#password-management
3 articles
Windows Events3
Windows Event ID 4782 – Security: User Account Password Changed
Event ID 4782 logs when a user account password is changed by an administrator or through administrative tools. This security audit event tracks password modifications for compliance and security monitoring purposes.
Windows Event ID 4724 – Microsoft-Windows-Security-Auditing: User Account Password Reset by Administrator
Event ID 4724 logs when an administrator resets another user's password in Active Directory or local accounts, providing critical security audit trail for password management activities.

Windows Event ID 4723 – Microsoft-Windows-Security-Auditing: User Account Password Change Attempt
Event ID 4723 logs when a user attempts to change another user's password. This security audit event tracks administrative password reset operations and helps monitor unauthorized password modifications across Windows domains.