User Account Changed: Target Account Name: %2 Target Domain: %3 Target Account ID: %4 Caller User Name: %5 Caller Domain: %6 Caller Logon ID: %7 Privileges: %8 Changed Attributes: Sam Account Name: %9 Display Name: %10 User Principal Name: %11 Home Directory: %12 Home Drive: %13 Script Path: %14 Profile Path: %15 User Workstations: %16 Password Last Set: %17 Account Expires: %18 Primary Group ID: %19 AllowedToDelegateTo: %20 Old UAC Value: %21 New UAC Value: %22 User Account Control: %23 User Parameters: %24 Sid History: %25 Logon Hours: %26

Details
Product: Windows Operating System
Event ID: 642
Source: Security
Version: 5.0
Symbolic Name: SE_AUDITID_USER_CHANGE
Message: User Account Changed: Target Account Name: %2 Target Domain: %3 Target Account ID: %4 Caller User Name: %5 Caller Domain: %6 Caller Logon ID: %7 Privileges: %8 Changed Attributes: Sam Account Name: %9 Display Name: %10 User Principal Name: %11 Home Directory: %12 Home Drive: %13 Script Path: %14 Profile Path: %15 User Workstations: %16 Password Last Set: %17 Account Expires: %18 Primary Group ID: %19 AllowedToDelegateTo: %20 Old UAC Value: %21 New UAC Value: %22 User Account Control: %23 User Parameters: %24 Sid History: %25 Logon Hours: %26
   
Explanation

A security-relevant property of the user account was changed.

This event is generated only when one of the following properties changes: Sam Account Name, Display Name, User Principal Name, Home Directory, Home Drive, Script Path, Profile Path, User Workstations, Password Last Set, Account Expires, Primary Group ID, AllowedToDelegateTo, UserAccountControl bit list, User Account Control, User Parameters, Sid History, or Logon Hours.

   
User Action

No user action is required.

Related:

Leave a Reply