Event ID 4621 is generated by the Local Security Authority (LSA) subsystem whenever the Administrator Recovery Agent policy undergoes modification. This policy defines which certificates and users can serve as recovery agents for EFS-encrypted files within the current security scope.
Recovery agents represent a critical component of enterprise EFS deployments. When users encrypt files with EFS, Windows automatically adds the current recovery agent certificates to the encrypted file's metadata. If a user loses their private key or leaves the organization, designated recovery agents can decrypt the files using their recovery certificates.
The event captures several important details: the subject and issuer of recovery agent certificates, whether certificates were added or removed, and the security identifier of the account making the change. This information proves invaluable during security audits and compliance reviews.
In domain environments, this event commonly appears when Group Policy processes EFS recovery settings. Local administrators might also trigger this event when manually configuring recovery agents through the Local Security Policy snap-in or when importing new recovery certificates through the Certificates MMC console.