#user-account-management
2 articles
Windows Events2
Event 4739
Microsoft-Windows-Security-Auditing
Windows EventInformation
Windows Event ID 4739 – Microsoft-Windows-Security-Auditing: User Account Changed
Event ID 4739 logs when a user account is modified in Active Directory or local security database, capturing changes to account properties, group memberships, and security settings for audit compliance.
March 189 min
Event 4738
Microsoft-Windows-Security-Auditing
Windows EventInformation
Windows Event ID 4738 – Microsoft-Windows-Security-Auditing: User Account Changed
Event ID 4738 fires when a user account is modified in Active Directory or local SAM database. Critical for security auditing and tracking unauthorized account changes.
March 1812 min