Event Id | 5139 |
Source | Microsoft-Windows-Security-Auditing |
Description | A directory service object was moved. Subject: Security ID:<Security ID> Account Name:<Account Name> Account Domain:<Domain name> Logon ID:<Logon ID> Directory Service: Name:<Name> Type:< Service Type> Object: Old DN: <Old DN> New DN: <New DN> GUID: <GUID> Class: <Class> Operation: Correlation ID:<Correlation ID> Application Correlation ID:<Application Correlation ID> |
Event Information | Cause : This event is logged when an AD objects from one OU to another, identifying the object moved and user who moved it and its old and new location.This event will be logged when the object's parent's audit policy has auditing enabled for moves of the object class involved and for the user performing the action or a group to which the user belongs. Resolution : This is an information event and no user action is required. |
Reference Links |
Catch threats immediately
We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.