Audit Failure - Account name: None


  • We have many security logs (Audit Failure - Event ID: 4768) on domain controller.

    Among these 4768 events, dozens of them every day are


    A Kerberos authentication ticket (TGT) was requested.

    Account Information:
    Account Name: None
    Supplied Realm Name: domain.local
    User ID: NULL SID

    Service Information:
    Service Name: krbtgt/domain.local
    Service ID: NULL SID

    Network Information:
    Client Address: ::ffff: (our microsoft TMG-webproxy server)
    Client Port: 24656

    Additional Information:
    Ticket Options: 0x40810010
    Result Code: 0x6
    Ticket Encryption Type: 0xFFFFFFFF
    Pre-Authentication Type: -

    Certificate Information:
    Certificate Issuer Name:
    Certificate Serial Number:
    Certificate Thumbprint:

    Certificate information is only provided if a certificate was used for pre-authentication.

    Pre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.  ---------------

    Do these mean some users were accessing internet web pages which were filtered on user basis, and TMG (web proxy) server failed to get/pass their user account info thus the domain controller said "I cannot authenticate user"?

    Any help is appreciated.


    • Edited by GPING Thursday, April 20, 2017 5:36 AM
    Thursday, April 20, 2017 5:29 AM

All replies

  • Hi,

    Was your issue resolved? If you resolved it using our solution, please "mark it as answer" to help other community members find the helpful reply quickly.

    If you resolve it using your own solution, please share your experience and solution here. It will be very beneficial for other community members who have similar questions. If no, please reply and tell us the current situation in order to provide further help.
    Best Regards,


    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact

    Monday, April 24, 2017 1:13 PM