Windows Security Log Event ID 4770

Operating Systems Windows 2008 R2 and 7
Windows 2012 R2 and 8.1
Windows 2016 and 10
Windows Server 2019 and 2022
 • Subcategory
Account Logon
 • Kerberos Service Ticket Operations
Type Success
Corresponding events
in Windows 2003
and before

4770: A Kerberos service ticket was renewed

Kerberos limits how long a ticket is valid. If a ticket expires when the user is still logged on, Windows automatically contacts the domain controller to renew the ticket which triggers this event.

Description Fields in 4770

Account Information: 

  • Account Name:  logon name of the account that just renewed the ticket
  • Supplied Realm Name: domain name of the account
  • User ID:   SID of the account 

Service Information:

  • Service Name:  the account name of the computer or service the user is renewing the ticket to
  • Service ID:  SID of the computer or service

Network Information:

  • Client Address:  IP address where user is present
  • Client Port:  source port

Additional Information:

  • Ticket Options:  unknown.  Please start a discussion if you have information to share on this field.
  • Ticket Encryption Type: unknown.  Please start a discussion if you have information to share on this field.

Examples of 4770

A Kerberos service ticket was renewed.

Account Information:

   Account Name:  WIN-857ZZX6RQHL$@ACME-FR.LOCAL
   Account Domain:  ACME-FR.LOCAL 

Service Information:

   Service Name:  krbtgt
   Service ID:  ACME-FR\krbtgt

Network Information:

   Client Address:  ::1
   Client Port:  0

Additional Information:

   Ticket Options:  0x2
   Ticket Encryption Type: 0x12

Ticket options and encryption types are defined in RFC 4120.

