Event ID 4774
An account was mapped for logonAn account was mapped for logon. Authentication Package: %1 Account UPN: %2 Mapped Name: %3
Auditing:
Although this event officially logs both success and failure events, only failure events appear to actually be logged.
Microsoft Documentation
Lookup Audit Policy Configuration Settings
C:\> AuditPol.exe /get /subcategory:"Credential Validation"
Operating Systems:
Windows 2008 Windows 2008 R2 Windows 2012 Windows 2012 R2 Windows 2016 Windows 2019 Windows 2022Tags:
Domain Controller Audit Success Audit FailureLEFT/RIGHT arrow keys for navigation
Back to List