| Previous | Next |
| SEC_E_TOO_MANY_PRINCIPALS | SEC_E_PKINIT_NAME_MISMATCH |
SEC_E_NO_PA_DATA
SEC_E_NO_PA_DATA signals this condition: Kerberos could not obtain the preauthentication data needed to select an encryption type. The client or security package expected KDC preauthentication hint data but did not receive it. This is usually an interoperability or policy mismatch in the Kerberos exchange.
What to check
- Inspect KDC and client event logs for the requested principal, preauthentication method, and encryption types.
- Check whether a smart-card or certificate-based path changed the expected preauthentication flow.
- Avoid enabling legacy encryption types merely to suppress the status; identify the package or policy mismatch first.
Microsoft: Kerberos authentication troubleshooting
Looking for a different code? Search another status or error code.
