﻿<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>WinSecWiki » Windows Security Settings » Local Policies » Audit Policy » Audit account management</title><generator>InstantKB.NET 2.0.3</generator><description>WinSecWiki</description><link>http://www.ultimatewindowssecurity.com/wiki/</link><webMaster>noreply@ultimatewindowssecurity.com</webMaster><lastBuildDate>Sat, 25 May 2013 09:23:47 GMT</lastBuildDate><ttl>20</ttl><item><title>Other Account Management Events</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50576.aspx</link><description>&lt;span class="Apple-style-span" style="WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: 11px Verdana; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(51,51,51); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0"&gt;Miscellaneous account management events. Logged on member servers and workstations in addition to domain controllers. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 can use Group Policy.&lt;br /&gt;&lt;br /&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=6&amp;amp;subcatid=46"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;br /&gt;&lt;br /&gt;&lt;table style="PADDING-BOTTOM: 0px; MARGIN: 0px; PADDING-LEFT: 0px; PADDING-RIGHT: 0px; PADDING-TOP: 0px" border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4739" class="pagelink" style="COLOR: rgb(0,102,153); TEXT-DECORATION: none" href="/securitylog/encyclopedia/event.aspx?eventid=4739" target="_blank"&gt;4739&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4739" class="pagelink" style="COLOR: rgb(0,102,153); TEXT-DECORATION: none" href="/securitylog/encyclopedia/event.aspx?eventid=4739"&gt;Domain Policy was changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4793" class="pagelink" style="COLOR: rgb(0,102,153); TEXT-DECORATION: none" href="/securitylog/encyclopedia/event.aspx?eventid=4793"&gt;4793&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4793" class="pagelink" style="COLOR: rgb(0,102,153); TEXT-DECORATION: none" href="/securitylog/encyclopedia/event.aspx?eventid=4793"&gt;The Password Policy Checking API was called.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/span&gt;&lt;br class="Apple-interchange-newline" /&gt;</description><pubDate>Tue, 28 Aug 2012 15:13:59 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Application Group Management</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50575.aspx</link><description>&lt;span class="Apple-style-span" style="WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: 11px Verdana; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(51,51,51); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0"&gt;&lt;font color="#000000"&gt;Application groups are part of Windows's role based access control for applications and are maintained in the Authorization Manager MMC snap-in. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 can use Group Policy.&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;&lt;font color="#000000"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=6&amp;amp;subcatid=45"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;br /&gt;&lt;span&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4783" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4783"&gt;4783&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4783" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4783"&gt;A basic application group was created.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4784" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4784"&gt;4784&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4784" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4784"&gt;A basic application group was changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4785" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4785"&gt;4785&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4785" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4785"&gt;A member was added to a basic application group.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4786" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4786"&gt;4786&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4786" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4786"&gt;A member was removed from a basic application group.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4787" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4787"&gt;4787&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4787" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4787"&gt;A non-member was added to a basic application group.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4788" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4788"&gt;4788&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4788" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4788"&gt;A non-member was removed from a basic application group.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4789" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4789"&gt;4789&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4789" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4789"&gt;A basic application group was deleted.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4790" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4790"&gt;4790&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4790" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4790"&gt;An LDAP query group was created.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4791" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4791"&gt;4791&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4791" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4791"&gt;A basic application group was changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4792" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4792"&gt;4792&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4792" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4792"&gt;An LDAP query group was deleted.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/span&gt;&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;&lt;/font&gt;&lt;/span&gt;</description><pubDate>Tue, 28 Aug 2012 15:09:32 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Distribution Group Management</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50574.aspx</link><description>&lt;span class="Apple-style-span" style="WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: 11px Verdana; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(51,51,51); WORD-SPACING: 0px; -webkit-text-size-adjust: auto; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-stroke-width: 0"&gt;&lt;font color="#000000"&gt;This event is only logged on domain controllers. &lt;font color="#333333" face="Verdana"&gt;To configure this on Server 2008 and Vista you must use&lt;span class="Apple-converted-space"&gt; &lt;/span&gt;auditpol. Windows 7 and Server 2008 R2 can use Group Policy. &lt;/font&gt;&lt;/font&gt;&lt;font color="#000000"&gt;In Active Directory Users and Computers "Security Disabled" groups are referred to as Distribution groups. AD has 2 types of groups: Security and Distribution. Distribution (security disabled) groups are for distribution lists in Exchange and cannot be assigned permissions or rights. Security (security enabled) groups can be used for permissions, rights and as distribution lists.