Microsoft-Windows-Directory-Services-SAM
112 events across 1 channel
Event ID 12288 — SAM failed to write changes to the database.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
__binLength | — |
Event ID 12289 — SAM failed to restore the database to an earlier state.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
__binLength | — |
Event ID 12290 — SAM failed to update the SAM database.
Message
Event ID 12291 — SAM failed to start the TCP/IP or SPX/IPX listening thread
Message
Fields
| Name | Description |
|---|---|
LogStatus | — |
__binLength | — |
Event ID 12292 — There are two or more objects that have the same account name attribute in the SAM database.
Message
Fields
| Name | Description |
|---|---|
AccountDistinguishedName | — |
Event ID 12293 — There are two or more objects that have the same SID attribute in the SAM database.
Message
Fields
| Name | Description |
|---|---|
AccountDistinguishedName | — |
Event ID 12294 — The SAM database was unable to lockout the account of %1 due to a resource error, such as a hard disk write failure.
Message
Fields
| Name | Description |
|---|---|
UserName | — |
ErrorCode | — |
__binLength | — |
Event ID 12295 — The SAM database attempted to delete the file %1 as it contains account information that is no longer used.
Message
Fields
| Name | Description |
|---|---|
FilePath | — |
WinError | — |
__binLength | — |
Event ID 12296 — The SAM database attempted to clear the directory %1 in order to remove files that were once used by the Directory Service.
Message
Fields
| Name | Description |
|---|---|
DirectoryPath | — |
WinError | — |
__binLength | — |
Event ID 12297 — %1 is now the primary domain controller for the domain.
Message
Fields
| Name | Description |
|---|---|
ComputerName | — |
Event ID 12298 — The account %1 cannot be converted to be a domain controller account as its object class attribute in the directory is not computer or is not deriv...
Message
Fields
| Name | Description |
|---|---|
ComputerName | — |
Event ID 12299 — The attempt to check whether group caching has been enabled in the Security Accounts Manager has failed, most likely due to lack of resources.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
__binLength | — |
Event ID 12300 — The group caching option in the Security Accounts Manager has now been properly updated.
Message
Event ID 12301 — The group caching option in the Security Accounts Manager has now been properly updated.
Message
Event ID 12302 — The %1 package failed to update additional credentials for user %2.
Message
Fields
| Name | Description |
|---|---|
SecurityPackage | — |
UserName | — |
ErrorCode | — |
__binLength | — |
Event ID 12303 — There are two or more well known objects that have the same SID attribute in the SAM database.
Message
Fields
| Name | Description |
|---|---|
AccountDistinguishedName | — |
Event ID 12304 — There are two or more objects that have the same account name attribute in the SAM database.
Message
Fields
| Name | Description |
|---|---|
AccountDistinguishedName | — |
SystemAssignedAccountName | — |
Event ID 12305 — An error occurred while creating new default accounts for this domain.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
__binLength | — |
Event ID 16384 — The account %1 could not be upgraded since there is an account with an equivalent name.
Message
Fields
| Name | Description |
|---|---|
AccountName | — |
ErrorCode | — |
__binLength | — |
Event ID 16385 — An error occurred upgrading user %1.
Message
Fields
| Name | Description |
|---|---|
UserName | — |
ErrorCode | — |
__binLength | — |
Event ID 16386 — An error occurred trying to read a user object from the old database.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
__binLength | — |
Event ID 16387 — An error occurred upgrading alias %1.
Message
Fields
| Name | Description |
|---|---|
GroupName | — |
ErrorCode | — |
__binLength | — |
Event ID 16388 — An error occurred trying to read an alias object from the old database.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
__binLength | — |
Event ID 16389 — An error occurred upgrading group %1.
Message
Fields
| Name | Description |
|---|---|
GroupName | — |
ErrorCode | — |
__binLength | — |
Event ID 16390 — An error occurred trying to read a group object from the old database.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
__binLength | — |
Event ID 16391 — An error occurred trying to add account %1 to alias %2.
Message
Fields
| Name | Description |
|---|---|
AccountDistinguishedName | — |
GroupName | — |
ErrorCode | — |
__binLength | — |
Event ID 16392 — The account with the sid %1 could not be added to group %2.
Message
Fields
| Name | Description |
|---|---|
AccountSID | — |
AccountDistinguishedName | — |
ErrorCode | — |
__binLength | — |
Event ID 16393 — An error occurred trying to add account %1 to group %2.
Message
Fields
| Name | Description |
|---|---|
AccountDistinguishedName | — |
GroupName | — |
ErrorCode | — |
__binLength | — |
Event ID 16394 — The account with the rid %1 could not be added to group %2.
