Event ID 676 Logged

  • Thread starter Thread starter Brandon Kendall
  • Start date Start date
B

Brandon Kendall

We're running a Windows 2000 domain in mixed-mode. One
specific client, a Windows 2000 Pro machine, is having
trouble. Every morning the user's account is locked out
and the following is logged in the event log:

Date: xx Source: Security
Time: xx Category: Account Logon
Type: Failure Event ID: 676
User: NT AUTHORTY\SYSTEM
Computer: [domain controller name]
Description:
Authentication Ticket Request Failed:
User Name: [username]
Supplied Realm Name: [AD domain]
Service Name: krbtgt/[domain name]
Ticket Options: 0x40810010
Failure Code: 0x12
Client Address: 192.168.1.78

I have searched the knowledgebase and cannot find anything
that sheds light on this issue. I'm hoping you guys can
help me.
Thanks.
-Brandon
 
Failure code 0x12 is a kerberos error as described in RFC 1510. (0x12=18
dec)

KDC_ERR_CLIENT_REVOKED 18 Clients credentials have been revoked

This is due to a workstation restriction on the account, or a logon time
restriction, or logon attempt outside logon hours, or accout disabled,
expired, or locked out.

Eric

--
Eric Fitzgerald
Program Manager, Windows Auditing
Microsoft Corporation

The above message is provided "AS-IS" with no warranties, and confers no
rights.
 
Back
Top