Skip to main content
AD Academy
Back to all events
4776Security (DC)AuthenticationWARNLast updated:

NTLM credential validation

What it means

The DC validated a password over NTLM. Microsoft is retiring NTLM — every 4776 today is a question: who still uses it and why.

When it is normal and when it is suspicious

Normal: legacy devices and apps still using NTLM. Suspicious: NTLM auth for an admin account, or many 0xC0000064 errors.

First steps

  1. 1Inventory who requests NTLM (Source Workstation) before you block it.
  2. 2Error Code 0xC000006A is again a wrong password.
  3. 3Plan the Kerberos move: DNS names instead of IPs, correct SPNs.

Fields worth checking

FieldWhat to look at
Logon AccountA privileged account over NTLM is a Pass-the-Hash target.
Source WorkstationThe source. A host that should be Kerberos-only warrants a look at why it fell back to NTLM.

Related events

This reference is a starting point for investigation, not a replacement for your organisation's security policy.