|
| 1 | +--- |
| 2 | +title: '' |
| 3 | +description: '' |
| 4 | +ms.date: 06/23/2025 |
| 5 | +manager: dcscontentpm |
| 6 | +audience: itpro |
| 7 | +ms.topic: troubleshooting |
| 8 | +ms.reviewer: '' |
| 9 | +ms.custom: |
| 10 | +- sap:windows security technologies\kerberos authentication |
| 11 | +- pcy:WinComm Directory Services |
| 12 | +--- |
| 13 | +# Event ID 7 is logged on a Windows Server 2025-based DC |
| 14 | + |
| 15 | +Active Directory domain controllers (DCs) that are running Windows Server 2025 might intermittently log event ID 7. This article provides suggestions for this error. |
| 16 | + |
| 17 | +## Event sample: |
| 18 | + |
| 19 | +The following is a sample of the event: |
| 20 | + |
| 21 | +Log Name: System |
| 22 | +Source: Microsoft-Windows-Kerberos-Key-Distribution-Center |
| 23 | +Date: 3/11/2025 10:07:03 AM |
| 24 | +Event ID: 7 |
| 25 | +Task Category: None |
| 26 | +Level: Error |
| 27 | +Keywords: Classic |
| 28 | +User: N/A |
| 29 | +Computer: 2025DC1.contoso.com |
| 30 | +Description: |
| 31 | +The Security Account Manager failed a KDC request in an unexpected way. The error is in the data field. The account name was and lookup type 0x108. |
| 32 | +Event Xml: |
| 33 | +<Event |
| 34 | +xmlns="http://schemas.microsoft.com/win/2004/08/events/event"> |
| 35 | + <System> |
| 36 | + <Provider Name="Microsoft-Windows-Kerberos-Key-Distribution-Center" Guid="{3FD9DA1A-5A54-46C5-9A26-9BD7C0685056}" EventSourceName="KDC" /> |
| 37 | + <EventID Qualifiers="49152">7</EventID> |
| 38 | + <Version>0</Version> |
| 39 | + <Level>2</Level> |
| 40 | + <Task>0</Task> |
| 41 | + <Opcode>0</Opcode> |
| 42 | + <Keywords>0x80000000000000</Keywords> |
| 43 | + <TimeCreated SystemTime="2025-03-11T07:07:03.7950701Z" /> |
| 44 | + <EventRecordID>29550</EventRecordID> |
| 45 | + <Correlation /> |
| 46 | + <Execution ProcessID="896" ThreadID="0" /> |
| 47 | + <Channel>System</Channel> |
| 48 | + <Computer>2025DC1.contoso.com</Computer> |
| 49 | + <Security /> |
| 50 | + </System> |
| 51 | + <EventData> |
| 52 | + <Data Name="AccountName"> |
| 53 | + </Data> |
| 54 | + <Data Name="LookupType">0x108</Data> |
| 55 | + <Binary>0D0000C0</Binary> |
| 56 | + </EventData> |
| 57 | +</Event> |
| 58 | + |
| 59 | +> [!IMPORTANT] |
| 60 | +
|
| 61 | +The text of the event has a blank account name: "The account name was ..." |
| 62 | + |
| 63 | +If the event ID lists a different account name or lookup type, it may be a separate issue and may require investigation. |
| 64 | + |
| 65 | +## Resolution |
| 66 | + |
| 67 | +This is only considered a cosmetic bug that can be safely ignored when the account name is blank. |
| 68 | + |
| 69 | +## State |
| 70 | + |
| 71 | +This only impacts Windows Server 2025 when running as an Active Directory KDC. No other versions of Windows Server have this issue. |
| 72 | + |
| 73 | +The Windows Product Group has acknowledged that this is a cosmetic bug and that these events can be safely ignored. |
0 commit comments