ANAVEM
Languagefr

#group-management

5 articles

Windows Events5

Windows Security Event Viewer displaying Event ID 4764 group membership changes on a SOC monitoring dashboard
Event 4764
Microsoft-Windows-Security-Auditing
Windows EventInformation

Windows Event ID 4764 – Microsoft-Windows-Security-Auditing: Group Member Added

Event ID 4764 logs when a user account is added to a security-enabled group in Active Directory or local system, providing audit trail for group membership changes.

March 1812 min
Windows security monitoring dashboard showing Event Viewer with security audit logs for group management events
Event 4734
Microsoft-Windows-Security-Auditing
Windows EventInformation

Windows Event ID 4734 – Microsoft-Windows-Security-Auditing: Security-Enabled Local Group Member Removed

Event ID 4734 fires when a member is removed from a security-enabled local group. This security audit event tracks group membership changes for compliance and security monitoring purposes.

March 1812 min
Security analyst reviewing Windows Event ID 4732 group membership changes on monitoring dashboard
Event 4732
Microsoft-Windows-Security-Auditing
Windows EventInformation

Windows Event ID 4732 – Microsoft-Windows-Security-Auditing: A Member Was Added to a Security-Enabled Local Group

Event ID 4732 fires when a user or computer account is added to a security-enabled local group. This security audit event helps administrators track group membership changes for compliance and security monitoring.

March 189 min
Windows Event Viewer Security log displaying Event ID 4731 group membership audit events on a cybersecurity monitoring dashboard
Event 4731
Microsoft-Windows-Security-Auditing
Windows EventInformation

Windows Event ID 4731 – Microsoft-Windows-Security-Auditing: Security-Enabled Local Group Member Added

Event ID 4731 fires when a member is added to a security-enabled local group on Windows systems. This security audit event tracks local group membership changes for compliance and security monitoring.

March 189 min
Windows security monitoring dashboard showing Event Viewer with security audit logs in a professional SOC environment
Event 4733
Microsoft-Windows-Security-Auditing
Windows EventInformation

Windows Event ID 4733 – Microsoft-Windows-Security-Auditing: Security Group Member Removed

Event ID 4733 logs when a user or computer account is removed from a security group in Active Directory, providing critical audit information for access control changes.

March 1812 min