Event ID 4782

The password hash of an account was accessed

The password hash an account was accessed.

Subject:
    Security ID:        %3
    Account Name:       %4
    Account Domain:     %5
    Logon ID:       %6

Target Account:
    Account Name:       %1
    Account Domain:     %2


This event generates on domain controllers during password migration of an account using Active Directory Migration Toolkit.

Typically “Subject\Security ID” is the SYSTEM account.

Auditing:     Always

Monitor for all events of this type, because any actions with account’s password hashes should be planned. If this action was not planned, investigate the reason for the change.


Volume:     Low


Microsoft Documentation

Event ID - 4782



NameFieldInsertion StringOSExample
Account NameTargetUserName%1Any bSmith
Account DomainTargetDomainName%2Any DOMAIN
Security IDSubjectUserSid%3Any SYSTEM
Account NameSubjectUserName%4Any DC01$
Account DomainSubjectDomainName%5Any DOMAIN


Lookup Audit Policy Configuration Settings

C:\> AuditPol.exe /get /subcategory:"Other Account Management Events"



LEFT/RIGHT arrow keys for navigation

Back to List