mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-12 21:37:22 +00:00
Merge branch 'main' into metasecurity3
This commit is contained in:
commit
372de67cd8
@ -2,7 +2,7 @@
|
||||
title: 4671(-) An application attempted to access a blocked ordinal through the TBS. (Windows 10)
|
||||
description: Describes security event 4671(-) An application attempted to access a blocked ordinal through the TBS.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4671(-): An application attempted to access a blocked ordinal through the TBS.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4672(S) Special privileges assigned to new logon. (Windows 10)
|
||||
description: Describes security event 4672(S) Special privileges assigned to new logon.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4672(S): Special privileges assigned to new logon.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4673(S, F) A privileged service was called. (Windows 10)
|
||||
description: Describes security event 4673(S, F) A privileged service was called. This event is generated for an attempt to perform privileged system service operations.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4673(S, F): A privileged service was called.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4674(S, F) An operation was attempted on a privileged object. (Windows 10)
|
||||
description: Describes security event 4674(S, F) An operation was attempted on a privileged object.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4674(S, F): An operation was attempted on a privileged object.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4675(S) SIDs were filtered. (Windows 10)
|
||||
description: Describes security event 4675(S) SIDs were filtered. This event is generated when SIDs were filtered for a specific Active Directory trust.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4675(S): SIDs were filtered.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4688(S) A new process has been created. (Windows 10)
|
||||
description: Describes security event 4688(S) A new process has been created. This event is generated when a new process starts.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 01/24/2022
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4688(S): A new process has been created.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4689(S) A process has exited. (Windows 10)
|
||||
description: Describes security event 4689(S) A process has exited. This event is generates when a process exits.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4689(S): A process has exited.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4690(S) An attempt was made to duplicate a handle to an object. (Windows 10)
|
||||
description: Describes security event 4690(S) An attempt was made to duplicate a handle to an object.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4690(S): An attempt was made to duplicate a handle to an object.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4691(S) Indirect access to an object was requested. (Windows 10)
|
||||
description: Describes security event 4691(S) Indirect access to an object was requested.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4691(S): Indirect access to an object was requested.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4692(S, F) Backup of data protection master key was attempted. (Windows 10)
|
||||
description: Describes security event 4692(S, F) Backup of data protection master key was attempted.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4692(S, F): Backup of data protection master key was attempted.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4693(S, F) Recovery of data protection master key was attempted. (Windows 10)
|
||||
description: Describes security event 4693(S, F) Recovery of data protection master key was attempted.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4693(S, F): Recovery of data protection master key was attempted.
|
||||
@ -25,7 +25,7 @@ ms.technology: windows-sec
|
||||
|
||||
This event generates every time that recovery is attempted for a [DPAPI](/previous-versions/ms995355(v=msdn.10)) Master Key.
|
||||
|
||||
While unprotecting data, if DPAPI cannot use the Master Key protected by the user's password, it sends the backup Master Key to a domain controller by using a mutually authenticated and privacy protected RPC call. The domain controller then decrypts the Master Key with its private key and sends it back to the client by using the same protected RPC call. This protected RPC call is used to ensure that no one listening on the network can get the Master Key.
|
||||
While unprotecting data, if DPAPI can't use the Master Key protected by the user's password, it sends the backup Master Key to a domain controller by using a mutually authenticated and privacy protected RPC call. The domain controller then decrypts the Master Key with its private key and sends it back to the client by using the same protected RPC call. This protected RPC call is used to ensure that no one listening on the network can get the Master Key.
|
||||
|
||||
This event generates on domain controllers, member servers, and workstations.
|
||||
|
||||
@ -79,9 +79,9 @@ Failure event generates when a Master Key restore operation fails for some reaso
|
||||
|
||||
**Subject:**
|
||||
|
||||
- **Security ID** \[Type = SID\]**:** SID of account that requested the “recover” operation. Event Viewer automatically tries to resolve SIDs and show the account name. If the SID cannot be resolved, you will see the source data in the event.
|
||||
- **Security ID** \[Type = SID\]**:** SID of account that requested the “recover” operation. Event Viewer automatically tries to resolve SIDs and show the account name. If the SID can't be resolved, you'll see the source data in the event.
