Windows Security Log Event ID 4822

Operating Systems Windows 2012 R2 and 8.1
Windows 2016 and 10
Windows Server 2019 and 2022
Category
 • Subcategory
System
 • Other System Events
Type Failure
Corresponding events
in Windows 2003
and before
 

4822: NTLM authentication failed because the account was a member of the Protected User group

On this page

This event is new to Server 2012 R2. It does not appear in earlier versions.

I haven't been able to produce this event. Have you? If so, please start a discussion (see above) and post a sample along with any comments you may have! Don't forget to sanitize any private information.

Free Security Log Resources by Randy

Supercharger Free Edition


Supercharger's built-in Xpath filters leave the noise behind.

Free.

 

Examples of 4822

NTLM authentication failed because the account was a member of the Protected User group.

Account Name:  %1
Device Name:   %2
Error Code:    %3

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection

 

Upcoming Webinars
    Additional Resources