Windows 10: A logon was attempted using explicit credentials, Event ID 4648

Discus and support A logon was attempted using explicit credentials, Event ID 4648 in Windows 10 News to solve the problem; [IMG]We stumbled upon Event ID 4648 in the Event Viewer that says “A logon was attempted using explicit credentials”. This is triggered when a process... Discussion in 'Windows 10 News' started by WinClub, Aug 20, 2025 at 7:33 AM.

  1. WinClub New Member

    A logon was attempted using explicit credentials, Event ID 4648


    A logon was attempted using explicit credentials, Event ID 4648 [​IMG]
    We stumbled upon Event ID 4648 in the Event Viewer that says “A logon was attempted using explicit credentials”. This is triggered when a process tries to log into an account by providing credentials (username and password) different from those of the currently logged-in user. While this may occur during legitimate operations such as scheduled tasks, […]

    This article A logon was attempted using explicit credentials, Event ID 4648 first appeared on TheWindowsClub.com.

    read more...
     

  2. Windows Hello - A logon was attempted using explicit credentials.

    Hi all,

    For some reason my PIN and fingerprint credentials have stopped working. Whenever I try to login to my laptop using with them, it says "your credentials couldn't be verified" and I get this error message in the event log:

    A logon was attempted using explicit credentials.

    Subject:

    Security ID: SYSTEM

    Account Name: ---

    Account Domain: ---

    Logon ID: 0x3E7

    Logon GUID: {00000000-0000-0000-0000-000000000000}

    Account Whose Credentials Were Used:

    Account Name: ---

    Account Domain: ---

    Logon GUID: {00000000-0000-0000-0000-000000000000}

    Target Server:

    Target Server Name: localhost

    Additional Information: localhost

    Process Information:

    Process ID: 0x2b38

    Process Name: C:\Windows\System32\svchost.exe

    Network Information:

    Network Address: ::1

    Port: 0

    This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.

    What is causing this, and how can I fix this so that I can use my PIN and Fingerprint again. I've tried resetting my PIN and Fingerprint, deleting the NGC folder and setting DevicePKInitEnabled under HKLM\System\CurrentControlSet\Control\Lsa\Kerberos\Parameters. to 0. (I'm on Win10)
     
  3. Logon event

    Hello, can someone help me to get out what kind of event is above?

    I can't understand who or what trying to connect into 192.168.10.50 server.

    A logon was attempted using explicit credentials.

    Subject:
    Security ID: SYSTEM
    Account Name: PC-1074-050917$
    Account Domain: test
    Logon ID: 0x3E7
    Logon GUID: {00000000-0000-0000-0000-000000000000}

    Account Whose Credentials Were Used:
    Account Name: admbaltsupuser
    Account Domain: HEADOFFICE.test.LV
    Logon GUID: {00000000-0000-0000-0000-000000000000}

    Target Server:
    Target Server Name: fileserver
    Additional Information: cifs/fileserver

    Process Information:
    Process ID: 0x4
    Process Name:

    Network Information:
    Network Address: 192.168.10.50
    Port: 445

    This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.

    System

    - Provider

    [ Name] Microsoft-Windows-Security-Auditing

    [ Guid] {54849625-5478-4994-A5BA-3E3B0328C30D}



    EventID 4648



    Version 0



    Level 0



    Task 12544



    Opcode 0



    Keywords 0x8020000000000000



    - TimeCreated

    [ SystemTime] 2018-12-20T06:27:07.319340400Z



    EventRecordID 127514



    - Correlation

    [ ActivityID] {FD92A94E-91ED-0003-6BA9-92FDED91D401}



    - Execution

    [ ProcessID] 792

    [ ThreadID] 932



    Channel Security



    Computer PC-1074-050917.headoffice.test.lv



    Security



    - EventData

    SubjectUserSid S-1-5-18

    SubjectUserName PC-1074-050917$

    SubjectDomainName HEADOFFICE

    SubjectLogonId 0x3e7

    LogonGuid {00000000-0000-0000-0000-000000000000}

    TargetUserName admbaltsupuser

    TargetDomainName HEADOFFICE.test.LV

    TargetLogonGuid {00000000-0000-0000-0000-000000000000}

    TargetServerName fileserver

    TargetInfo cifs/fileserver

    ProcessId 0x4

    ProcessName

    IpAddress 192.168.10.50

    IpPort 445
     
    MaksimMaksim3, Aug 20, 2025 at 7:34 AM
    #3
  4. A logon was attempted using explicit credentials, Event ID 4648

    Strange login attempt on pc

    Logon events that happen while you're away aren't necessarily malicious

    It's perfectly normal for a system to experience logon events despite no intrusion. You don't even need any third party programs installed for this to occur; Windows itself will generate logon events.

