Direct Inward Dialing: +1 408 916 9892
Kerberos replaced NT LAN Manager (NTLM) as the default authentication for Windows OS, as a much faster and safer alternative. IT administrators can enable auditing of Kerberos authentication, which allows recording of events created during this process. Admins can monitor these events to keep an eye on both failed and successful logon activities of users logging into the domain. Any sudden anomalous changes, such as an unusually high number of failed logon attempts, could indicate the possibility of a brute force attack, and more. Read on to find out how to audit Kerberos authentication events:
Once the above steps are complete, Kerberos authentication events will be stored in the event log. These events can be viewed in the Event Viewer by performing the following actions on the domain controller (DC):
Event ID | Subcategory | Event Type | Description |
---|---|---|---|
4768 | Kerberos Authentication Service | Success and Failure | A Kerberos authentication ticket (TGT) was requested |
4769 | Kerberos Service Ticket Operations | Success and Failure | A Kerberos service ticket was requested |
4770 | Kerberos Service Ticket Operations | Success | A Kerberos service ticket was renewed |
4771 | Kerberos Authentication Service | Failure | Kerberos pre-authentication failed |
4772 | Kerberos Authentication Service | Failure | A Kerberos authentication ticket request failed |
4773 | Kerberos Service Ticket Operations | Failure | A Kerberos service ticket request failed |
Limitations of Active Directory (AD) native auditing:
ManageEngine ADAudit Plus is an Active Directory auditing tool that can help monitor user logon activity using Kerberos authentication events. You can also detect possible security threats with reports on anomalous logon activity and automate responses to such threats.
Gain deeper insight into logons taking place in your organization, and understand when and where each logon took place.
Monitor users logged into multiple computers to detect security risks in your organization since a third party might be accessing the user account to gain control.
Monitor and obtain reports for all logon activity on DCs, member servers, and workstations.
Gain deeper insight into logons taking place in your organization, and understand when and where each logon took place.
Monitor users logged into multiple computers to detect security risks in your organization since a third party might be accessing the user account to gain control.
Monitor and obtain reports for all logon activity on DCs, member servers, and workstations.
Advantages of using ADAudit Plus: