Kerberos Authentication Failures WS 2025

๐Ÿ”’ Secure Bits ๐Ÿ’ก
๐—ž๐—ฒ๐—ฟ๐—ฏ๐—ฒ๐—ฟ๐—ผ๐˜€ ๐—”๐˜‚๐˜๐—ต ๐—™๐—ฎ๐—ถ๐—น๐˜‚๐—ฟ๐—ฒ๐˜€ ๐—ถ๐—ป ๐— ๐—ถ๐˜…๐—ฒ๐—ฑ ๐—˜๐—ป๐˜ƒ๐—ถ๐—ฟ๐—ผ๐—ป๐—บ๐—ฒ๐—ป๐˜๐˜€ (๐—ช๐—ฆ ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฑ + ๐—ช๐—ฆ ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฎ ๐——๐—–๐˜€)

Ran into this issue twice already โ€” and itโ€™s sneaky.
So hereโ€™s what you should know ๐Ÿ‘‡

If youโ€™re running a mixed domain with ๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€ ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ฒ๐—ฟ ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฎ ๐—ฎ๐—ป๐—ฑ ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฑ ๐——๐—–๐˜€, watch out for Kerberos authentication errors after password changes.

๐Ÿ’ฅย ๐—œ๐˜€๐˜€๐˜‚๐—ฒ:
If a userโ€™s password is changed on a WS 2025 DC, and they later try to authenticate against a WS 2022 DC โ€” you may get:
๐Ÿ›‘ ๐—ž๐—ฅ๐—•๐Ÿฑ_๐—ž๐——๐—–_๐—˜๐—ฅ๐—ฅ_๐—˜๐—ง๐—ฌ๐—ฃ๐—˜_๐—ก๐—ข๐—ฆ๐—จ๐—ฃ๐—ฃ in Wireshark
๐Ÿ›‘ Event ID 4771 with failure codeย ๐Ÿฌ๐˜…๐—˜ย in logs
I experienced this in hardened environments with only AES enabled.

It looks like WS 2025 may generate key material that WS 2022 cannot read or validate properly, ๐—ฐ๐—ฎ๐˜‚๐˜€๐—ถ๐—ป๐—ด ๐—ฎ๐˜‚๐˜๐—ต ๐˜๐—ผ ๐—ณ๐—ฎ๐—ถ๐—นย โ€” even though everything looks configured correctly.

โœ… Once passwords are changed back on WS 2022 DCs โ†’ things work again across both.

๐Ÿ”ย ๐—›๐—ผ๐˜„ ๐˜๐—ผ ๐—ฑ๐—ฒ๐˜๐—ฒ๐—ฐ๐˜ ๐—ถ๐˜:
โ€ข Look for repeated ETYPE_NOSUPP errors in Wireshark
โ€ข Review Event ID 4771 with 0xE code
โ€ข Focus on accounts that recently changed passwords on WS 2025 DCs

๐Ÿฉน ๐—ง๐—ฒ๐—บ๐—ฝ๐—ผ๐—ฟ๐—ฎ๐—ฟ๐˜† ๐˜„๐—ผ๐—ฟ๐—ธ๐—ฎ๐—ฟ๐—ผ๐˜‚๐—ป๐—ฑ:
โ€ข Rotate affected passwords on WS 2022 or older DCs
โ€ข Or avoid mixed environments with WS 2025 DCs โ€” for now

Iโ€™ve seen this issue now multiple times, and spotted it discussed in a few community threads as well โ€” ๐˜€๐—ผ ๐—ถ๐˜โ€™๐˜€ ๐—ป๐—ผ๐˜ ๐—ถ๐˜€๐—ผ๐—น๐—ฎ๐˜๐—ฒ๐—ฑ.

โ“๐—”๐—ป๐˜†๐—ผ๐—ป๐—ฒ ๐—ฒ๐—น๐˜€๐—ฒ seeing similar problems? If youโ€™re running WS 2016 or WS 2019 DCs in a mixed setup โ€” are you affected too?