Event Id | 4767 |
Source | Microsoft-Windows-Security-Auditing |
Description | A user account was unlocked. Subject: Security ID:<Domain\User name> Account Name:<User name> Account Domain:<Domain name> Logon ID:<Logon ID> Target Account: Security ID:<Domain\User name> Account Name:<User name> Account Domain:<Domain name> |
Event Information | Cause: This event is logged on when you unlock an account that was locked out. Subject field in description contains account information of the user who unlocked the account. Target account field contains the account information of the user whose account was unlocked. User Action: Verify the target account informatin and the account information of the user who unlocked the account is authorized. Note :This event is logged on windows vista and windows server 2008 operating system. |
Reference Links | Alternate Event ID in pre vista OS |
Catch threats immediately
We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.