Event Id | 4742 |
Source | Microsoft-Windows-Security-Auditing |
Description | A computer account was changed. Subject: Security ID: <Security ID > Account Name: <Account Name > Account Domain: <Domain Name > Logon ID: <Logon ID> Computer Account That Was Changed: Security ID: <Security ID > Account Name: <Account Name > Account Domain: <Domain Name > Changed Attributes: SAM Account Name: - <SAM Account Name> Display Name: - < Display Name > User Principal Name: - < User Principal Name > Home Directory: - < Home Directory > Home Drive: - < Home Drive > Script Path: - < Script Path > Profile Path: - < Profile Path > User Workstations: - < User Workstations > Password Last Set: - < Password Last Set > Account Expires: - < Account Expires > Primary Group ID: - < Primary Group ID > AllowedToDelegateTo: - < Primary Group ID > Old UAC Value: 0x85 New UAC Value: 0x84 User Account Control: < User Account Control > Account Enabled User Parameters: - < User Parameters > SID History: - < SID History > Logon Hours: - < Logon Hours > DNS Host Name: - < DNS Host Name > Service Principal Names: - < Service Principal Names > Additional Information: Privileges: - |
Event Information | Cause : This event is logged when a computer account was changed. |
Reference Links |
Catch threats immediately
We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.