Message
Fields
| Name | Description |
|---|---|
AccountRID | — |
GroupName | — |
ErrorCode | — |
__binLength | — |
Event ID 16395 — A fatal error occurred trying to transfer the SAM account database into the directory service.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
__binLength | — |
Event ID 16397 — Setting the administrator's password to the string you specified failed.
Message
Event ID 16398 — An error occurred trying to upgrade a SAM user's User_Parameters attribute.
Message
Fields
| Name | Description |
|---|---|
SecurityPackage | — |
__binLength | — |
ErrorCode | — |
Event ID 16399 — An error occured trying to set User Parameters attribute for this user This operation is failed.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
__binLength | — |
Event ID 16400 — An error occured trying to upgrade the following SAM User Object - %1.
Message
Fields
| Name | Description |
|---|---|
UserName | — |
ErrorCode | — |
__binLength | — |
Event ID 16401 — An error occurred when trying to add the account %1 to the group %2.
Message
Fields
| Name | Description |
|---|---|
Name | — |
AccountName | — |
GroupName | — |
ErrorMessage | — |
Binary | — |
Example Event
system:
provider: Microsoft-Windows-Directory-Services-SAM
guid: 0D4FDC09-8C27-494A-BDA0-505E4FD8ADAE
event_source_name: ''
event_id: 16401
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854775808
time_created: '2022-04-07T08:14:31.641248+00:00'
event_record_id: 628
correlation: {}
execution:
process_id: 648
thread_id: 652
channel: System
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
Name: SAMMSG_MEMBERSHIP_SETUP_ERROR_NO_GROUP
AccountName: INTERNET USER
GroupName: IIS_IUSRS
ErrorMessage: "The specified local group does not exist.\r\n"
Binary: '60050000'
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 16402 — An error occurred when trying to add the account %1 to the group %2.
Message
Fields
| Name | Description |
|---|---|
AccountName | — |
GroupName | — |
ErrorMessage | — |
ErrorCode | — |
__binLength | — |
Event ID 16403 — The error ".
Message
Fields
| Name | Description |
|---|---|
Name | — |
AccountName | — |
ErrorMessage | — |
Binary | — |
Example Event
system:
provider: Microsoft-Windows-Directory-Services-SAM
guid: 0D4FDC09-8C27-494A-BDA0-505E4FD8ADAE
event_source_name: ''
event_id: 16403
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854775808
time_created: '2022-04-07T08:14:31.644632+00:00'
event_record_id: 638
correlation: {}
execution:
process_id: 648
thread_id: 652
channel: System
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
Name: SAMMSG_USER_SETUP_ERROR
AccountName: WDAGUtilityAccount
ErrorMessage: "The specified network password is not correct.\r\n"
Binary: '56000000'
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 16404 — The Security Accounts Manager failed to add the Enterprise Admins group to the local Administrators alias.
Message
Event ID 16405 — During the installation of the Directory Service, this server's machine account was deleted hence preventing this Domain Controller from starting up.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
__binLength | — |
Event ID 16406 — The Security Account Database detected that the well known account %1 does not exist.
Message
Fields
| Name | Description |
|---|---|
UserName | — |
ErrorCode | — |
__binLength | — |
Event ID 16407 — The Security Account Database detected that the well known group or local group %1 does not exist.
Message
Fields
| Name | Description |
|---|---|
GroupName | — |
ErrorCode | — |
__binLength | — |
Event ID 16408 — Domain operation mode has been changed to Native Mode.
Message
Event ID 16409 — Active Directory Domain Services failed to add a security principal to well known security principals container.
Message
Fields
| Name | Description |
|---|---|
AccountName | — |
__binLength | — |
ErrorCode | — |
Event ID 16410 — Active Directory Domain Services failed to add all of the new security principals to well known security principals container.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
__binLength | — |
Event ID 16411 — Active Directory Domain Services failed to rename a security principal in well known security principals container.
Message
Fields
| Name | Description |
|---|---|
AccountName | — |
__binLength | — |
ErrorCode | — |
Event ID 16412 — Active Directory Domain Services failed to rename some of the security principals in well known security principals container.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
__binLength | — |
Event ID 16413 — An error occurred when trying to remove the account %1 from the group %2.
Message
Fields
| Name | Description |
|---|---|
Name | — |
AccountName | — |
GroupName | — |
ErrorString | — |
Binary | — |
Example Event
system:
provider: Microsoft-Windows-Directory-Services-SAM
guid: 0D4FDC09-8C27-494A-BDA0-505E4FD8ADAE
event_source_name: ''
event_id: 16413
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854775808
time_created: '2022-04-07T08:14:31.656794+00:00'
event_record_id: 639
correlation: {}
execution:
process_id: 648
thread_id: 652
channel: System
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
Name: SAMMSG_MEMBERSHIP_REMOVAL_SETUP_ERROR
AccountName: Network Service
GroupName: Performance Log Users
ErrorString: "The system cannot find the file specified.\r\n"
Binary: '02000000'
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 16640 — The account-identifier allocator finished initializing.
