Anavem
Languagefr

Windows Events — Event ID Reference & Troubleshooting

Complete Windows Event ID reference. Understand every system event, its causes and solutions.

389 events
Windows Event ID 4755 – Security: User Account Enabled
4755InformationSecurity

Windows Event ID 4755 – Security: User Account Enabled

Event ID 4755 logs when a user account is enabled in Active Directory or local security database. This security audit event tracks account management activities for compliance and monitoring purposes.

Mar 18, 20264212m
Windows Event ID 4754 – Microsoft-Windows-Security-Auditing: Security-Enabled Universal Group Member Added
4754InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 4754 – Microsoft-Windows-Security-Auditing: Security-Enabled Universal Group Member Added

Event ID 4754 fires when a member is added to a security-enabled universal group in Active Directory. This audit event tracks group membership changes for compliance and security monitoring.

Mar 18, 20264012m
Windows Event ID 4753 – Microsoft-Windows-Security-Auditing: Security-Enabled Global Group Member Removed
4753InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 4753 – Microsoft-Windows-Security-Auditing: Security-Enabled Global Group Member Removed

Event ID 4753 logs when a member is removed from a security-enabled global group in Active Directory. This security audit event tracks group membership changes for compliance and security monitoring.

Mar 18, 20264612m
Windows Event ID 4752 – Microsoft-Windows-Security-Auditing: A Member Was Added to a Security-Disabled Global Group
4752InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 4752 – Microsoft-Windows-Security-Auditing: A Member Was Added to a Security-Disabled Global Group

Event ID 4752 fires when a user or computer account is added to a security-disabled global group in Active Directory, providing audit trail for group membership changes.

Mar 18, 2026409m
Windows Event ID 4751 – Security: Computer Account Added to Security-Enabled Global Group
4751InformationSecurity

Windows Event ID 4751 – Security: Computer Account Added to Security-Enabled Global Group

Event ID 4751 fires when a computer account is added to a security-enabled global group in Active Directory. This security audit event tracks group membership changes for computer objects.

Mar 18, 2026509m
Windows Event ID 4750 – Microsoft-Windows-Security-Auditing: Computer Account Password Changed
4750InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 4750 – Microsoft-Windows-Security-Auditing: Computer Account Password Changed

Event ID 4750 logs when a computer account password is changed in Active Directory. This security audit event tracks machine account password updates, typically occurring every 30 days automatically or during manual resets.

Mar 18, 20264212m
Windows Event ID 4749 – Microsoft-Windows-Security-Auditing: Security-Enabled Global Group Deleted
4749InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 4749 – Microsoft-Windows-Security-Auditing: Security-Enabled Global Group Deleted

Event ID 4749 logs when a security-enabled global group is deleted from Active Directory. This audit event helps track group management changes and potential security risks.

Mar 18, 2026429m
Windows Event ID 4748 – Microsoft-Windows-Security-Auditing: Computer Account Deleted
4748InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 4748 – Microsoft-Windows-Security-Auditing: Computer Account Deleted

Event ID 4748 fires when a computer account is deleted from Active Directory. This security audit event tracks machine account removal for compliance and security monitoring purposes.

Mar 18, 2026469m
Windows Event ID 4747 – Security: Computer Account Password Changed
4747InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 4747 – Security: Computer Account Password Changed

Event ID 4747 indicates a computer account password has been changed in Active Directory. This security audit event fires when domain controllers update machine account passwords during normal operations or administrative actions.

Mar 18, 2026469m
Windows Event ID 4746 – Microsoft-Windows-Security-Auditing: Computer Account Deleted
4746InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 4746 – Microsoft-Windows-Security-Auditing: Computer Account Deleted

Event ID 4746 records when a computer account is deleted from Active Directory. This security audit event tracks administrative actions that remove machine accounts from the domain.

Mar 18, 2026459m
Windows Event ID 4745 – Microsoft-Windows-Security-Auditing: Computer Account Created
4745InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 4745 – Microsoft-Windows-Security-Auditing: Computer Account Created

Event ID 4745 logs when a computer account is created in Active Directory. This security audit event tracks domain computer additions for compliance and security monitoring purposes.

Mar 18, 2026499m
Windows Event ID 4744 – Microsoft-Windows-Security-Auditing: Computer Account Created
4744InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 4744 – Microsoft-Windows-Security-Auditing: Computer Account Created

Event ID 4744 logs when a computer account is created in Active Directory. This security audit event tracks domain computer additions for compliance and security monitoring purposes.

Mar 18, 20264412m
Windows Event ID 4743 – Microsoft-Windows-Security-Auditing: Computer Account Changed
4743InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 4743 – Microsoft-Windows-Security-Auditing: Computer Account Changed

Event ID 4743 logs when a computer account is modified in Active Directory, tracking changes to computer objects including attributes, group memberships, and security settings.

Mar 18, 2026419m
Windows Event ID 4742 – Microsoft-Windows-Security-Auditing: Computer Account Changed
4742InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 4742 – Microsoft-Windows-Security-Auditing: Computer Account Changed

Event ID 4742 logs when a computer account is modified in Active Directory. This security audit event tracks changes to computer object attributes, group memberships, and account properties for compliance monitoring.

Mar 18, 20265512m
Windows Event ID 4741 – Microsoft-Windows-Security-Auditing: Computer Account Created
4741InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 4741 – Microsoft-Windows-Security-Auditing: Computer Account Created

Event ID 4741 logs when a computer account is created in Active Directory. This security audit event tracks domain join operations and computer object creation for compliance monitoring.

Mar 18, 2026469m
Windows Event ID 4739 – Microsoft-Windows-Security-Auditing: User Account Changed
4739InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 4739 – Microsoft-Windows-Security-Auditing: User Account Changed

Event ID 4739 logs when a user account is modified in Active Directory or local security database, capturing changes to account properties, group memberships, and security settings for audit compliance.

Mar 18, 2026549m
Windows Event ID 4738 – Microsoft-Windows-Security-Auditing: User Account Changed
4738InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 4738 – Microsoft-Windows-Security-Auditing: User Account Changed

Event ID 4738 fires when a user account is modified in Active Directory or local SAM database. Critical for security auditing and tracking unauthorized account changes.

Mar 18, 20266412m
Windows Event ID 4737 – Microsoft-Windows-Security-Auditing: Security-Enabled Global Group Changed
4737InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 4737 – Microsoft-Windows-Security-Auditing: Security-Enabled Global Group Changed

Event ID 4737 fires when a security-enabled global group is modified in Active Directory, tracking changes to group properties, membership, or attributes for security auditing purposes.

Mar 18, 2026559m