Windows Security Log Event ID 4621

Operating Systems Windows 2008 R2 and 7
Windows 2012 R2 and 8.1
Windows 2016 and 10
Category
 • Subcategory
System
 • Security State Change
Type Success
Corresponding events
in Windows 2003
and before
 
Discussions on Event ID 4621
Ask a question about this event

4621: Administrator recovered system from CrashOnAuditFail

On this page

In testing I configured the log to crash on audit failure and then filled up the security log which indeed brought the system down.  I rebooted, reset the CrashOnAuditFail registry setting, cleared the log and restarted.  The event was never logged. I haven't been able to produce this event. Have you? If so, please start a discussion (see above) and post a sample along with any comments you may have! Don't forget to sanitize any private information.

Free Security Log Resources by Randy

Supercharger Free Edition


Supercharger's built-in Xpath filters leave the noise behind.

Free.

 

Examples of 4621

Administrator recovered system from CrashOnAuditFail. Users who are not administrators will now be allowed to log on. Some auditable activity might not have been recorded.

Value of CrashOnAuditFail: %1

This event is logged after a system reboots following CrashOnAuditFail.

Keep me up-to-date on the Windows Security Log.
Email*:
*We will NOT share this

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection



 

Additional Resources