ReferenceCONSTRUCTED
Windows logon and Kerberos failure codes: 4625, 4776, 4768 and 4771
The status and sub-status codes in a failed Windows logon, the Kerberos result codes on the domain controller, and which combination is a typo, a locked account, a stale service or somebody guessing.
version 1.0checked 2026-09-26windows3 min read
Where a failure is written
Which event you get depends on the protocol and on which machine checked the password, and that decides where you have to look.
| Event | Written on | When |
|---|---|---|
| 4625 | The machine the logon was attempted on | Any failed logon, local or network |
| 4776 | The domain controller, or the local machine for local accounts | NTLM credential validation, success or failure |
| 4768 | The domain controller | A Kerberos ticket-granting ticket was requested, success or failure |
| 4771 | The domain controller | Kerberos pre-authentication failed, most often a wrong password |
A password spray against a domain using Kerberos produces 4771 on the domain controllers and nothing on the servers it was aimed at. A dashboard built only on 4625 from member servers never sees it.
4625 and 4776 status codes
4625 carries a Status and a Sub Status. When Status is 0xC000006D, the generic "unknown user name or bad password", the Sub Status is the real reason. 4776 reports the same NTSTATUS values as its error code.
| Code | Meaning | Reading it |
|---|---|---|
| 0xC000006A | Correct user name, wrong password | Typos, or guessing. Many accounts from one source is a spray |
| 0xC0000064 | The user name does not exist | Enumeration, or an application with a stale account name |
| 0xC0000234 | The account is locked out | The consequence, not the cause. Find the failures before it |
| 0xC0000072 | The account is disabled | Attempts against leavers' accounts are worth a look |
| 0xC000006F | Logon outside permitted hours | |
| 0xC0000070 | Logon from a workstation the account is not allowed to use | |
| 0xC0000071 | The password has expired | Commonly a service or scheduled task still using an old password |
| 0xC0000193 | The account has expired | |
| 0xC0000224 | The user must change the password at next logon | |
| 0xC000015B | The user has not been granted this logon type on this machine | Somebody trying to log on in a way policy forbids, such as a service account interactively |
| 0xC0000133 | Clocks out of sync between the client and the domain controller | Kerberos fails beyond five minutes of skew by default |
| 0xC0000413 | Blocked by the authentication firewall | Selective authentication across a trust |
Kerberos result codes, 4768 and 4771
| Code | Name | Reading it |
|---|---|---|
| 0x6 | KDC_ERR_C_PRINCIPAL_UNKNOWN | The user does not exist. In volume, from one source, it is enumeration |
| 0x12 | KDC_ERR_CLIENT_REVOKED | Disabled, expired or locked out |
| 0x17 | KDC_ERR_KEY_EXPIRED | The password has expired |
| 0x18 | KDC_ERR_PREAUTH_FAILED | Wrong password. The Kerberos equivalent of 0xC000006A |
| 0x25 | KRB_AP_ERR_SKEW | Clock skew |
On a successful 4768, Pre-Authentication Type 0 means pre-authentication is disabled for the account, which is what makes AS-REP roasting possible. Nothing should have that setting without a documented reason.
Reading a burst
- Many accounts, one source, one or two failures each, 0xC000006A or 0x18. A password spray. Look for the success that follows from the same source.
- One account, many failures, then 0xC0000234. Guessing, or a phone with an old password. The source address tells you which.
- One account, steady failures with 0xC0000071 around the clock. A service, scheduled task or mapped drive still using an expired password. Noise, but it hides real failures behind it, so fix it.
- 0xC0000064 across many made-up names. Somebody is trying to find out which accounts exist.
The password spray lab works the first pattern from the domain controller's side.