Back to all events4776AuthenticationWARNLast updated:
NTLM credential validation
What it means
The DC validated a password over NTLM. Microsoft is retiring NTLM — every 4776 today is a question: who still uses it and why.
When it is normal and when it is suspicious
Normal: legacy devices and apps still using NTLM. Suspicious: NTLM auth for an admin account, or many 0xC0000064 errors.
First steps
- 1Inventory who requests NTLM (Source Workstation) before you block it.
- 2Error Code 0xC000006A is again a wrong password.
- 3Plan the Kerberos move: DNS names instead of IPs, correct SPNs.
Fields worth checking
Related events
This reference is a starting point for investigation, not a replacement for your organisation's security policy.