Event ID: 5138

A directory service object was undeleted.

A directory service object was undeleted.

Subject:
    Security ID:        %3
    Account Name:       %4
    Account Domain:     %5
    Logon ID:       %6

Directory Service:
    Name:   %7
    Type:   %8

Object:
    Old DN: %9
    New DN: %10
    GUID:   %11
    Class:  %12

Operation:
    Correlation ID: %1
    Application Correlation ID: %2
Microsoft Documentation

Event ID - 5138



This event generates every time an Active Directory object is undeleted. It happens, for example, when an Active Directory object was restored from the Active Directory Recycle Bin.

This event only generates if the container to which the Active Directory object was restored has a particular entry in its SACL: the “Create” action, auditing for specific classes or objects. An example is the “Create User objects” action.



Lookup Audit Policy Configuration Settings

C:\> AuditPol.exe /get /subcategory:"Directory Service Changes"
How to enable Windows Auditing



LEFT/RIGHT arrow keys for navigation

Back to List