Friday, May 14, 2010

Kerberos pre-authentication failed on DC from 127.0.0.1

Scenario: You recieve a large amount of Event ID 675 on a DC where client Adress is 127.0.0.1. It is usally from the administrator account.

This can be a result of a number of issues, first check that no service or process is using the particular account.

In my case it was problem with the DHCP DNS registration that were set to use the Administrator account. So, go look at:

Manage Your Server –> Manage this DHCP server –> In the DHCP dialog; right click the server and choose Properties –> Advanced tab –> Credentials. Make sure the account entered there have necessary rights and that the password is correctly entered (see http://support.microsoft.com/kb/816592 for details).