&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;&lt;font color="#000000"&gt;Coverage on events generated by this category is currently are the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=6&amp;amp;subcatid=44"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;span&gt;&lt;br /&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4744" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4744"&gt;4744&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4744" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4744"&gt;A security-disabled local group was created.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4745" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4745"&gt;4745&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4745" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4745"&gt;A security-disabled local group was changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4746" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4746"&gt;4746&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4746" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4746"&gt;A member was added to a security-disabled local group.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4747" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4747"&gt;4747&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4747" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4747"&gt;A member was removed from a security-disabled local group.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4748" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4748"&gt;4748&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4748" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4748"&gt;A security-disabled local group was deleted.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4749" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4749"&gt;4749&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4749" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4749"&gt;A security-disabled global group was created.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4750" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4750"&gt;4750&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4750" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4750"&gt;A security-disabled global group was changed&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4751" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4751"&gt;4751&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4751" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4751"&gt;A member was added to a security-disabled global group.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4752" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4752"&gt;4752&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4752" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4752"&gt;A member was removed from a security-disabled global group.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4753" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4753"&gt;4753&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4753" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4753"&gt;A security-disabled global group was deleted.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4759" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4759"&gt;4759&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4759" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4759"&gt;A security-disabled universal group was created.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4760" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4760"&gt;4760&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4760" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4760"&gt;A security-disabled universal group was changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4761" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4761"&gt;4761&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4761" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4761"&gt;A member was added to a security-disabled universal group.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4762" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4762"&gt;4762&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4762" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4762"&gt;A member was removed from a security-disabled universal group.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4763" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4763"&gt;4763&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4763" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4763"&gt;A security-disabled universal group was deleted.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/span&gt;&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;&lt;/font&gt;&lt;/span&gt;</description><pubDate>Tue, 28 Aug 2012 14:42:53 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Security Group Management</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50573.aspx</link><description>&lt;span class="Apple-style-span" style="WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: 11px Verdana; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(51,51,51); WORD-SPACING: 0px; -webkit-text-size-adjust: auto; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-stroke-width: 0"&gt;&lt;font color="#000000"&gt;This category is logged on workstations, member servers and domain controllers. &lt;font color="#333333" face="Verdana"&gt;To configure this on Server 2008 and Vista you must use&lt;span class="Apple-converted-space"&gt; &lt;/span&gt;auditpol. Windows 7 and Server 2008 R2 can use Group Policy.&lt;/font&gt;&lt;/font&gt;&lt;a id="Active_Directory_0" style="COLOR: rgb(0,102,153); TEXT-DECORATION: none"&gt;&lt;/a&gt;&lt;font color="#000000"&gt; &lt;/font&gt;&lt;h2 class="separator" style="BORDER-BOTTOM: rgb(51,51,51) 1px solid; PADDING-BOTTOM: 2px; FONT-FAMILY: Arial, Helvetica, sans-serif; MARGIN-BOTTOM: 8px; COLOR: rgb(3,103,163); FONT-SIZE: medium"&gt;Active Directory&lt;/h2&gt;&lt;font color="#000000"&gt;In Active Directory Users and Computers "Security Enabled" groups are simply referred to as Security groups. AD has 2 types of groups: Security and Distribution. Distribution (security disabled) groups are for distribution lists in Exchange and cannot be assigned permissions or rights. Security (security enabled) groups can be used for permissions, rights and as distribution lists.&lt;span class="Apple-converted-space"&gt; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;A domain local group means the group can only be granted access to objects within its domain but can have members from any trusted domain.&lt;/font&gt;&lt;a id="Local_SAM_1" style="COLOR: rgb(0,102,153); TEXT-DECORATION: none"&gt;&lt;/a&gt; &lt;h2 class="separator" style="BORDER-BOTTOM: rgb(51,51,51) 1px solid; PADDING-BOTTOM: 2px; FONT-FAMILY: Arial, Helvetica, sans-serif; MARGIN-BOTTOM: 8px; COLOR: rgb(3,103,163); FONT-SIZE: medium"&gt;Local SAM&lt;/h2&gt;&lt;font color="#000000"&gt;All groups are security groups in the computer's SAM. Local SAM groups can be granted access to objects on the local computer only but may have members from the local SAM and any trusted domain.