Windows Security Log Event ID 4824
Operating Systems |
Windows 2012 R2 and 8.1
Windows 2016 and 10
Windows Server 2019 and 2022
|
Category • Subcategory | System • Other System Events |
Type
|
Failure
|
Corresponding events
in Windows
2003 and before |
|
4824: Kerberos preauthentication by using DES or RC4 failed because the account was a member of the Protected User group
On this page
This event is new to Server 2012 R2. It does not appear in earlier versions.
I haven't been able to produce this event. Have you? If so, please start a discussion (see above) and post a sample along with any comments you may have! Don't forget to sanitize any private information.
Free Security Log Resources by Randy
Supercharger Free Edition
Supercharger's built-in Xpath filters leave the noise behind.
Free.
Kerberos preauthentication by using DES or RC4 failed because the account was a member of the Protected User group.
Account Information:
Security ID: %2
Account Name: %1
Service Information:
Service Name: %3
Network Information:
Client Address: %7
Client Port: %8
Additional Information:
Ticket Options: %4
Failure Code: %5
Pre-Authentication Type: %6
Certificate Information:
Certificate Issuer Name: %9
Certificate Serial Number: %10
Certificate Thumbprint: %11
Certificate information is only provided if a certificate was used for pre-authentication.
Pre-authentication types, ticket options and failure codes are defined in RFC 4120.
If the ticket was malformed or damaged during transit and could not be decrypted, then many fields in this event might not be present.
Top 10 Windows Security Events to Monitor
Free Tool for Windows Event Collection