MISC
Windows Security Log Events
Resources
4720
A user account was created
4722
A user account was enabled
4723
An attempt was made to change an account's password
4724
An attempt was made to reset an accounts password
4725
A user account was disabled
4726
A user account was deleted
4738
A user account was changed
4781
The name of an account was changed
4782
The password hash an account was accessed
4624
An account was successfully logged on
4740
A user account was locked out
4634
An account was logged off
4625
An account failed to log on
4648
A logon was attempted using explicit credentials
4732
A member was added to a security-enabled local group
4728
A member was added to a security-enabled global group
4756
A member was added to a security-enabled universal group
4733
A member was removed from a security-enabled local group
4729
A member was removed from a security-enabled global group
4757
A member was removed from a security-enabled universal group
4657
A registry value was modified
4672
Special privileges assigned to new logon
4697
A service was installed in the system
4698
A scheduled task was created
4699
A scheduled task was deleted
4700
A scheduled task was enabled
4701
A scheduled task was disabled
4702
A scheduled task was updated
4608
Windows is starting up
4609
Windows is shutting down
4800
The workstation was locked
4801
The workstation was unlocked
5140
A network share object was accessed
5145
A network share object was checked to see whether client can be granted desired access
1102
The audit log was cleared. (Security)
Failure Information:
The section explains why the logon failed.
0xC0000064
user name does not exist
0xC000006A
user name is correct but the password is wrong
0xC0000234
user is currently locked out
0xC0000072
account is currently disabled
0xC000006F
user tried to logon outside his day of week or time of day restrictions
0xC0000070
workstation restriction, or Authentication Policy Silo violation (look for event ID 4820 on domain controller)
0xC0000193
account expiration
0xC0000071
expired password
0xC0000133
clocks between DC and other computer too far out of sync
0xC0000224
user is required to change password at next logon
0xC0000225
evidently a bug in Windows and not a risk
0xc000015b
The user has not been granted the requested logon type (aka logon right) at this machine
Logon Types
2
Console
3
Network
4
Batch (Scheduled Tasks)
5
Windows Services
7
Screen Lock/Unlock
8
Network (Cleartext Logon)
9
Alternate Credentials Specified (RunAs)
10
Remote Interactive (RDP)
11
Cached Credentials (e.g., Offline DC)
12
Cached Remote Interactive (RDP, similar to Type 10)
13
Cached Unlock (Similar to Type 7)
Last updated