Event ID 5169

A directory service object was modified.

A directory service object was modified.

Subject:
    Security ID:        %3
    Account Name:       %4
    Account Domain:     %5
    Logon ID:           %6

Directory Service:
    Name:   %7
    Type:   %8

Object:
    DN:     %9
    GUID:   %10
    Class:  %11

Attribute:
    LDAP Display Name:  %12
    Syntax (OID):       %13
    Value:              %14
    Expiration Time:    %15

Operation:
    Type:                       %16
    Correlation ID:             %1
    Application Correlation ID: %2


This event documents modifications to AD objects, identifying the object, user, attribute modified, the new value of the attribute if applicable and the operation performed.

Auditing:     Conditional

Use it for sensitive groups (Domain Admins), Service Accounts, and Root OUs.


Volume:     Low

The expected volume for this event is low in typical environments utilizing targeted SACLs.




NameFieldInsertion StringOSExample
Correlation IDOpCorrelationID%1Any {02647639-8626-...}
Application Correlation IDAppCorrelationID%2Any -
Security IDSubjectUserSid%3Any S-1-5-21
Account NameSubjectUserName%4Any dadmin
Account DomainSubjectDomainName%5Any CONTOSO
Logon IDSubjectLogonId%6Any 0x32004
Directory Service NameDSName%7Any contoso.local
Directory Service TypeDSType%8Any %%676
Object DNObjectDN%9Any CN=Jeff Smith,OU=Sales...
Object GUIDObjectGUID%10Any {4f3a1b2c-8d9e-...}
Object ClassObjectClass%11Any user
LDAP Display NameAttributeLDAPDisplayName%12Any description
Syntax (OID)AttributeSyntaxOID%13Any 2.5.5.12
ValueAttributeValue%14Any Senior Developer
Senior DeveloperAttributeValueExpiration%15Any 0x7FFFF...
Operation TypeOperationType%16Any %%14675


Lookup Audit Policy Configuration Settings

C:\> AuditPol.exe /get /subcategory:"Directory Service Access"



LEFT/RIGHT arrow keys for navigation

Back to List