Windows Security Log Event ID 4929

Operating Systems Windows 2008 R2 and 7
Windows 2012 R2 and 8.1
Windows 2016 and 10
Windows Server 2019 and 2022
Category
 • Subcategory
Directory Service
 • Detailed Directory Service Replication
Type Success
Corresponding events
in Windows 2003
and before
 

4929: An Active Directory replica source naming context was removed

On this page

Directory Service replication has little to no security relevance.  I recommend disabling these 2 subcategories: 

  • Directory Service Replication
  • Detailed Directory Service Replication

Since DCSync and DCShadow have come out I've changed my mind about the above statement.  Check out this webinar AD Attack Deep Dive: Gaining Persistence using DCSync and DCShadow with Mimikatz

Free Security Log Resources by Randy

Supercharger Free Edition


Centrally manage WEC subscriptions.

Free.

 

Examples of 4929

An Active Directory replica source naming context was removed.

Destination DRA: %1
Source DRA: %2
Source Address: %3
Naming Context: %4
Options:  %5
Status Code: %6

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection

 

Additional Resources