Error Text.
LogonSession UnicodeString
ClientTime UnicodeString
ServerTime UnicodeString
ErrorCode UnicodeString
ErrorMessage UnicodeString
ExtendedError UnicodeString
ClientRealm UnicodeString
ClientName UnicodeString
ServerRealm UnicodeString
ServerName UnicodeString
TargetName UnicodeString
ErrorText UnicodeString
binary Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-Kerberos",
    "event_id": 3,
    "level": "Error",
    "task": null,
    "opcode": null,
    "time_created": "2026-03-13T23:09:23.8825311+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "System"
  },
  "event_data": {
    "ServerTime": "23:9:23.0000 3/13/2026 Z",
    "ErrorText": null,
    "ServerRealm": "LUDUS.DOMAIN",
    "Line": "e00",
    "TargetName": "krbtgt/LUDUS.DOMAIN@LUDUS.DOMAIN",
    "ServerName": "krbtgt/LUDUS.DOMAIN",
    "ErrorCode": "0x19",
    "File": "onecore\\ds\\security\\protocols\\kerberos\\client2\\logonapi.cxx",
    "ClientRealm": null,
    "ClientTime": null,
    "ErrorMessage": "KDC_ERR_PREAUTH_REQUIRED",
    "LogonSession": "LUDUS.DOMAIN\\domainadmin",
    "ExtendedError": null,
    "ClientName": null
  }
}

Event ID 2147483654: The Kerberos SSPI package generated an output token of size NeededSize bytes, which was too large to fit in the token buffer of size ActualSize bytes, provided by ...

#
Channel
Operational

Description

The Kerberos SSPI package generated an output token of size NeededSize bytes, which was too large to fit in the token buffer of size ActualSize bytes, provided by process id ClientProcessID.

Message #

The Kerberos SSPI package generated an output token of size %1 bytes, which was too large to fit in the token buffer of size %2 bytes, provided by process id %3.
 
 The output SSPI token size is probably the result of the user %4 being a member of a large number of groups.
 
 It is recommended to minimize the number of groups a user belongs to. If the problem can not be corrected by reducing the group memberships of this user, contact your system administrator to increase the maximum token size, which is configured on each computer individually using the registry value: HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters\MaxTokenSize.

Fields #

NameDescription
NeededSize UnicodeString
ActualSize UnicodeString
ClientProcessID UnicodeString
ClientName UnicodeString
binary Binary

Event ID 2147483658: The Kerberos subsystem currently cannot retrieve tickets from your domain controller using the UDP network protocol.

#
Channel
Operational

Description

The Kerberos subsystem currently cannot retrieve tickets from your domain controller using the UDP network protocol. This is typically due to network problems. Contact your system administrator.

Message #

The Kerberos subsystem currently cannot retrieve tickets from your domain controller using the UDP network protocol. This is typically due to network problems. Contact your system administrator.

Event ID 2147483660: While using your smart card over a VPN connection, the Kerberos subsystem encountered an error.

#
Channel
Operational

Description

While using your smart card over a VPN connection, the Kerberos subsystem encountered an error. Typically, this indicates the card has been pulled from the card reader during the VPN session. One possible solution is to close the VPN connection, reinsert the card, and establish the connection again.

Message #

While using your smart card over a VPN connection, the Kerberos subsystem encountered an error. Typically, this indicates the card has been pulled from the card reader during the VPN session. One possible solution is to close the VPN connection, reinsert the card, and establish the connection again.

Event ID 2147483661: The smart card PIN stored in Credential Manager is missing or invalid.

#
Channel
Operational

Description

The smart card PIN stored in Credential Manager is missing or invalid. The smart card PIN is stored in memory only for the current interactive logon session, and is deleted if the card is removed from the card reader or when the user logs off. To resolve this error, keep the card in the reader, open Credential Manager in Control Panel, and reenter the PIN for the credential Username.

Message #

The smart card PIN stored in Credential Manager is missing or invalid. The smart card PIN is stored in memory only for the current interactive logon session, and is deleted if the card is removed from the card reader or when the user logs off. To resolve this error, keep the card in the reader, open Credential Manager in Control Panel, and reenter the PIN for the credential %1.

Fields #

NameDescription
Username UnicodeString
binary Binary

Event ID 2147483662: The password stored in Credential Manager is invalid.

