Event Id | 4747 |
Source | Microsoft-Windows-Security-Auditing |
Description | A member was removed from a security-disabled local group. Subject: Security ID:<Security ID> Account Name:<Account Name> Account Domain:<Domain name> Logon ID:<Logon ID> Member: Security ID:<Security ID> Account Name:<Account Name> Group: Security ID:<Security ID> Group Name:<Group Name> Group Domain:<Group Domain> Additional Information: Privileges: |
Event Information | Cause : This user can remove the user/group/computer in Member: to the Local Distribution group in Group.This event is only logged on domain controllers. Resolution: This is an information event and no user action is required. |
Reference Links |
Catch threats immediately
We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.