Message
Fields
| Name | Description |
|---|---|
MinimumDomainRID | — |
MaximumDomainRID | — |
RIDPoolSize | — |
MinimumAvailableRID | — |
MaximumAvailableRID | — |
MinimumAllocatedRID | — |
MaximumAllocatedRID | — |
CurrentRIDValue | — |
Event ID 16641 — The account-identifier pool for this domain controller could not be updated.
Message
Event ID 16642 — The account-identifier allocator was unable to assign a new identifier.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
__binLength | — |
Event ID 16643 — An initial account-identifier pool has not yet been allocated to this domain controller.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
__binLength | — |
Event ID 16644 — The maximum domain account identifier value has been reached.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
__binLength | — |
Event ID 16645 — The maximum account identifier allocated to this domain controller has been assigned.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
__binLength | — |
Event ID 16646 — The computed account identifier is invalid because it is out of the range of the current account-identifier pool belonging to this domain controller.
Message
Fields
| Name | Description |
|---|---|
ComputedRIDValue | — |
ErrorCode | — |
__binLength | — |
Event ID 16647 — The domain controller is starting a request for a new account-identifier pool.
Message
Fields
| Name | Description |
|---|---|
Name | — |
Example Event
system:
provider: Microsoft-Windows-Directory-Services-SAM
guid: 0D4FDC09-8C27-494A-BDA0-505E4FD8ADAE
event_source_name: ''
event_id: 16647
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854775808
time_created: '2022-04-07T08:14:41.496467+00:00'
event_record_id: 696
correlation: {}
execution:
process_id: 648
thread_id: 856
channel: System
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
Name: SAMMSG_REQUESTING_NEW_RID_POOL
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 16648 — The request for a new account-identifier pool has completed successfully.
Message
Fields
| Name | Description |
|---|---|
Name | — |
Binary | — |
Example Event
system:
provider: Microsoft-Windows-Directory-Services-SAM
guid: 0D4FDC09-8C27-494A-BDA0-505E4FD8ADAE
event_source_name: ''
event_id: 16648
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854775808
time_created: '2022-04-07T08:14:41.498371+00:00'
event_record_id: 697
correlation: {}
execution:
process_id: 648
thread_id: 856
channel: System
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
Name: SAMMSG_RID_REQUEST_STATUS_SUCCESS
Binary: '00000000'
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 16649 — The account-identifier-manager object creation completed.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
__binLength | — |
Event ID 16650 — The account-identifier allocator failed to initialize properly.
Message
Event ID 16651 — The request for a new account-identifier pool failed.
Message
Fields
| Name | Description |
|---|---|
ErrorMessage | — |
Event ID 16652 — The domain controller is booting to directory services restore mode.
Message
Event ID 16653 — A pool size for account-identifiers (RIDs) that was configured by an Administrator is greater than the supported maximum.
Message
Fields
| Name | Description |
|---|---|
Maximum | — |
Event ID 16654 — A pool of account-identifiers (RIDs) has been invalidated.
Message
Event ID 16655 — The global maximum for account-identifiers (RIDs) has been increased to %1.
Message
Fields
| Name | Description |
|---|---|
NewValue | — |
Event ID 16656 — Action required!
Message
Fields
| Name | Description |
|---|---|
CeilingTriggerRid | — |
Event ID 16657 — Action required!
Message
Fields
| Name | Description |
|---|---|
CeilingTriggerRid | — |
Event ID 16658 — This event is a periodic update on the remaining total quantity of available account-identifiers (RIDs).
Message
Fields
| Name | Description |
|---|---|
RemainingRids | — |
Event ID 16935 — Failed to secure the machine account %1.
Message
Fields
| Name | Description |
|---|---|
ComputerName | — |
ErrorCode | — |
__binLength | — |
Event ID 16936 — Failed to secure the machine account %1.
Message
Fields
| Name | Description |
|---|---|
ComputerName | — |
ErrorCode | — |
__binLength | — |
Event ID 16937 — Secured the machine account %1.
