Event ID 5379

Records instances where Credential Manager credentials were read

Credential Manager credentials were read.

Subject:
    Security ID:        %1
    Account Name:       %2
    Account Domain:     %3
    Logon ID:       %4
    Read Operation:     %5

This event occurs when a user performs a read operation on stored credentials in Credential Manager.


When a user or a service accesses credentials (like Windows credentials, web credentials, domain tokens, or certificates) stored within the Windows Credential Manager vault, this event is triggered.

Some of the insertion strings (TargetName and below) will now show in the event message and are only available in the XML view of the event.

Auditing:     Conditional


Volume:     LowMediumHighVery High

Low to medium on servers, high to very high on workstations




NameFieldInsertion StringOSExample
Security IDSubjectUserSid%1Any NT AUTHORITY\SYSTEM
Account NameSubjectUserName%2Any SERVER10$
Account DomainSubjectDomainName%3Any THEDOMAIN
Logon IDSubjectLogonId%4Any 0x3e7
TargetNameTargetName%5Any MicrosoftAccount:user=02jfjnefanmamzjt
TypeType%6Any 0
CountOfCredentialsReturnedCountOfCredentialsReturned%7Any 0
ReadOperationReadOperation%8Any Enumerate Credentials
ReturnCodeReturnCode%9Any 3221226021
ProcessCreationTimeProcessCreationTime%10Any 2026-06-20T16:16:13.611218300Z
ClientProcessIdClientProcessId%11Any 12345


Lookup Audit Policy Configuration Settings

C:\> AuditPol.exe /get /subcategory:"User Account Management"



LEFT/RIGHT arrow keys for navigation

Back to List