Windows Security Log Event ID 4774
Operating Systems |
Windows 2008 R2 and 7
Windows 2012 R2 and 8.1
Windows 2016 and 10
Windows Server 2019 and 2022
|
Category • Subcategory | Account Logon • Credential Validation |
Type
|
Success
|
Corresponding events
in Windows
2003 and before |
678
|
4774: An account was mapped for logon
On this page
I have not actually seen this event logged by Windows but suspect that if it is logged at all it would be in conjunction with IIS's certificate mapping capability where users are authenticated via a client certificate which is then mapped to a Windows user account according to mapping rules defined in IIS.
I haven't been able to produce this event. Have you? If so, please start a discussion (see above) and post a sample along with any comments you may have! Don't forget to sanitize any private information.
Free Security Log Resources by Randy
- Authentication Package: %1
- Account UPN: %2
- Mapped Name: %3
Supercharger Free Edition
Supercharger's built-in Xpath filters leave the noise behind.
Free.