Windows Security Log Event ID 659

Operating Systems Windows Server 2000
Windows 2003 and XP
CategoryAccount Management
Type Success
Corresponding events
in Windows 2008
and Vista
Discussions on Event ID 659
Ask a question about this event

659: Security Enabled Universal Group Changed

On this page

Security universal group changed.Type:

AD has 2 types of groups: Security and Distribution. Distribution (security disabled) groups are for distribution lists in Exchange and cannot be assigned permissions or rights. Security (security enabled) groups can be used for permissions, rights and as distribution lists.


AD has 3 scopes of groups: Local, Global, Universal. See knowledge base article 326265.

This event does include group member additions and deletions for which there are other event IDs. 

This event is logged only on Domain Controllers.

Free Security Log Resources by Randy

Description Fields in 659

  •  Target Account Name: %1
  •  Target Domain: %2
  •  Target Account ID: %3
  •  Caller User Name: %4
  •  Caller Domain: %5
  •  Caller Logon ID: %6
  •  Privileges: %7
  •  Changed Attributes: (These two fields are on Server 2003 only)
  •  Sam Account Name: %8
  •  Sid History: %9

Supercharger Enterprise

Load Balancing for Windows Event Collection


Examples of 659

Security Enabled Universal Group Changed:
Target Account Name:AccountingStaff
Target Domain:ELMW2
Target Account ID:AccountingStaff
Caller User Name:Administrator
Caller Domain:ELMW2
Caller Logon ID:(0x0,0x12D622)

Windows Server 2003 adds these fields:

Changed Attributes:
Sam Account Name:-
Sid History:-

Keep me up-to-date on the Windows Security Log.
*We will NOT share this

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection


Additional Resources