Windows Events — Event ID Reference & Troubleshooting
Windows Event ID 4758 – Microsoft-Windows-Security-Auditing: User Account Enabled
Event ID 4758 fires when a user account is enabled in Active Directory or local SAM database. This security audit event tracks account state changes for compliance and security monitoring purposes.
Windows Event ID 4757 – Microsoft-Windows-Security-Auditing: Universal Security Group Member Removed
Event ID 4757 fires when a member is removed from a universal security group in Active Directory. This audit event tracks group membership changes for security compliance and access control monitoring.
Windows Event ID 4756 – Microsoft-Windows-Security-Auditing: Universal Security Group Member Added
Event ID 4756 fires when a member is added to a universal security group in Active Directory. This security audit event tracks group membership changes for compliance and security monitoring.
Windows Event ID 4755 – Security: User Account Enabled
Event ID 4755 logs when a user account is enabled in Active Directory or local security database. This security audit event tracks account management activities for compliance and monitoring purposes.
Windows Event ID 4754 – Microsoft-Windows-Security-Auditing: Security-Enabled Universal Group Member Added
Event ID 4754 fires when a member is added to a security-enabled universal group in Active Directory. This audit event tracks group membership changes for compliance and security monitoring.
Windows Event ID 4753 – Microsoft-Windows-Security-Auditing: Security-Enabled Global Group Member Removed
Event ID 4753 logs when a member is removed from a security-enabled global group in Active Directory. This security audit event tracks group membership changes for compliance and security monitoring.
Windows Event ID 4752 – Microsoft-Windows-Security-Auditing: A Member Was Added to a Security-Disabled Global Group
Event ID 4752 fires when a user or computer account is added to a security-disabled global group in Active Directory, providing audit trail for group membership changes.
Windows Event ID 4751 – Security: Computer Account Added to Security-Enabled Global Group
Event ID 4751 fires when a computer account is added to a security-enabled global group in Active Directory. This security audit event tracks group membership changes for computer objects.
Windows Event ID 4750 – Microsoft-Windows-Security-Auditing: Computer Account Password Changed
Event ID 4750 logs when a computer account password is changed in Active Directory. This security audit event tracks machine account password updates, typically occurring every 30 days automatically or during manual resets.
Windows Event ID 4749 – Microsoft-Windows-Security-Auditing: Security-Enabled Global Group Deleted
Event ID 4749 logs when a security-enabled global group is deleted from Active Directory. This audit event helps track group management changes and potential security risks.
Windows Event ID 4748 – Microsoft-Windows-Security-Auditing: Computer Account Deleted
Event ID 4748 fires when a computer account is deleted from Active Directory. This security audit event tracks machine account removal for compliance and security monitoring purposes.
Windows Event ID 4747 – Security: Computer Account Password Changed
Event ID 4747 indicates a computer account password has been changed in Active Directory. This security audit event fires when domain controllers update machine account passwords during normal operations or administrative actions.
Windows Event ID 4746 – Microsoft-Windows-Security-Auditing: Computer Account Deleted
Event ID 4746 records when a computer account is deleted from Active Directory. This security audit event tracks administrative actions that remove machine accounts from the domain.
Windows Event ID 4745 – Microsoft-Windows-Security-Auditing: Computer Account Created
Event ID 4745 logs when a computer account is created in Active Directory. This security audit event tracks domain computer additions for compliance and security monitoring purposes.
Windows Event ID 4744 – Microsoft-Windows-Security-Auditing: Computer Account Created
Event ID 4744 logs when a computer account is created in Active Directory. This security audit event tracks domain computer additions for compliance and security monitoring purposes.
Windows Event ID 4743 – Microsoft-Windows-Security-Auditing: Computer Account Changed
Event ID 4743 logs when a computer account is modified in Active Directory, tracking changes to computer objects including attributes, group memberships, and security settings.
Windows Event ID 4742 – Microsoft-Windows-Security-Auditing: Computer Account Changed
Event ID 4742 logs when a computer account is modified in Active Directory. This security audit event tracks changes to computer object attributes, group memberships, and account properties for compliance monitoring.
Windows Event ID 4741 – Microsoft-Windows-Security-Auditing: Computer Account Created
Event ID 4741 logs when a computer account is created in Active Directory. This security audit event tracks domain join operations and computer object creation for compliance monitoring.
Windows Event ID 4739 – Microsoft-Windows-Security-Auditing: User Account Changed
Event ID 4739 logs when a user account is modified in Active Directory or local security database, capturing changes to account properties, group memberships, and security settings for audit compliance.
Windows Event ID 4738 – Microsoft-Windows-Security-Auditing: User Account Changed
Event ID 4738 fires when a user account is modified in Active Directory or local SAM database. Critical for security auditing and tracking unauthorized account changes.
Windows Event ID 4737 – Microsoft-Windows-Security-Auditing: Security-Enabled Global Group Changed
Event ID 4737 fires when a security-enabled global group is modified in Active Directory, tracking changes to group properties, membership, or attributes for security auditing purposes.