Event ID 4782
The password hash of an account was accessedThe password hash an account was accessed.
Subject:
Security ID: %3
Account Name: %4
Account Domain: %5
Logon ID: %6
Target Account:
Account Name: %1
Account Domain: %2This event generates on domain controllers during password migration of an account using Active Directory Migration Toolkit.
Typically “Subject\Security ID” is the SYSTEM account.
Auditing: Always Monitor for all events of this type, because any actions with account’s password hashes should be planned. If this action was not planned, investigate the reason for the change.
| Name | Field | Insertion String | OS | Example | |
|---|
| Account Name | TargetUserName | %1 | Any | bSmith |
| Account Domain | TargetDomainName | %2 | Any | DOMAIN |
| Security ID | SubjectUserSid | %3 | Any | SYSTEM |
| Account Name | SubjectUserName | %4 | Any | DC01$ |
| Account Domain | SubjectDomainName | %5 | Any | DOMAIN |
The name of the account for which the password hash was migrated.
User account example: bSmith
Computer account example: SERVER01$
Subject’s domain or computer name. Formats vary, and include the following:
Domain NETBIOS name example: DOMAIN
Lowercase full domain name: domain.local
Uppercase full domain name: DOMAIN.LOCAL
SID of account that requested hash migration operation. Event Viewer automatically tries to resolve SIDs and show the account name. If the SID cannot be resolved, you will see the source data in the event.
The name of the account that requested hash migration operation.
Subject’s domain name. Formats vary, and include the following:
Domain NETBIOS name example: DOMAIN
Lowercase full domain name: domain.local
Uppercase full domain name: DOMAIN.LOCAL
For ANONYMOUS LOGON you will see NT AUTHORITY value for this field.
Lookup Audit Policy Configuration Settings
C:\> AuditPol.exe /get /subcategory:"Other Account Management Events"
LEFT/RIGHT arrow keys for navigation
Back to List