Skip to main content

Active Directory Domain Services

Log NameEvent IDSeverityDescription
Security4624InfoSuccessful logon
Security4625WarningFailed logon attempt
Security4672HighSpecial privileges assigned (Admin logon)
Security4740HighAccount locked out
Security4720HighUser account created
Security4726HighUser account deleted
Security4723 / 4724MediumPassword changed / reset
Security4728 / 4729HighUser added/removed from security group
Security4732 / 4733MediumMember added/removed from local group
Security4768 / 4771MediumKerberos ticket request/failure
Security4648MediumLogon attempt with explicit credentials
Directory Service2887HighLDAP signing not enforced
Directory Service2889HighLDAP simple bind without SSL detected
Security4740MediumUser account locked out
Security4768–4771MediumKerberos ticket requests/failures
Security4625HighFailed logon attempt
Security1102CriticalAudit logs cleared
System5719HighNo domain controller available
Security5722HighSecure channel setup failed
Security5805MediumTrust relationship failed
Security4731 / 4735 / 4737MediumGPO created / modified / deleted
Security4719HighAudit policy changed
Security5136HighDirectory object modified
Security5137HighDirectory object created
Security5138HighDirectory object undeleted (from recycle bin)
Security5139MediumDirectory object moved
Security5141HighDirectory object deleted
Windows PowerShell4103MediumPowerShell command pipeline execution
Windows PowerShell4104HighPowerShell script block execution
Security4688MediumNew process created
Security4697HighService installed on system
Microsoft-Windows-Sysmon/Operational1HighProcess creation
Microsoft-Windows-Sysmon/Operational3MediumNetwork connection established
Microsoft-Windows-Sysmon/Operational7MediumImage loaded
Microsoft-Windows-Sysmon/Operational10MediumProcess access
Microsoft-Windows-Sysmon/Operational13MediumRegistry modification
Security4769HighKerberos service ticket request failure
Security4771HighKerberos pre-authentication failed
Security2889HighLDAP simple bind without SSL detected
Security4739HighDomain policy changed
Security4741MediumUser account created
Security4742MediumComputer account changed
Security4743MediumComputer account deleted
Directory Service1864HighDomain controller not replicating
Directory Service2042CriticalReplication disabled due to stale DC
Directory Service1566HighKCC topology error
Directory Service2103CriticalNTDS database recovery mode
System1311HighReplication connectivity failure