Event ID: 4774An account was mapped for logon
An account was mapped for logon. Authentication Package: %1 Account UPN: %2 Mapped Name: %3
Although this event officially logs both success and failure events, only failure events appear to actually be logged.
Lookup Audit Policy Configuration Settings
C:\> AuditPol.exe /get /subcategory:"Credential Validation"
Operating Systems:Windows 2008 Windows 2008 R2 Windows 2012 Windows 2012 R2 Windows 2016 Windows 2019
Tags:Domain Controller Audit Success Audit Failure
Audit Category:Account Logon
Audit Subcategory:Credential Validation
LEFT/RIGHT arrow keys for navigationBack to List