Windows EventInformation
Windows Event ID 4738 – Microsoft-Windows-Security-Auditing: User Account Changed
Event ID 4738 fires when a user account is modified in Active Directory or local SAM database. Critical for security auditing and tracking unauthorized account changes.