Windows Security Log Event ID 4770

Operating Systems Windows 2008 R2 and 7
Windows 2012 R2 and 8.1
Windows 2016 and 10
Windows Server 2019 and 2022
 • Subcategory
Account Logon
 • Kerberos Service Ticket Operations
Type Success
Corresponding events
in Windows 2003
and before

4770: A Kerberos service ticket was renewed

On this page

Kerberos limits how long a ticket is valid. If a ticket expires when the user is still logged on, Windows automatically contacts the domain controller to renew the ticket which triggers this event.

Free Security Log Resources by Randy

Description Fields in 4770

Account Information: 

  • Account Name:  logon name of the account that just renewed the ticket
  • Supplied Realm Name: domain name of the account
  • User ID:   SID of the account 

Service Information:

  • Service Name:  the account name of the computer or service the user is renewing the ticket to
  • Service ID:  SID of the computer or service

Network Information:

  • Client Address:  IP address where user is present
  • Client Port:  source port

Additional Information:

  • Ticket Options:  unknown.  Please start a discussion if you have information to share on this field.
  • Ticket Encryption Type: unknown.  Please start a discussion if you have information to share on this field.

Supercharger Enterprise


Examples of 4770

A Kerberos service ticket was renewed.

Account Information:

   Account Name:  WIN-857ZZX6RQHL$@ACME-FR.LOCAL
   Account Domain:  ACME-FR.LOCAL 

Service Information:

   Service Name:  krbtgt
   Service ID:  ACME-FR\krbtgt

Network Information:

   Client Address:  ::1
   Client Port:  0

Additional Information:

   Ticket Options:  0x2
   Ticket Encryption Type: 0x12

Ticket options and encryption types are defined in RFC 4120.

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection


Additional Resources