Event ID 4794
An attempt was made to set the Directory Services Restore Mode administrator passwordAn attempt was made to set the Directory Services Restore Mode administrator password. Subject: Security ID: %1 Account Name: %2 Account Domain: %3 Logon ID: %4 Additional Information: Caller Workstation: %5 Status Code: %6
This event generates every time Directory Services Restore Mode (DSRM) administrator password is changed.
This event generates only on domain controllers.
Lookup Audit Policy Configuration Settings
C:\> AuditPol.exe /get /subcategory:"User Account Management"
Operating Systems:
Windows 2008 R2 Windows 2012 R2 Windows 2016 Windows 2008 Windows 2012 Windows 2019 Windows 2022Tags:
Domain Controller Audit Success Audit FailureLEFT/RIGHT arrow keys for navigation
Back to List