Hello,
We are trying to narrow down as to what is causing a lot of Kerberos Pre-Authentication Failures and logging events to Domain Controller. Every 675 event is followed by 672 for successful logon. We are trying to investigate as to why event Id 675 is logged with 0x19. What does 0x19 failure code mean (documentation just says additional authentication required). If this is normal behavior is there a Microsoft Document that explains this behavior. In the following events, DC is a windows 2003 server and client is a windows 2008 member server
The events are as follows
EventID 675
Event Type:Failure Audit
Event Source:Security
Event Category:Account Logon
Event ID:675
Date:5/12/2010
Time:11:20:48 AM
User:NT AUTHORITY\SYSTEM
Computer:DC
Description:
Pre-authentication failed:
User Name:UserAccount
User ID:Domain\UserAccount
Service Name:krbtgt/Domain
Pre-Authentication Type:0x0
Failure Code:0x19
Client Address:10.x.x.x
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
EventID 672