| Previous | Next |
| SEC_E_KDC_INVALID_REQUEST | SEC_E_KDC_UNKNOWN_ETYPE |
SEC_E_KDC_UNABLE_TO_REFER
SEC_E_KDC_UNABLE_TO_REFER signals this condition: The KDC could not create the referral needed for the requested service. Kerberos could not refer the client to the domain or realm that should handle the target service. This can occur with cross-domain or cross-forest service access when DNS, trusts, or SPN ownership do not describe a valid path.
What to check
- Verify the target service FQDN and its SPN owner.
- Check the relevant domain and forest trust topology, including which realm owns the target account.
- Review domain-controller logs for referral and trust errors before changing delegation settings.
Microsoft: Kerberos authentication troubleshooting
Looking for a different code? Search another status or error code.
