Windows Security Log Event ID 635
Operating Systems Windows Server 2000
Windows XP
Windows Server 2003
Category Account Management
Type Success
Corresponding events
in Windows 2008
and Vista
4731  
Discussions on Event ID 635

635: Security Enabled Local Group Created

On this page

Local security group created.Type:

AD has 2 types of groups: Security and Distribution. Distribution (security disabled) groups are for distribution lists in Exchange and cannot be assigned permissions or rights. Security (security enabled) groups can be used for permissions, rights and as distribution lists.

Scope:

AD has 3 scopes of groups: Local, Global, Universal. See knowledge base article 326265.

Free Security Log Quick Reference Chart

  • New Account Name: %1
  • New Domain: %2
  • New Account ID: %3
  • Caller User Name: %4
  • Caller Domain: %5
  • Caller Logon ID: %6
  • Privileges: %7

Windows Server 2003 adds these fields:

  • Attributes:
  • Sam Account Name: %8
  • Sid History: %9

Top 10 Events to Monitor

Security Enabled Local Group Created:
New Account Name:AccountingStaff
New Domain:ELMW2
New Account ID:ELMW2\AccountingStaff
Caller User Name:Administrator
Caller Domain:ELMW2
Caller Logon ID:(0x0,0x12D622)
Privileges:-

Windows Server 2003 adds these fields

Attributes:
Sam Account Name:TestGroup
Sid History:-

Keep me up-to-date on the Windows Security Log.
Email*:
*We will NOT share this