Event ID 4731
A security-enabled local group was createdA security-enabled local group was created.
Subject:
Security ID: %4
Account Name: %5
Account Domain: %6
Logon ID: %7
New Group:
Security ID: %3
Group Name: %1
Group Domain: %2
Attributes:
SAM Account Name: %9
SID History: %10
Additional Information:
Privileges: %8This event generates every time a new security-enabled (security) local group was created.
This event generates on domain controllers, member servers, and workstations.
Microsoft Documentation
| Name | Field | Insertion String | OS | Example | ||
|---|---|---|---|---|---|---|
| Group Name | TargetUserName | %1 | Any | AccountOperators | ||
| Group Domain | TargetDomainName | %2 | Any | DOMAIN | ||
| Security ID | TargetSid | %3 | Any | S-1-5-21-3457937927-2839227994-823803824-6605 | ||
| Security ID | SubjectUserSid | %4 | Any | S-1-5-21-3457937927-2839227994-823803824-1104 | ||
| Account Name | SubjectUserName | %5 | Any | UserName | ||
| Account Domain | SubjectDomainName | %6 | Any | DOMAIN | ||
| Logon ID | SubjectLogonId | %7 | Any | 0x3031e | ||
| Privileges | PrivilegeList | %8 | Any | View Codes | ||
| SAM Account Name | SamAccountName | %9 | Any | AccountOperators | ||
| SID History | SidHistory | %10 | Any | - | ||
Lookup Audit Policy Configuration Settings
C:\> AuditPol.exe /get /subcategory:"Security Group Management"
LEFT/RIGHT arrow keys for navigation
Back to List