Event ID: 4713

Kerberos policy was changed

Kerberos policy was changed.

    Security ID:        %1
    Account Name:       %2
    Account Domain:     %3
    Logon ID:           %4

Changes Made:
('--' means no changes, otherwise each change is shown as:
(Parameter Name):   (new value) (old value))

This event is generated only on domain controllers.

Auditing:     Always

Since Kerberos settings affect domain security and changes are generally infrequent, it's recommended to always audit this.

Volume:     Low

Microsoft Documentation

Event ID - 4713

Name Field Insertion String OS Example
Security ID SubjectUserSid %1 Any DOMAIN\TheAdmin
Account Name SubjectUserName %2 Any TheAdmin
Account Domain SubjectDomainName %3 Any DOMAIN
Logon ID SubjectLogonId %4 Any 0x3e7
Changes Made KerberosPolicyChange %5 Any KerMaxT: 0x10c388d000 (0x861c46800); KerMaxR: 0x19254d38000 (0xc92a69c000);

Lookup Audit Policy Configuration Settings

C:\> AuditPol.exe /get /subcategory:"Authentication Policy Change"

LEFT/RIGHT arrow keys for navigation

Back to List