|
||||
|
||||
> **Note** A **security identifier (SID)** is a unique value of variable length used to identify a trustee (security principal). Each account has a unique SID that is issued by an authority, such as an Active Directory domain controller, and stored in a security database. Each time a user logs on, the system retrieves the SID for that user from the database and places it in the access token for that user. The system uses the SID in the access token to identify the user in all subsequent interactions with Windows security. When a SID has been used as the unique identifier for a user or group, it cannot ever be used again to identify another user or group. For more information about SIDs, see [Security identifiers](/windows/access-protection/access-control/security-identifiers).
|
||||
> **Note** A **security identifier (SID)** is a unique value of variable length used to identify a trustee (security principal). Each account has a unique SID that is issued by an authority, such as an Active Directory domain controller, and stored in a security database. Each time a user logs on, the system retrieves the SID for that user from the database and places it in the access token for that user. The system uses the SID in the access token to identify the user in all subsequent interactions with Windows security. When a SID has been used as the unique identifier for a user or group, it can't ever be used again to identify another user or group. For more information about SIDs, see [Security identifiers](/windows/access-protection/access-control/security-identifiers).
|
||||
|
||||
- **Account Name** \[Type = UnicodeString\]**:** the name of the account that requested the “recover” operation.
|
||||
|
||||
@ -101,13 +101,13 @@ Failure event generates when a Master Key restore operation fails for some reaso
|
||||
|
||||
**Key Information:**
|
||||
|
||||
- **Key Identifier** \[Type = UnicodeString\]**:** unique identifier of a master key which was recovered. The Master Key is used, with some additional data, to generate an actual symmetric session key to encrypt\\decrypt the data using DPAPI. All of user's Master Keys are located in user profile -> %APPDATA%\\Roaming\\Microsoft\\Windows\\Protect\\%SID% folder. The name of every Master Key file is it’s ID.
|
||||
- **Key Identifier** \[Type = UnicodeString\]**:** unique identifier of a master key which was recovered. The Master Key is used, with some additional data, to generate an actual symmetric session key to encrypt\\decrypt the data using DPAPI. All of user's Master Keys are located in user profile -> %APPDATA%\\Roaming\\Microsoft\\Windows\\Protect\\%SID% folder. The name of every Master Key file is its ID.
|
||||
|
||||
- **Recovery Server** \[Type = UnicodeString\]: the name (typically – DNS name) of the computer that you contacted to recover your Master Key. For domain joined machines, it’s typically a name of a domain controller.
|
||||
|
||||
> **Note** In this event Recovery Server field contains information from Recovery Reason field.
|
||||
|
||||
- **Recovery Key ID** \[Type = UnicodeString\]**:** unique identifier of a recovery key. The recovery key is generated when a user chooses to create a Password Reset Disk (PRD) from the user's Control Panel or when first Master Key is generated. First, DPAPI generates a RSA public/private key pair, which is the recovery key. In this field you will see unique Recovery key ID which was used for Master key recovery operation. This parameter might not be captured in the event, and in that case will be empty.
|
||||
- **Recovery Key ID** \[Type = UnicodeString\]**:** unique identifier of a recovery key. The recovery key is generated when a user chooses to create a Password Reset Disk (PRD) from the user's Control Panel or when first Master Key is generated. First, DPAPI generates an RSA public/private key pair, which is the recovery key. In this field you'll see unique Recovery key ID which was used for Master key recovery operation. This parameter might not be captured in the event, and in that case will be empty.
|
||||
|
||||
- **Recovery Reason** \[Type = HexInt32\]: hexadecimal code of recovery reason.
|
||||
|
||||
@ -121,7 +121,7 @@ Failure event generates when a Master Key restore operation fails for some reaso
|
||||
|
||||
For 4693(S, F): Recovery of data protection master key was attempted.
|
||||
|
||||
- This event is typically an informational event and it is difficult to detect any malicious activity using this event. It’s mainly used for DPAPI troubleshooting.
|
||||
- This event is typically an informational event and it's difficult to detect any malicious activity using this event. It’s mainly used for DPAPI troubleshooting.
|
||||
|
||||
- For domain joined computers, **Recovery Reason** should typically be a domain controller DNS name.
