Details | |
Product: | Windows Operating System |
Event ID: | 642 |
Source: | Security |
Version: | 5.0 |
Symbolic Name: | SE_AUDITID_USER_CHANGE |
Message: | User Account Changed: Target Account Name: %2 Target Domain: %3 Target Account ID: %4 Caller User Name: %5 Caller Domain: %6 Caller Logon ID: %7 Privileges: %8 Changed Attributes: Sam Account Name: %9 Display Name: %10 User Principal Name: %11 Home Directory: %12 Home Drive: %13 Script Path: %14 Profile Path: %15 User Workstations: %16 Password Last Set: %17 Account Expires: %18 Primary Group ID: %19 AllowedToDelegateTo: %20 Old UAC Value: %21 New UAC Value: %22 User Account Control: %23 User Parameters: %24 Sid History: %25 Logon Hours: %26 |
Explanation | |
A security-relevant property of the user account was changed. This event is generated only when one of the following properties changes: Sam Account Name, Display Name, User Principal Name, Home Directory, Home Drive, Script Path, Profile Path, User Workstations, Password Last Set, Account Expires, Primary Group ID, AllowedToDelegateTo, UserAccountControl bit list, User Account Control, User Parameters, Sid History, or Logon Hours. |
|
User Action | |
No user action is required. |