Skip to content
GitHub

Windows Security Log References


Most handy Windows Security Log Event ID’s.

Event IDAction
4720Created
4722Enabled
4723User changed own password
4724Privileged User changed this user’s password
4725Disabled
4726Deleted
4738Changed
4740Locked out
4767Unlocked
4781Name change
Group ChangesCreatedChangedDeletedMember AddedMember Removed
Security Local47314737473447324733
Security Global47274735473047284729
Security Universal47544755475847564757
Distribution Local47444745474847464747
Distribution Global47494750475347514752
Distribution Universal47594760476347614762
Event IDAction
4768A Kerberos authentication ticket (TGT) was requested
4771Kerberos pre-authentication failed
4772A Kerberos authentication ticket requested failed

For both 4771 and 4772 see the following Kerberos Failure Codes

Event IDAction
0x6Bad user name
0x7New computer account?
0x9Administrator should reset password
OxCWorkstation restriction
0x12Account disabled, expired, locked out,logon hours restriction
0x17The user’s password has expired
0x18Bad password
0x20Frequently logged by computer accounts
0x25Workstation’s clock too far out of sync with the DC’s
Event IDAction
4624Successful logon
4647User initiated logoff
4625Logon failure (See Logon Failure Codes)
4778Remote desktop session reconnected
4779Remote desktop session disconnected
4800Workstation locked
4801Workstation unlocked
4802Screen saver invoked
4803Screen saver dismissed
Event IDAction
2Interactive
3Network (i.e. mapped drive)
4Batch (i.e. schedule task)
5Service (service startup)
7Unlock (i.e. unattended workstation with password protected screen saver)
8Network Cleartext (Most often indicates a logon to IIS with “basic authentication”)
10Remote Desktop
11Logon with cached credentials
Event IDAction
OxC0000064User name does not exist
0xC000006AUser name is correct but the password is wrong
0xC0000234User is currently locked out
0xC0000072Account is currently disabled
0xC000006FUser tried to logon outside his day of week or time of day restrictions
0xC0000070Workstation restriction
0xC00000193Account expiration
0xC0000071Expired password
OxC0000133Clocks between DC and other computer too far out of sync
OxC0000224User is required to change password at next logon
OxC0000225Evidently a bug in Windows and not a risk
0x000015bThe user has not been granted the requested logon type (aka logon right) at this machine