#
Channel
Operational

Description

The password stored in Credential Manager is invalid. This might be caused by the logged on user changing the password from this computer or a different computer. To resolve this error, open Credential Manager in Control Panel, and reenter the password for the credential Username.

Message #

The password stored in Credential Manager is invalid. This might be caused by the logged on user changing the password from this computer or a different computer. To resolve this error, open Credential Manager in Control Panel, and reenter the password for the credential %1.

Fields #

NameDescription
Username UnicodeString
binary Binary

Event ID 2147483663: The Kerberos SSPI package generated an output token of size NeededSize bytes, which was too large to fit in the token buffer of size ActualSize bytes, provided by ...

#
Channel
Operational

Description

The Kerberos SSPI package generated an output token of size NeededSize bytes, which was too large to fit in the token buffer of size ActualSize bytes, provided by process id ClientProcessID.

Message #

The Kerberos SSPI package generated an output token of size %1 bytes, which was too large to fit in the token buffer of size %2 bytes, provided by process id %3.
 
 The application needs to be modified to supply a token buffer of size at least %4 bytes.

Fields #

NameDescription
NeededSize UnicodeString
ActualSize UnicodeString
ClientProcessID UnicodeString
RequiredSize UnicodeString
binary Binary

Event ID 2147483666: The delegated TGT for the user has expired.

#
Channel
Operational

Description

The delegated TGT for the user (Server) has expired. A renewal was attempted and failed with error ClientPrincipalName. The server logon session (Client) has stopped delegating the user's credential. For future unconstrained delegation to succeed, the user needs to authenticate again to the server. TGT Details: Client: Server Server: Flags Flags: Start_Time Start Time: End_Time End Time: Renew_Until Renew Until: Luid

Message #

The delegated TGT for the user (%2) has expired. A renewal was attempted and failed with error %8. The server logon session (%1) has stopped delegating the user's credential. For future unconstrained delegation to succeed, the user needs to authenticate again to the server. 

TGT Details:
    Client: %2
    Server: %3
    Flags: %4
    Start Time: %5
    End Time: %6
    Renew Until: %7

Fields #

NameDescription
Client
Server[TGT Details] Client.
Flags[TGT Details] Server.
Start_Time[TGT Details] Flags.
End_Time
Renew_Until
Luid UnicodeString
ClientPrincipalName UnicodeString
ServicePrincipalName UnicodeString
TicketFlags UnicodeString
StartTime UnicodeString
EndTime UnicodeString
RenewUntil UnicodeString
ErrorCode UnicodeString

Event ID 2147483667: The KDC certificate for the domain controller does not contain the KDC Extended Key Usage (EKU): 1.

#
Channel
Operational

Description

The KDC certificate for the domain controller does not contain the KDC Extended Key Usage (EKU): 1.3.6.1.5.2.3.5: Error Code ErrorCode. The domain administrator will need to obtain a certificate with the KDC EKU for the domain controller to resolve this error. When using Windows Server Certificate Services create a certificated based on the Kerberos Authentication Template.

Message #

The KDC certificate for the domain controller does not contain the KDC Extended Key Usage (EKU): 1.3.6.1.5.2.3.5: Error Code %1. The domain administrator will need to obtain a certificate with the KDC EKU for the domain controller to resolve this error. When using Windows Server Certificate Services create a certificated based on the Kerberos Authentication Template.

Fields #

NameDescription
ErrorCode UnicodeString

Event ID 2147483668: The KDC certificate for the domain controller does not have the DNS name of domain DomainName in the Subject Alternative Name (SAN) attribute: Error Code ErrorCode.

#
Channel
Operational

Description

The KDC certificate for the domain controller does not have the DNS name of domain DomainName in the Subject Alternative Name (SAN) attribute: Error Code ErrorCode. The domain administrator will need to obtain a KDC certificate with the DNS domain name in the SAN attribute for the domain controller to resolve this error. When using Windows Server Certificate Services create a certificated based on the Kerberos Authentication Template.

Message #

The KDC certificate for the domain controller does not have the DNS name of domain %1 in the Subject Alternative Name (SAN) attribute: Error Code %2. The domain administrator will need to obtain a KDC certificate with the DNS domain name in the SAN attribute for the domain controller to resolve this error. When using Windows Server Certificate Services create a certificated based on the Kerberos Authentication Template.