&lt;/font&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;&lt;font color="#000000"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=6&amp;amp;subcatid=43"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;span&gt;&lt;br /&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4727" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4727"&gt;4727&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4727" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4727"&gt;A security-enabled global group was created.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4728" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4728"&gt;4728&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4728" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4728"&gt;A member was added to a security-enabled global group.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4729" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4729"&gt;4729&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4729" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4729"&gt;A member was removed from a security-enabled global group.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4730" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4730"&gt;4730&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4730" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4730"&gt;A security-enabled global group was deleted.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4731" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4731"&gt;4731&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4731" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4731"&gt;A security-enabled local group was created.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4732" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4732"&gt;4732&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4732" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4732"&gt;A member was added to a security-enabled local group.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4733" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4733"&gt;4733&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4733" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4733"&gt;A member was removed from a security-enabled local group.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4734" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4734"&gt;4734&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4734" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4734"&gt;A security-enabled local group was deleted.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4735" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4735"&gt;4735&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4735" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4735"&gt;A security-enabled local group was changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4737" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4737"&gt;4737&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4737" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4737"&gt;A security-enabled global group was changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4754" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4754"&gt;4754&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4754" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4754"&gt;A security-enabled universal group was created.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4755" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4755"&gt;4755&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4755" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4755"&gt;A security-enabled universal group was changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4756" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4756"&gt;4756&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4756" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4756"&gt;A member was added to a security-enabled universal group.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4757" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4757"&gt;4757&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4757" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4757"&gt;A member was removed from a security-enabled universal group.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4758" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4758"&gt;4758&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4758" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4758"&gt;A security-enabled universal group was deleted.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4764" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4764"&gt;4764&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4764" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4764"&gt;A groups type was changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/span&gt;&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;</description><pubDate>Tue, 28 Aug 2012 14:40:44 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Computer Account Management</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50572.aspx</link><description>&lt;font color="#000000"&gt;This category is only logged on domain controllers. &lt;font color="#333333" face="Verdana" size="2"&gt;To configure this on Server 2008 and Vista you must use&lt;span class="Apple-converted-space"&gt; &lt;/span&gt;auditpol. Windows 7 and Server 2008 R2 can use Group Policy.&lt;/font&gt;  &lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;&lt;font size="2"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=6&amp;amp;subcatid=42"&gt;Security Log Encyclopedia&lt;/a&gt;: &lt;br /&gt;&lt;span&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4741" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4741"&gt;4741&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4741" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4741"&gt;A computer account was created.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4742" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4742"&gt;4742&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4742" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4742"&gt;A computer account was changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4743" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4743"&gt;4743&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4743" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4743"&gt;A computer account was deleted.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/span&gt;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;</description><pubDate>Tue, 28 Aug 2012 14:29:27 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>User Account Management</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50571.aspx</link><description>&lt;span id="ctl00_ctlContentPlaceHolder_ctl00_ctlViewArticle_ctlPanelBar_lblArticleText"&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;&lt;span class="Apple-style-span" style="WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: 11px Verdana; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(51,51,51); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0"&gt;This category tracks changes to local user accounts on workstations, member servers and Active Directory domain user accounts on domain controllers. To configure this on Server 2008 and Vista you must use&lt;span class="Apple-converted-space"&gt; &lt;/span&gt;auditpol. Windows 7 and Server 2008 R2 can use Group Policy.