4820 Security log · Kerberos Authentication Service medium severity low volume

Windows Event ID 4820 — A Kerberos Ticket-Granting-Ticket (TGT) was denied because the device does not meet the access control restrictions

TGT denied due to device-based access control (compound authentication). Device health or membership restriction failed.

Why event 4820 matters

Indicates device claiming to be compliant but failing validation. May appear during pass-the-ticket attacks from non-compliant devices.

How to detect it

Alert: frequent denials from specific devices or accounts. Investigate device compliance status.

Log source
Security
Advanced Audit Policy — enable the 'Kerberos Authentication Service' subcategory (Success and/or Failure).
Fields to pivot on
SubjectUserNameTargetUserNameLogonTypeIpAddressWorkstationName

Detection queries

Starting points — adapt the log source, projected fields and thresholds for your environment.

Sentinel / Defender KQL
SecurityEvent
| where EventID == 4820   // A Kerberos Ticket-Granting-Ticket (TGT) was denied because the device does not meet the access control restrictions
| project TimeGenerated, Computer, SubjectUserName, TargetUserName, LogonType, IpAddress, WorkstationName
| sort by TimeGenerated desc
Splunk SPL
index=* sourcetype="WinEventLog:Security" EventCode=4820
| stats count earliest(_time) as first_seen latest(_time) as last_seen by ComputerName
| sort - count   `# A Kerberos Ticket-Granting-Ticket (TGT) was denied because the device does not meet the access control restrictions — add EventData fields: SubjectUserName, TargetUserName, LogonType, IpAddress`
Hunt event 4820 in Sentinel/Defender →
Build a KQL query for this event in the KQL Query Builder.
Search all event IDs →
Open the interactive Windows Event ID lookup.

Related Kerberos Authentication Service events

4768 A Kerberos authentication ticket (TGT) was requested 4769 A Kerberos service ticket was requested 4770 A Kerberos service ticket was renewed 4771 Kerberos pre-authentication failed 4772 A Kerberos authentication ticket request failed 4773 A Kerberos service ticket request failed 4774 An account was mapped for logon 4775 An account could not be mapped for logon 4776 The domain controller attempted to validate the credentials for an account (NTLM) 4777 The domain controller failed to validate the credentials for an account 4821 A Kerberos service ticket was denied because the user, device, or both do not meet the access control restrictions 4822 NTLM authentication failed because the account was a member of the Protected Users group

Frequently asked questions

What is Windows Event ID 4820?

A Kerberos Ticket-Granting-Ticket (TGT) was denied because the device does not meet the access control restrictions. TGT denied due to device-based access control (compound authentication). Device health or membership restriction failed.

Which log records event 4820?

Event 4820 is written to the Security channel by Microsoft-Windows-Security-Auditing. Advanced Audit Policy — enable the 'Kerberos Authentication Service' subcategory (Success and/or Failure).

How do you detect activity around event 4820?

Alert: frequent denials from specific devices or accounts. Investigate device compliance status.