Event ID 4767
A user account was unlocked
A user account was unlocked.
Subject:
Security ID: %4
Account Name: %5
Account Domain: %6
Logon ID: %7
Target Account:
Security ID: %3
Account Name: %1
Account Domain: %2
This event generates every time a user account is unlocked.
For user accounts, this event generates on domain controllers, member servers, and workstations.
Name |
Field |
Insertion String |
OS |
Example |
|
|
Account Name |
TargetUserName |
%1 |
Any |
Auditor
|
|
Account Domain |
TargetDomainName |
%2 |
Any |
DOMAIN
|
|
Security ID |
TargetSid |
%3 |
Any |
S-1-5-21-3457937927-2839227994-823803824-2104
|
|
Security ID |
SubjectUserSid |
%4 |
Any |
S-1-5-21-3457937927-2839227994-823803824-1104
|
|
Account Name |
SubjectUserName |
%5 |
Any |
dadmin
|
|
Account Domain |
SubjectDomainName |
%6 |
Any |
DOMAIN
|
|
Logon ID |
SubjectLogonId |
%7 |
Any |
0x30d5f
|
The name of the account that was unlocked.
"Subject’s domain or computer name. Formats vary, and include the following:
Domain NETBIOS name example: DOMAIN
Lowercase full domain name: domain.local
Uppercase full domain name: DOMAIN.LOCAL
For some well-known security principals, such as LOCAL SERVICE or ANONYMOUS LOGON, the value of this field is “NT AUTHORITY”.
For local user accounts, this field will contain the name of the computer or device that this account belongs to, for example: “ComputerName”."
SID of account that was unlocked. Event Viewer automatically tries to resolve SIDs and show the account name. If the SID cannot be resolved, you will see the source data in the event.
SID of account that performed the unlock operation. Event Viewer automatically tries to resolve SIDs and show the account name. If the SID cannot be resolved, you will see the source data in the event.
The name of the account that performed the unlock operation.
Subject’s domain or computer name. Formats vary, and include the following:
Domain NETBIOS name example: DOMAIN
Lowercase full domain name: domain.local
Uppercase full domain name: DOMAIN.LOCAL
For some well-known security principals, such as LOCAL SERVICE or ANONYMOUS LOGON, the value of this field is “NT AUTHORITY”.
For local user accounts, this field will contain the name of the computer or device that this account belongs to, for example: “ComputerName”."
Lookup Audit Policy Configuration Settings
C:\> AuditPol.exe /get /subcategory:"User Account Management"
LEFT/RIGHT arrow keys for navigation
Back to List