TopicWindows Server →
A domain or system controller validated identifiers via NTLM.
Source of event
Microsoft-Windows-Security-Auditing — Security category.
Possible causes
- Old application
- Local authentication or network
- Fallback when Kerberos is not used
Verifications to be carried out
- Read your code
- Identify Posting
- Check why NTLM is used if Kerberos is expected
Useful orders….
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4776} -MaxEvents 50
To be retained….
An Event ID must always be interpreted with its source, its full message, its timing and the context of the system. The same number may exist in several providers of events.