Skip to content

Commit 3b17773

Browse files
committed
add draft
1 parent 5eab4fc commit 3b17773

File tree

2 files changed

+77
-2
lines changed

2 files changed

+77
-2
lines changed

support/windows-server/toc.yml

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -756,7 +756,7 @@ items:
756756
items:
757757
- name: Extend stand-alone tiered storage spaces
758758
href: ./backup-and-storage/extend-stand-alone-tiered-storage-spaces.md
759-
- name: Manage disks in standalone Storage Spaces
759+
- name: Manage disks in standalone Storage Spaces
760760
href: ./backup-and-storage/manage-disks-standalone-storage-spaces.md
761761
- name: System Restore or resetting your computer
762762
items:
@@ -2902,6 +2902,8 @@ items:
29022902
href: ./windows-security/description-support-suite-b-cryptographic-ipsec.md
29032903
- name: Kerberos authentication
29042904
items:
2905+
- name: Event ID 7 on a DC running Windows Server 2025
2906+
href: windows-security/event-id-7-on-a-dc-running-windows-server-2025.md
29052907
- name: 'Troubleshooting guidance: Kerberos authentication'
29062908
href: ./windows-security/kerberos-authentication-troubleshooting-guidance.md
29072909
- name: Active Directory authentication fails with klist error 0x8009030e
@@ -2948,7 +2950,7 @@ items:
29482950
href: ./windows-security/troubleshoot-kerberos-constrained-delegation-issues.md
29492951
- name: Troubleshoot Kerberos using a log analysis test scenario
29502952
href: ./windows-security/kerberos-authentication-log-analysis-test-scenario.md
2951-
- name: 'Troubleshoot resource-based constrained delegation issues'
2953+
- name: Troubleshoot resource-based constrained delegation issues
29522954
href: ./windows-security/troubleshoot-kerberos-rbcd-issues.md
29532955
- name: Troubleshoot SSO issues
29542956
href: ./windows-security/troubleshoot-kerberos-sso-issues.md
Lines changed: 73 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,73 @@
1+
---
2+
title: ''
3+
description: ''
4+
ms.date: 06/23/2025
5+
manager: dcscontentpm
6+
audience: itpro
7+
ms.topic: troubleshooting
8+
ms.reviewer: ''
9+
ms.custom:
10+
- sap:windows security technologies\kerberos authentication
11+
- pcy:WinComm Directory Services
12+
---
13+
# Event ID 7 is logged on a Windows Server 2025-based DC
14+
15+
Active Directory domain controllers (DCs) that are running Windows Server 2025 might intermittently log event ID 7. This article provides suggestions for this error.
16+
17+
## Event sample:
18+
19+
The following is a sample of the event:
20+
21+
Log Name: System
22+
Source: Microsoft-Windows-Kerberos-Key-Distribution-Center
23+
Date: 3/11/2025 10:07:03 AM
24+
Event ID: 7
25+
Task Category: None
26+
Level: Error
27+
Keywords: Classic
28+
User: N/A
29+
Computer: 2025DC1.contoso.com
30+
Description:
31+
The Security Account Manager failed a KDC request in an unexpected way. The error is in the data field. The account name was and lookup type 0x108.
32+
Event Xml:
33+
<Event
34+
xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
35+
<System>
36+
<Provider Name="Microsoft-Windows-Kerberos-Key-Distribution-Center" Guid="{3FD9DA1A-5A54-46C5-9A26-9BD7C0685056}" EventSourceName="KDC" />
37+
<EventID Qualifiers="49152">7</EventID>
38+
<Version>0</Version>
39+
<Level>2</Level>
40+
<Task>0</Task>
41+
<Opcode>0</Opcode>
42+
<Keywords>0x80000000000000</Keywords>
43+
<TimeCreated SystemTime="2025-03-11T07:07:03.7950701Z" />
44+
<EventRecordID>29550</EventRecordID>
45+
<Correlation />
46+
<Execution ProcessID="896" ThreadID="0" />
47+
<Channel>System</Channel>
48+
<Computer>2025DC1.contoso.com</Computer>
49+
<Security />
50+
</System>
51+
<EventData>
52+
<Data Name="AccountName">
53+
</Data>
54+
<Data Name="LookupType">0x108</Data>
55+
<Binary>0D0000C0</Binary>
56+
</EventData>
57+
</Event>
58+
59+
> [!IMPORTANT]
60+
61+
The text of the event has a blank account name: "The account name was ..."
62+
63+
If the event ID lists a different account name or lookup type, it may be a separate issue and may require investigation.
64+
65+
## Resolution
66+
67+
This is only considered a cosmetic bug that can be safely ignored when the account name is blank.
68+
69+
## State
70+
71+
This only impacts Windows Server 2025 when running as an Active Directory KDC. No other versions of Windows Server have this issue.
72+
73+
The Windows Product Group has acknowledged that this is a cosmetic bug and that these events can be safely ignored.

0 commit comments

Comments
 (0)