Event ID 4675
SIDs were filteredSIDs were filtered. Target Account: Security ID: %1 Account Name: %2 Account Domain: %3 Trust Information: Trust Direction: %4 Trust Attributes: %5 Trust Type: %6 TDO Domain SID: %7 Filtered SIDs: %8
Generates when SIDs were filtered for a specific Active Directory trust.
Auditing:
Always
It is recommended to enable auditing for all associated subcategories on domain controllers, servers and workstations.
Microsoft Documentation
Lookup Audit Policy Configuration Settings
C:\> AuditPol.exe /get /subcategory:Logon
LEFT/RIGHT arrow keys for navigation
Back to List