Event Id | 4794 |
Source | Microsoft-Windows-Security-Auditing |
Description | An attempt was made to set the Directory Services Restore Mode administrator password. Subject: Security ID: <Security ID> Account Name: <Account Name> Account Domain: <Domain Name> Logon ID: <Logon ID> Additional Information: Caller Workstation: <Caller Workstation> Status Code:<Status Code> |
Event Information | Cause : This event is logged when an attempt was made to set the directory services restore mode ministrator password. |
Reference Links |
Catch threats immediately
We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.