|
||||
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4694(S, F) Protection of auditable protected data was attempted. (Windows 10)
|
||||
description: Describes security event 4694(S, F) Protection of auditable protected data was attempted.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4694(S, F): Protection of auditable protected data was attempted.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4695(S, F) Unprotection of auditable protected data was attempted. (Windows 10)
|
||||
description: Describes security event 4695(S, F) Unprotection of auditable protected data was attempted.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4695(S, F): Unprotection of auditable protected data was attempted.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4696(S) A primary token was assigned to process. (Windows 10)
|
||||
description: Describes security event 4696(S) A primary token was assigned to process.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4696(S): A primary token was assigned to process.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4697(S) A service was installed in the system. (Windows 10)
|
||||
description: Describes security event 4697(S) A service was installed in the system.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4697(S): A service was installed in the system.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4698(S) A scheduled task was created. (Windows 10)
|
||||
description: Describes security event 4698(S) A scheduled task was created. This event is generated when a scheduled task is created.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4698(S): A scheduled task was created.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4699(S) A scheduled task was deleted. (Windows 10)
|
||||
description: Describes security event 4699(S) A scheduled task was deleted. This event is generated every time a scheduled task is deleted.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4699(S): A scheduled task was deleted.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4700(S) A scheduled task was enabled. (Windows 10)
|
||||
description: Describes security event 4700(S) A scheduled task was enabled. This event is generated every time a scheduled task is enabled.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4700(S): A scheduled task was enabled.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4701(S) A scheduled task was disabled. (Windows 10)
|
||||
description: Describes security event 4701(S) A scheduled task was disabled. This event is generated every time a scheduled task is disabled.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4701(S): A scheduled task was disabled.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4702(S) A scheduled task was updated. (Windows 10)
|
||||
description: Describes security event 4702(S) A scheduled task was updated. This event is generated when a scheduled task is updated/changed.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4702(S): A scheduled task was updated.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4703(S) A user right was adjusted. (Windows 10)
|
||||
description: Describes security event 4703(S) A user right was adjusted. This event is generated when token privileges are enabled or disabled for a specific account.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4703(S): A user right was adjusted.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4704(S) A user right was assigned. (Windows 10)
|
||||
description: Describes security event 4704(S) A user right was assigned. This event is generated when a user right is assigned to an account.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4704(S): A user right was assigned.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4705(S) A user right was removed. (Windows 10)
|
||||
description: Describes security event 4705(S) A user right was removed. This event is generated when a user right is removed from an account.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4705(S): A user right was removed.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4706(S) A new trust was created to a domain. (Windows 10)
|
||||
description: Describes security event 4706(S) A new trust was created to a domain. This event is generated when a new trust is created for a domain.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4706(S): A new trust was created to a domain.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4707(S) A trust to a domain was removed. (Windows 10)
|
||||
description: Describes security event 4707(S) A trust to a domain was removed. This event is generated when a domain trust is removed.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4707(S): A trust to a domain was removed.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4713(S) Kerberos policy was changed. (Windows 10)
|
||||
description: Describes security event 4713(S) Kerberos policy was changed. This event is generated when Kerberos policy is changed.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4713(S): Kerberos policy was changed.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4714(S) Encrypted data recovery policy was changed. (Windows 10)
|
||||
description: Describes security event 4714(S) Encrypted data recovery policy was changed.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4714(S): Encrypted data recovery policy was changed.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4715(S) The audit policy (SACL) on an object was changed. (Windows 10)
|
||||
description: Describes security event 4715(S) The audit policy (SACL) on an object was changed.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4715(S): The audit policy (SACL) on an object was changed.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4716(S) Trusted domain information was modified. (Windows 10)
|
||||
description: Describes security event 4716(S) Trusted domain information was modified.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4716(S): Trusted domain information was modified.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4717(S) System security access was granted to an account. (Windows 10)
|
||||
description: Describes security event 4717(S) System security access was granted to an account.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4717(S): System security access was granted to an account.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4718(S) System security access was removed from an account. (Windows 10)
|
||||
description: Describes security event 4718(S) System security access was removed from an account.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4718(S): System security access was removed from an account.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4719(S) System audit policy was changed. (Windows 10)
|
||||