    For example, Windows comes configured out of the box with various tasks scheduled in Task Scheduler. When one of these tasks runs, it must be started in the context of a user account, even if that's something like the built-in SYSTEM account. This generates a logon event and is logged to the Security event log with event ID 4624.

    How to identify unwanted logons

    If you suspect unwanted use of your computer, then you need to look more closely at the events themselves. Specifically you should inspect the Logon Type field which distinguishes how the account was logged on. The possible types are:

    The logon types that are most suggestive of someone having gained interactive/remote access are 2, 7, 10, and 11.

    For any suspicious logon events, observe the Account Name and Account Domain fields as these will usually identify the name of the user that logged in.

    If your system has already been compromised, then unwanted logons may be taking place. However, if such logons are being attempted but are failing, these can be inspected by reviewing event ID 4625 in the Security log which indicates an attempted, but failed logon event. The Logon Type and other fields discussed above apply to these events as well. (Note that your system must be configured to log these events before they are captured in the Event Viewer.)

    More Information

     
    Twisty Impersonator, Aug 20, 2025 at 7:34 AM
    #4
Thema:

A logon was attempted using explicit credentials, Event ID 4648

Loading...
  1. A logon was attempted using explicit credentials, Event ID 4648 - Similar Threads - logon was attempted

  2. Logon Event Event ID 4648. Events only log during a successful remote desktop in to the...

    in Windows 10 Gaming
    Logon Event Event ID 4648. Events only log during a successful remote desktop in to the...: We have a computer that isn't allowed to be connected to the internet but we have it set up so that we can remote in to it to work on it. It is not connected to our domain at all but is still throwing this logon error despite no one trying to log in with this username. Here...
  3. Logon Event Event ID 4648. Events only log during a successful remote desktop in to the...

    in Windows 10 Software and Apps
    Logon Event Event ID 4648. Events only log during a successful remote desktop in to the...: We have a computer that isn't allowed to be connected to the internet but we have it set up so that we can remote in to it to work on it. It is not connected to our domain at all but is still throwing this logon error despite no one trying to log in with this username. Here...
  4. Logon Event Event ID 4648. Events only log during a successful remote desktop in to the...

    in AntiVirus, Firewalls and System Security
    Logon Event Event ID 4648. Events only log during a successful remote desktop in to the...: We have a computer that isn't allowed to be connected to the internet but we have it set up so that we can remote in to it to work on it. It is not connected to our domain at all but is still throwing this logon error despite no one trying to log in with this username. Here...
  5. Windows Hello - A logon was attempted using explicit credentials.

    in Windows Hello & Lockscreen
    Windows Hello - A logon was attempted using explicit credentials.: Hi all, For some reason my PIN and fingerprint credentials have stopped working. Whenever I try to login to my laptop using with them, it says "your credentials couldn't be verified" and I get this error message in the event log: A logon was attempted using explicit...
  6. Windows Hello - A logon was attempted using explicit credentials.

    in Windows 10 Gaming
    Windows Hello - A logon was attempted using explicit credentials.: Hi all, For some reason my PIN and fingerprint credentials have stopped working. Whenever I try to login to my laptop using with them, it says "your credentials couldn't be verified" and I get this error message in the event log: A logon was attempted using explicit...
  7. Windows Hello - A logon was attempted using explicit credentials.

    in Windows 10 Software and Apps
    Windows Hello - A logon was attempted using explicit credentials.: Hi all, For some reason my PIN and fingerprint credentials have stopped working. Whenever I try to login to my laptop using with them, it says "your credentials couldn't be verified" and I get this error message in the event log: A logon was attempted using explicit...
  8. Credentials Manager credentials were read multiple repeated attempts Event ID 5379

    in Windows 10 Software and Apps
    Credentials Manager credentials were read multiple repeated attempts Event ID 5379: Still having issues with Event ID 5379 and multiple other ones. Also "Special privileges assigned to new logon" Event ID 4672.Accompanied by the following symptoms:Complete lock up of my I/O, mouse, keyboard, and the "USB disconnected" sound.I can review Event Viewer and I...
  9. Credentials Manager credentials were read multiple repeated attempts Event ID 5379

    in Windows 10 BSOD Crashes and Debugging
    Credentials Manager credentials were read multiple repeated attempts Event ID 5379: Still having issues with Event ID 5379 and multiple other ones. Also "Special privileges assigned to new logon" Event ID 4672.Accompanied by the following symptoms:Complete lock up of my I/O, mouse, keyboard, and the "USB disconnected" sound.I can review Event Viewer and I...
  10. Logon Event IDs Explanations

    in AntiVirus, Firewalls and System Security
    Logon Event IDs Explanations: Hi, I'm a non-dev person and would like some answers regarding Event Viewer in Windows 10. I wanted to keep tabs on if my PC was logged in during my absence. I found that Event ID 4624 shows the successful logins. But when I filter the ID, it turns out that several events...