The User field for this event (and all other events in the Audit account logon event category) doesn't help you determine who the user was the field always reads N/A. In Windows Kerberos, password verification takes place during pre-authentication. If the ticket request fails Windows will either log this event, failure 4771, or 4768 if the problem arose during "pre-authentication". If the username and password are correct and the user account passes status and restriction checks, the DC grants the TGT and logs event ID 4768 (authentication ticket granted). This event is logged on domain controllers only and only failure instances of this event are logged.Īt the beginning of the day when a user sits down at his or her workstation and enters his domain username and password, the workstation contacts a local DC and requests a TGT.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |