Windows Security Log Event ID 642

Operating Systems Windows Server 2000
Windows 2003 and XP
CategoryAccount Management
Type Success
Corresponding events
in Windows 2008
and Vista
4738  
Discussions on Event ID 642
Retrieving full text of event log message
User enabled/disabled
Changed Attributes in 642
User Account Control 'Don't Expire Password' - Enabled
ASPNET account changes (642)

642: User Account Changed

On this page

"Target" user account was changed by "Caller" user.

On Windows 2000 and XP, for some types of changes, the event will include a description of what was changed on the 2nd line of the description.

Often the change will will not be indicated in the event but another event at the same time will will indicate the change. For example when the account name is changed, it will be indicated by event 685.

On Windows Server 2003, there is never a change description on the 2nd line. The change is documented under "changed attributes".

Free Security Log Resources by Randy

Description Fields in 642

Windows 2003:

  • User Account Changed:
  • Target Account Name: %2
  • Target Domain: %3
  • Target Account ID: %4
  • Caller User Name: %5
  • Caller Domain: %6
  • Caller Logon ID: %7
  • Privileges: %8
  • Changed Attributes:
  • Sam Account Name: %9
  • Display Name: %10
  • User Principal Name: %11
  • Home Directory: %12
  • Home Drive: %13
  • Script Path: %14
  • Profile Path: %15
  • User Workstations: %16
  • Password Last Set: %17
  • Account Expires: %18
  • Primary Group ID: %19
  • AllowedToDelegateTo: %20
  • Old UAC Value: %21
  • New UAC Value: %22
  • User Account Control: %23
  • User Parameters: %24
  • Sid History: %25
  • Logon Hours: %26

Supercharger Free Edition

 

Examples of 642

User Account Changed:
Target Account Name:alicej
Target Domain:ELMW2
Target Account ID:ELMW2\alicej
Caller User Name:Administrator
Caller Domain:ELMW2
Caller Logon ID:(0x0,0x1469C1)
Privileges:-
Changed Attributes:
Sam Account Name:-
Display Name:-
User Principal Name:-
Home Directory:-
Home Drive:-
Script Path:-
Profile Path:-
User Workstations:-
Password Last Set:-
Account Expires:9/7/2004 12:00:00 AM
Primary Group ID:-
AllowedToDelegateTo:-
Old UAC Value:-
New UAC Value:-
User Account Control:-
User Parameters:-
Sid History:-
Logon Hours:-

Windows XP:

User Account Changed:
Target Account Name: Guest
Target Domain: STG
Target Account ID: STG\Guest1
Caller User Name: wsmith
Caller Domain: STG
Caller Logon ID: (0x0,0x3013E)
Privileges:

Keep me up-to-date on the Windows Security Log.
Email*:
*We will NOT share this

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection



 

Upcoming Webinars
    Additional Resources