Windows EventInformation
Windows Event ID 4936 – Microsoft-Windows-Security-Auditing: User Account Management Policy Change
Event ID 4936 logs changes to user account management policies in Active Directory. This security audit event fires when administrators modify password policies, account lockout settings, or Kerberos authentication policies.