Home
Resources
Training
About Us
eStore

>

resources > security log resource center > encyclopedia > event 611 on Windows 2003

 

 

 

 

 

 

 

Latest Blog: Log monitoring and the Terry Childs/City of San Francisco debacle

 

Windows Security Log Events by ID

look up more events by Event ID or Category

Event ID

611

Title

Trusted Domain Removed

Type: Example: Randy's Comments:
Success

OS:

Windows 2003

Category:

Policy Change

Trusted Domain Removed:
Domain Name:SouthAmerica
Domain ID:-
Removed By:
User Name:administrator
Domain:ELM
Logon ID:(0x0,0x158EB7)

Unlike Windows 2000, Windows Server 2003 only logs this event once for each new domain. Although the description says "new *trusted* domain" this event gets logged for both trusted and trusting relationships.

If directory service access auditing is turned on, the DC also logs an event 565 (object opened) and 564 (object deleted) where the object service is LSA and the object type is TrustedDomainObject. Object name identifies the domain.
See also event IDs 610, 611 and 620

Next:

Get all the tools you need in one newsletter!
Free log parser scripts, clear explanations of Microsoft's latest security bulletins, and more. View a sample issue.
Email Address:
Your email address will not be shared. You may unsubscribe at any time.


Upcoming Webinars by Randy Franklin Smith


Additional Links

A
D
V