Kerberos Pre-Authentication Types

TypeType NameDescription
0Logon without Pre-Authentication.
2PA-ENC-TIMESTAMPThis is a normal type for standard password authentication
11PA-ETYPE-INFOThe ETYPE-INFO pre-authentication type is sent by the KDC in a KRB-ERROR indicating a requirement for additional pre-authentication. It is usually used to notify a client of which key to use for the encryption of an encrypted timestamp for the purposes of sending a PA-ENC-TIMESTAMP pre-authentication value.
Never saw this Pre-Authentication Type in Microsoft Active Directory environment
15PA-PK-AS-REP_OLDUsed for Smart Card logon authentication
16PA-PK-AS-REQRequest sent to KDC in Smart Card authentication scenarios
17PA-PK-AS-REPThis type should also be used for Smart Card authentication, but in certain Active Directory environments, it is never seen
19PA-ETYPE-INFO2The ETYPE-INFO2 pre-authentication type is sent by the KDC in a KRB-ERROR indicating a requirement for additional pre-authentication. It is usually used to notify a client of which key to use for the encryption of an encrypted timestamp for the purposes of sending a PA-ENC-TIMESTAMP pre-authentication value.
Never saw this Pre-Authentication Type in Microsoft Active Directory environment
20PA-SVR-REFERRAL-INFOUsed in KDC Referrals tickets
138PA-ENCRYPTED-CHALLENGELogon using Kerberos Armoring (FAST). Supported starting from Windows Server 2012 domain controllers and Windows 8 clients
This type shows in Audit Failure events.
Kerberos Pre-Authentication Types