#group-management
5 articles
Windows Events5
Windows Event ID 4764 – Microsoft-Windows-Security-Auditing: Group Member Added
Event ID 4764 logs when a user account is added to a security-enabled group in Active Directory or local system, providing audit trail for group membership changes.
Windows Event ID 4734 – Microsoft-Windows-Security-Auditing: Security-Enabled Local Group Member Removed
Event ID 4734 fires when a member is removed from a security-enabled local group. This security audit event tracks group membership changes for compliance and security monitoring purposes.
Windows Event ID 4732 – Microsoft-Windows-Security-Auditing: A Member Was Added to a Security-Enabled Local Group
Event ID 4732 fires when a user or computer account is added to a security-enabled local group. This security audit event helps administrators track group membership changes for compliance and security monitoring.
Windows Event ID 4731 – Microsoft-Windows-Security-Auditing: Security-Enabled Local Group Member Added
Event ID 4731 fires when a member is added to a security-enabled local group on Windows systems. This security audit event tracks local group membership changes for compliance and security monitoring.
Windows Event ID 4733 – Microsoft-Windows-Security-Auditing: Security Group Member Removed
Event ID 4733 logs when a user or computer account is removed from a security group in Active Directory, providing critical audit information for access control changes.