description: Describes security event 4719(S) System audit policy was changed. This event is generated when the computer audit policy changes.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4719(S): System audit policy was changed.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4720(S) A user account was created. (Windows 10)
|
||||
description: Describes security event 4720(S) A user account was created. This event is generated a user object is created.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4720(S): A user account was created.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4722(S) A user account was enabled. (Windows 10)
|
||||
description: Describes security event 4722(S) A user account was enabled. This event is generated when a user or computer object is enabled.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4722(S): A user account was enabled.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4723(S, F) An attempt was made to change an account's password. (Windows 10)
|
||||
description: Describes security event 4723(S, F) An attempt was made to change an account's password.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4723(S, F): An attempt was made to change an account's password.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4724(S, F) An attempt was made to reset an account's password. (Windows 10)
|
||||
description: Describes security event 4724(S, F) An attempt was made to reset an account's password.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4724(S, F): An attempt was made to reset an account's password.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4725(S) A user account was disabled. (Windows 10)
|
||||
description: Describes security event 4725(S) A user account was disabled. This event is generated when a user or computer object is disabled.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4725(S): A user account was disabled.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4726(S) A user account was deleted. (Windows 10)
|
||||
description: Describes security event 4726(S) A user account was deleted. This event is generated when a user object is deleted.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4726(S): A user account was deleted.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4731(S) A security-enabled local group was created. (Windows 10)
|
||||
description: Describes security event 4731(S) A security-enabled local group was created.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4731(S): A security-enabled local group was created.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4732(S) A member was added to a security-enabled local group. (Windows 10)
|
||||
description: Describes security event 4732(S) A member was added to a security-enabled local group.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4732(S): A member was added to a security-enabled local group.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4733(S) A member was removed from a security-enabled local group. (Windows 10)
|
||||
description: Describes security event 4733(S) A member was removed from a security-enabled local group.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4733(S): A member was removed from a security-enabled local group.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4734(S) A security-enabled local group was deleted. (Windows 10)
|
||||
description: Describes security event 4734(S) A security-enabled local group was deleted.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4734(S): A security-enabled local group was deleted.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4735(S) A security-enabled local group was changed. (Windows 10)
|
||||
description: Describes security event 4735(S) A security-enabled local group was changed.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4735(S): A security-enabled local group was changed.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4738(S) A user account was changed. (Windows 10)
|
||||
description: Describes security event 4738(S) A user account was changed. This event is generated when a user object is changed.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4738(S): A user account was changed.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4739(S) Domain Policy was changed. (Windows 10)
|
||||
description: Describes security event 4739(S) Domain Policy was changed. This event is generated when certain changes are made to the local computer security policy.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4739(S): Domain Policy was changed.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4740(S) A user account was locked out. (Windows 10)
|
||||
description: Describes security event 4740(S) A user account was locked out. This event is generated every time a user account is locked out.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4740(S): A user account was locked out.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4741(S) A computer account was created. (Windows 10)
|
||||
description: Describes security event 4741(S) A computer account was created. This event is generated every time a computer object is created.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4741(S): A computer account was created.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4742(S) A computer account was changed. (Windows 10)
|
||||
description: Describes security event 4742(S) A computer account was changed. This event is generated every time a computer object is changed.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4742(S): A computer account was changed.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4743(S) A computer account was deleted. (Windows 10)
|
||||
description: Describes security event 4743(S) A computer account was deleted. This event is generated every time a computer object is deleted.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4743(S): A computer account was deleted.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4749(S) A security-disabled global group was created. (Windows 10)
|
||||
description: Describes security event 4749(S) A security-disabled global group was created.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4749(S): A security-disabled global group was created.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4750(S) A security-disabled global group was changed. (Windows 10)
|
||||
description: Describes security event 4750(S) A security-disabled global group was changed.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4750(S): A security-disabled global group was changed.
|
||||
|
@ -2,7 +2,7 @@
|
||||
title: 4751(S) A member was added to a security-disabled global group. (Windows 10)
|
||||
description: Describes security event 4751(S) A member was added to a security-disabled global group.
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.technology: windows-sec
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# 4751(S): A member was added to a security-disabled global group.
|
||||
|
Loading…
x
Reference in New Issue
Block a user