Event Id | 633 |
Source | Security |
Description | Security Enabled Global Group Member Removed: Member Name: <Member Name>       Member ID: <Member ID>       Target Account Name: <Target Account Name>       Target Domain: <Target Domain>       Target Account ID: <Target Account ID>       Caller User Name: <Caller User Name>       Caller Domain: <Caller Domain>       Caller Logon ID: <Caller Logon ID>       Privileges: <Privileges>      |
Event Information | According to Microsoft Cause: This event record indicates that a member has been removed from a global group. This event also occurs when a user account is deleted and removed from the built-in None group used internally by Windows 2000. There is no Failure Audit form of this audit event record. Removing members from groups can have security implications. This is especially true when a user is removed from the Administrator group. Resolution: The person with administrative rights for the computer should check to see who is being removed from groups that have security implications. Make sure that users removed from security sensitive groups really should be removed. |
Reference Links | "Event Id 633 of Source security Alternate Event ID in Vista and Windows Server 2008 is 4729. |
Catch threats immediately
We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.