Event ID 4782
The password hash an account was accessedThe password hash an account was accessed. Subject: Security ID: %3 Account Name: %4 Account Domain: %5 Logon ID: %6 Target Account: Account Name: %1 Account Domain: %2
This event generates on domain controllers during password migration of an account using Active Directory Migration Toolkit.
Typically “Subject\Security ID” is the SYSTEM account.
Auditing:
Always
Monitor for all events of this type, because any actions with account’s password hashes should be planned. If this action was not planned, investigate the reason for the change.
Volume:
Low
Microsoft Documentation
Lookup Audit Policy Configuration Settings
C:\> AuditPol.exe /get /subcategory:"Other Account Management Events"
Operating Systems:
Windows 2008 R2 Windows 2012 R2 Windows 2016 Windows 2008 Windows 2008 Windows 2012 Windows 2019 Windows 2022Tags:
Domain Controller Audit SuccessLEFT/RIGHT arrow keys for navigation
Back to List