Event ID 4734
A security-enabled local group was deletedA security-enabled local group was deleted. Subject: Security ID: %4 Account Name: %5 Account Domain: %6 Logon ID: %7 Group: Security ID: %3 Group Name: %1 Group Domain: %2 Additional Information: Privileges: %8
This event generates every time security-enabled (security) local group is deleted.
This event generates on domain controllers, member servers, and workstations.
Microsoft Documentation
Name | Field | Insertion String | OS | Example | ||
---|---|---|---|---|---|---|
Group Name | TargetUserName | %1 | Any | AccountOperators | ||
Group Domain | TargetDomainName | %2 | Any | DOMAIN | ||
Security ID | TargetSid | %3 | Any | S-1-5-21-3457937927-2839227994-823803824-6605 | ||
Security ID | SubjectUserSid | %4 | Any | S-1-5-21-3457937927-2839227994-823803824-1104 | ||
Account Name | SubjectUserName | %5 | Any | UserName | ||
Account Domain | SubjectDomainName | %6 | Any | DOMAIN | ||
Logon ID | SubjectLogonId | %7 | Any | 0x35e38 | ||
Privileges | PrivilegeList | %8 | Any | View Codes |
Lookup Audit Policy Configuration Settings
C:\> AuditPol.exe /get /subcategory:"Security Group Management"
LEFT/RIGHT arrow keys for navigation
Back to List