This might be a long shot. In our environment, we have ~600 Macs in Active Directory.
In less than 2 hours, our splunk auditing logs are reporting over 16,000 events of "kerberos pre-authentication failed". Microsoft eventcode 4771 , failure 0x18. The log is going against the computer object, not the user.
I know for Windows machines, they automatically contact active directory and change their computer passwords. I'm wondering if the Macs are failing to do so and are somehow generating these errors. Any Active Directory and Mac experts out there that have any insight?
