Skip to main content
AD Academy
Back to all events
4771Security (DC)AuthenticationWARNLast updated:

Kerberos pre-authentication failed

What it means

TGT request rejected. 0x18 wrong password, 0x12 account disabled/locked/expired, 0x25 clock skew over 5 minutes.

When it is normal and when it is suspicious

Normal: a single 0x18 failure after a password change. Suspicious: a run of 0x12 (account disabled/locked) or many accounts from one source.

First steps

  1. 1Decode Failure Code — it points straight at the cause.
  2. 20x25 means fix time: w32tm /query /status on client and DC.
  3. 3Repeating 0x18 from one host is a likely lockout source.

Fields worth checking

FieldWhat to look at
Failure Code0x18 = bad password, 0x12 = account locked/disabled, 0x17 = password expired.
Client AddressThe requesting IP — the fastest way to find the device causing lockouts.

Related events

This reference is a starting point for investigation, not a replacement for your organisation's security policy.