Kerberos: The target account name is incorrect

PDQ Deploy and/or PDQ Inventory report "Kerberos: The target account name is incorrect" when scanning or deploying to a computer.

PDQ Deploy error details showing "Kerberos: The target account name is incorrect" with Computer Name and Effective Host Name fields highlighted.

Windows Event Viewer displaying a Security-Kerberos Event ID 4 entry with a highlighted KRB_AP_ERR_MODIFIED error message.

What this error means

The Windows and Kerberos native error "KRB_AP_ERR_MODIFIED" means PDQ Deploy or PDQ Inventory connected to the target computer through Kerberos, but the computer's identity verification failed. Windows logs this on the PDQ server in the System event log with event ID 4 and source Security-Kerberos; review that log entry to see which computer the software was trying to reach.

An anology

Kerberos is like knocking on Bob's door and expecting Bob to answer. If someone else answers and claims to be Bob, Kerberos doesn't trust the response and refuses to continue because the identity of the computer doesn't match what was expected.

Common cause: DNS misconfiguration

This error is typically caused by a misconfigured DNS environment, such as stale DNS entries or multiple DNS records pointing to the same IP address. PDQ software connects to computers over SMB, and SMB authentication relies on Kerberos or NTLM, both of which depend on DNS resolving correctly.

Was this article helpful?