Fields #

NameDescription
DomainName UnicodeString
ErrorCode UnicodeString

Event ID 2147483669: During Kerberos Network Ticket Logon, the service ticket for Account .

#
Channel
Operational

Fields #

NameDescription
param1
param2
param3
param4

Event ID 2147483670: During Kerberos Network Ticket Logon, the service ticket for Account .

#
Channel
Operational

Fields #

NameDescription
Reason
ErrorCode

Event ID 2147483671: During Kerberos Network Ticket Logon, the service ticket for Account .

#
Channel
Operational

Fields #

NameDescription
param1
param2

Event ID 3221225479: The digitally signed Privilege Attribute Certificate (PAC) that contains the authorization information for client ClientName in realm Realm could not be valid...

#
Channel
Operational

Description

The digitally signed Privilege Attribute Certificate (PAC) that contains the authorization information for client ClientName in realm Realm could not be validated.

Message #

The digitally signed Privilege Attribute Certificate (PAC) that contains the authorization information for client %1 in realm %2 could not be validated.
 
 This error is usually caused by domain trust failures; Contact your system administrator.

Fields #

NameDescription
ClientName UnicodeString
Realm UnicodeString
binary Binary

Event ID 3221225480: The domain controller rejected the client certificate of user Message, used for smart card logon.

#
Channel
Operational

Description

The domain controller rejected the client certificate of user Message, used for smart card logon. The following error was returned from the certificate validation process: Name.

Message #

The domain controller rejected the client certificate of user %2, used for smart card logon. The following error was returned from the certificate validation process: %1.

Fields #

NameDescription
Name UnicodeString
Message UnicodeString
binary Binary

Event ID 3221225481: The client has failed to validate the domain controller certificate for Message.

#
Channel
Operational

Description

The client has failed to validate the domain controller certificate for Message. The following error was returned from the certificate validation process: Name.

Message #

The client has failed to validate the domain controller certificate for %2. The following error was returned from the certificate validation process: %1.

Fields #

NameDescription
Name UnicodeString
Message UnicodeString
binary Binary

Event ID 3221225483: The Distinguished Name in the subject field of your smart card logon certificate does not contain enough information to identify the appropriate do...

#
Channel
Operational

Description

The Distinguished Name in the subject field of your smart card logon certificate does not contain enough information to identify the appropriate domain on an non-domain joined computer. Contact your system administrator.

Message #

The Distinguished Name in the subject field of your smart card logon certificate does not contain enough information to identify the appropriate domain on an non-domain joined computer. Contact your system administrator.

Event ID 3221225488: The Kerberos SSPI package failed to find the smart card certificate in the certificate store.

#
Channel
Operational

Description

The Kerberos SSPI package failed to find the smart card certificate in the certificate store. To remedy this failure, logon as user Username and insert the smart card into the smart card reader, then use the Certificates snap-in to verify that the smart card certificate is in the user's personal certificate store.

Message #

The Kerberos SSPI package failed to find the smart card certificate in the certificate store. To remedy this failure, logon as user %1 and insert the smart card into the smart card reader, then use the Certificates snap-in to verify that the smart card certificate is in the user's personal certificate store.

Fields #

NameDescription
Username UnicodeString
binary Binary

Event ID 3221225489: The Kerberos SSPI package failed to locate the forest or domain Forest to search.

#
Channel
Operational

Description

The Kerberos SSPI package failed to locate the forest or domain Forest to search. Ensure that the Use forest search order Group Policy is correctly configured, and that this forest or domain is available.

Message #

The Kerberos SSPI package failed to locate the forest or domain %1 to search.  Ensure that the Use forest search order Group Policy is correctly configured, and that this forest or domain is available.

Fields #

NameDescription
Forest UnicodeString
binary Binary

Provenance

ETW provider GUID {98E6CFCB-EE0A-41E0-A57B-622D4E1B30B1}

Defined in kerberos.dll, which carries the event manifest.

  • WS2022-20348.4893, sample captured from a live trace, binary version 10.0.20348.2849, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.2849, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.4202, captured 2026-06-02 — Manifest XML pack, 2.0 MB