I have a problem: where to start
Pick the symptom the user describes and get the events to check plus ready-made commands.
A user keeps getting locked out, even after a password reset
What usually causes this: Start with 4740 on the PDC Emulator: Caller Computer Name points at the culprit device (usually a phone or a service with an old password).
Events to check
Practical recipes
"The trust relationship between this workstation and the domain failed"
What usually causes this: Do not rejoin the domain. Repair the channel with Test-ComputerSecureChannel -Repair.
Events to check
- 5722Secure channel setup with a machine account failed
- 3210Failed to authenticate to the domain (Netlogon)
- 5723Secure channel request from a machine account that does not exist
Practical recipes
Replication between domain controllers is not working
What usually causes this: repadmin /replsummary gives the picture in seconds. 2042 means the DC was offline too long — do not reconnect it without cleanup.
Events to check
- 1311KCC cannot build a replication topology
- 1388Lingering object re-created
- 1988Lingering object — replication halted
- 2042It has been too long since this machine replicated
Practical recipes
Suspected breach or a stolen account
What usually causes this: Look first for 4728 (added to Domain Admins) and 1102 (log cleared). Preserve logs before doing anything.
Events to check
- 4625Failed logon
- 4728Member added to a global group (e.g. Domain Admins)
- 4672Special privileges assigned to new logon
- 1102Security log was cleared
- 4719System audit policy was changed
Practical recipes
Group Policy is not applying to a workstation
What usually causes this: 1058 means the host cannot read the GPO file from SYSVOL. Run gpresult /h and check DNS.
Events to check
- 1058Client could not read a GPO file from SYSVOL
- 1085A specific GPO extension failed to apply
- 5136A directory service object was modified (including GPOs)
Practical recipes
Signing in takes several minutes
What usually causes this: Usually DNS: the host points at 8.8.8.8 instead of the DC and cannot find the SRV records.
Events to check
- 1058Client could not read a GPO file from SYSVOL
- 5722Secure channel setup with a machine account failed
- 4768A Kerberos TGT was requested
Practical recipes
The SIEM alerted on unusual Kerberos activity
What usually causes this: Check 4769 with encryption type 0x17 against many distinct SPNs within minutes — the Kerberoasting signature.
Events to check
- 4769Service ticket (TGS) requested — the Kerberoasting signal
- 4768A Kerberos TGT was requested
- 4771Kerberos pre-authentication failed
Practical recipes
A user lost access to a shared folder
What usually causes this: Check 4733/4729 in the last hours — someone was removed from a group. A re-logon is needed after restoring it.
Events to check
- 4733Member removed from a domain local group
- 4729Member removed from a global group
- 4624Successful logon
Practical recipes