&lt;/span&gt;&lt;/span&gt;  &lt;div&gt;&lt;span style="COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=6&amp;amp;subcatid=41"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;span&gt;&lt;br /&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4720" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4720"&gt;4720&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4720" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4720"&gt;A user account was created.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4722" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4722"&gt;4722&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4722" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4722"&gt;A user account was enabled.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4723" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4723"&gt;4723&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4723" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4723"&gt;An attempt was made to change an account's password.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4724" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4724"&gt;4724&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4724" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4724"&gt;An attempt was made to reset an accounts password.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4725" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4725"&gt;4725&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4725" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4725"&gt;A user account was disabled.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4726" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4726"&gt;4726&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4726" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4726"&gt;A user account was deleted.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4738" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4738"&gt;4738&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4738" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4738"&gt;A user account was changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4740" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4740"&gt;4740&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4740" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4740"&gt;A user account was locked out.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4767" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4767"&gt;4767&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4767" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4767"&gt;A user account was unlocked.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4780" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4780"&gt;4780&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4780" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4780"&gt;The ACL was set on accounts which are members of administrators groups.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4781" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4781"&gt;4781&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4781" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4781"&gt;The name of an account was changed:&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4794" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4794"&gt;4794&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4794" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4794"&gt;An attempt was made to set the Directory Services Restore Mode administrator password&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5376" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5376"&gt;5376&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5376" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5376"&gt;Credential Manager credentials were backed up.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5377" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5377"&gt;5377&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5377" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5377"&gt;Credential Manager credentials were restored from a backup.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/span&gt;</description><pubDate>Tue, 21 Aug 2012 15:03:10 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>OVERVIEW: Audit Account Management</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50024.aspx</link><description>&lt;span style="FONT-SIZE: 11px; COLOR: rgb(51,51,51); FONT-FAMILY: Verdana"&gt; &lt;font color="#000000"&gt;The Audit account management events policy, which you can use to monitor changes to user accounts and groups, is valuable for auditiing the activity of administrators and Help Desk staff.  This policy logs password resets, newly crated accounts, and changes to group memebership.  On DCs, the policy logs changes to domain users, domain groups, and computer accounts.  On member servers, it logs changes to local users and groups. We have not observed any failure events in this category. &lt;br /&gt;&lt;br /&gt;The following is an exerpt from my book, &lt;/font&gt;&lt;a href="/securitylog/resourcekits/Default.aspx"&gt;The Windows Server Security Log Revealed &lt;/a&gt;: &lt;br /&gt;&lt;br /&gt;&lt;font class="Quote"&gt;The Account Management security log category is particularly valuable because you can use it to track maintenance of user, group, and computer objects in AD as well as to track local users and groups in member server and workstation SAMs.  This category is also very easy to use because Windows uses a different even ID for each type of object and operation. &lt;/font&gt;&lt;br /&gt;&lt;br /&gt;For a list of Event IDs generated by this category, see the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=6"&gt;Security Log Encyclopedia&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;h2&gt;&lt;font size="3"&gt;Bottom Line&lt;/font&gt; &lt;/h2&gt;&lt;span style="FONT-SIZE: 15px; COLOR: rgb(0,0,0); FONT-FAMILY: Verdana"&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Windows XP, 2000 and 2003: I recommend enabling this policy for success and failure on all computers including workstations. &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Windows Server 2008 and Vista: I don't recommend managing audit policy at this level because too much noise is generated. Use subcategories instead. See &lt;a href="/wiki/WindowsSecuritySettings/62" target="_blank"&gt;Audit Category: Account Management &lt;/a&gt;(Windows Server 2008 and Vista) . &lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/span&gt;</description><pubDate>Thu, 02 Apr 2009 18:12:29 GMT</pubDate><dc:creator>instantasp@gmail.com</dc:creator></item></channel></rss>