<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic High volume of failed logins (0xC000006A) toward Domain Controllers in General Discussion</title>
    <link>https://community.netapp.com/t5/General-Discussion/High-volume-of-failed-logins-0xC000006A-toward-Domain-Controllers/m-p/467083#M1678</link>
    <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;we are experiencing an unusual behavior in our environment and would like to understand if anyone has encountered a similar situation or can suggest possible mitigations.&lt;/P&gt;&lt;P&gt;Through our SIEM, we are receiving a large number (hundreds/thousands) of failed login notifications against our Domain Controllers, with error code&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;0xC000006A&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(bad password).&lt;BR /&gt;These attempts appear to originate from our NetApp servers and are related to user access to network shares.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Questions:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Have you ever experienced similar behavior in NetApp/ Active Directory environments?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Are there any configurations or mechanisms to prevent these authentication loops (e.g., credential cache handling, session timeouts, specific GPOs)?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Are there best practices or tools to quickly identify the exact source of these requests?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Have you implemented effective mitigation strategies to reduce SIEM noise without losing relevant events?&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Any suggestions or shared experiences would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
    <pubDate>Thu, 07 May 2026 07:18:58 GMT</pubDate>
    <dc:creator>lozivi</dc:creator>
    <dc:date>2026-05-07T07:18:58Z</dc:date>
    <item>
      <title>High volume of failed logins (0xC000006A) toward Domain Controllers</title>
      <link>https://community.netapp.com/t5/General-Discussion/High-volume-of-failed-logins-0xC000006A-toward-Domain-Controllers/m-p/467083#M1678</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;we are experiencing an unusual behavior in our environment and would like to understand if anyone has encountered a similar situation or can suggest possible mitigations.&lt;/P&gt;&lt;P&gt;Through our SIEM, we are receiving a large number (hundreds/thousands) of failed login notifications against our Domain Controllers, with error code&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;0xC000006A&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(bad password).&lt;BR /&gt;These attempts appear to originate from our NetApp servers and are related to user access to network shares.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Questions:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Have you ever experienced similar behavior in NetApp/ Active Directory environments?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Are there any configurations or mechanisms to prevent these authentication loops (e.g., credential cache handling, session timeouts, specific GPOs)?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Are there best practices or tools to quickly identify the exact source of these requests?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Have you implemented effective mitigation strategies to reduce SIEM noise without losing relevant events?&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Any suggestions or shared experiences would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Thu, 07 May 2026 07:18:58 GMT</pubDate>
      <guid>https://community.netapp.com/t5/General-Discussion/High-volume-of-failed-logins-0xC000006A-toward-Domain-Controllers/m-p/467083#M1678</guid>
      <dc:creator>lozivi</dc:creator>
      <dc:date>2026-05-07T07:18:58Z</dc:date>
    </item>
    <item>
      <title>Re: High volume of failed logins (0xC000006A) toward Domain Controllers</title>
      <link>https://community.netapp.com/t5/General-Discussion/High-volume-of-failed-logins-0xC000006A-toward-Domain-Controllers/m-p/467100#M1679</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sound like the probable cause is "&lt;EM&gt;a&amp;nbsp;bad password (possibly correct when initially stored, but rendered invalid by a subsequent password change) is being presented during an NTLM authentication attempt from the CIFS client&lt;/EM&gt;". You would need to run a secd trace in diag mode on the ONTAP cluster to determine the CIFS client.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://kb.netapp.com/on-prem/ontap/da/NAS/NAS-KBs/DC_denies_log_on_for_a_user_due_to_bad_password_with_ONTAP_CIFS_as_client" target="_blank"&gt;DC denies logon for a user due to bad password, with ONTAP CIFS as client - NetApp Knowledge Base&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would try to identify the CIFS client/clients causing the issue first to determine if there's a method to mitigate the issue re-occurring in your environment&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/Matt&lt;/P&gt;</description>
      <pubDate>Sun, 10 May 2026 23:56:44 GMT</pubDate>
      <guid>https://community.netapp.com/t5/General-Discussion/High-volume-of-failed-logins-0xC000006A-toward-Domain-Controllers/m-p/467100#M1679</guid>
      <dc:creator>mbeattie</dc:creator>
      <dc:date>2026-05-10T23:56:44Z</dc:date>
    </item>
  </channel>
</rss>