Message
Fields
| Name | Description |
|---|---|
Name | — |
ComputerName | — |
Binary | — |
Example Event
system:
provider: Microsoft-Windows-Directory-Services-SAM
guid: 0D4FDC09-8C27-494A-BDA0-505E4FD8ADAE
event_source_name: ''
event_id: 16937
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854775808
time_created: '2022-04-07T08:14:31.637430+00:00'
event_record_id: 624
correlation: {}
execution:
process_id: 648
thread_id: 652
channel: System
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
Name: SAMMSG_MACHINE_ACCOUNT_SECURE
ComputerName: ''
Binary: '00000000'
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 16944 — The certificate that is used for authentication does not have an issuance policy descriptor corresponding to OID %1 in the Active Directory database.
Message
Fields
| Name | Description |
|---|---|
OID | — |
ErrorCode | — |
Event ID 16945 — The certificate issuance policy that is represented by OID %2 does not have a link to a security identifier (SID), or this link cannot be read.
Message
Fields
| Name | Description |
|---|---|
OID | — |
OID Object DN | — |
ErrorCode | — |
OIDObjectDN | — |
Event ID 16946 — Multiple certificate issuance policy descriptors were found in the Active Directory database.
Message
Fields
| Name | Description |
|---|---|
OID | — |
Event ID 16947 — The certificate issuance policy descriptor %2 is linked through its attribute msDS-OIDToGroupLink to a group that is not a security group, has memb...
Message
Fields
| Name | Description |
|---|---|
OID | — |
OID Object DN | — |
Group DN | — |
Group GUID | — |
Group SID | — |
ErrorCode | — |
OIDObjectDN | — |
GroupDN | — |
GroupGUID | — |
GroupSID | — |
Event ID 16948 — The requested modification for group %1 could not be performed.
Message
Fields
| Name | Description |
|---|---|
Group DN | — |
Group GUID | — |
Group SID | — |
Operation | — |
ErrorCode | — |
GroupDN | — |
GroupGUID | — |
GroupSID | — |
Event ID 16949 — The certificate issuance policy descriptor %1 cannot be linked to group %2.
Message
Fields
| Name | Description |
|---|---|
OID Name | — |
Group Name | — |
Group GUID | — |
Group SID | — |
ErrorCode | — |
OIDName | — |
GroupName | — |
GroupGUID | — |
GroupSID | — |
Event ID 16950 — The following invalid claims issued to user %1 have been dropped: %2.
Message
Fields
| Name | Description |
|---|---|
User | — |
DroppedClaims | — |
Event ID 16951 — Claims issued to user %1 could not be validated and have been dropped.
Message
Fields
| Name | Description |
|---|---|
User | — |
Error code: | — |
Errorcode | — |
Event ID 16952 — Claims issued to user %1 could not be validated and have been dropped.
Message
Fields
| Name | Description |
|---|---|
User | — |
Error code: | — |
Errorcode | — |
Event ID 16953 — The password notification DLL %1 failed to load with error %4.
Message
Fields
| Name | Description |
|---|---|
NotificationPackage: | — |
Registry key: | — |
Registry value: | — |
Error code: | — |
NotificationPackage | — |
Registrykey | — |
Registryvalue | — |
Errorcode | — |
Event ID 16960 — SAM was configured to not listen on the TCP protocol.
Message
Event ID 16961 — Legacy password validation mode has been enabled on this machine.
Message
Event ID 16962 — Remote calls to the SAM database are being restricted using the default security descriptor.
Message
Fields
| Name | Description |
|---|---|
Name | Remote calls to the SAM database are being restricted using the default security descriptor. |
Default SD String: | — |
Example Event
system:
provider: Microsoft-Windows-Directory-Services-SAM
guid: 0D4FDC09-8C27-494A-BDA0-505E4FD8ADAE
event_source_name: ''
event_id: 16962
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854775808
time_created: '2023-11-06T06:25:28.054783+00:00'
event_record_id: 1666
correlation:
ActivityID: F590C418-1079-0001-5BC5-90F57910DA01
execution:
process_id: 808
thread_id: 812
channel: System
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
Name: SAMMSG_RESTRICT_REMOTE_SAM_DEFAULT_SD
'Default SD String:': O:SYG:SYD:(A;;RC;;;BA)
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 16963 — Remote calls to the SAM database are being restricted using the configured registry security descriptor.
Message
Fields
| Name | Description |
|---|---|
RegistrySDString | — |
Event ID 16964 — The registry security descriptor is malformed.
Message
Fields
| Name | Description |
|---|---|
MalformedSDString | — |
DefaultSDString | — |
Event ID 16965 — A remote call to the SAM database has been denied.
Message
Fields
| Name | Description |
|---|---|
Client_SID | — |
Network_address | — |
ClientSID | — |
ClientNetworkAddress | — |
Event ID 16966 — Audit only mode is now enabled for remote calls to the SAM database.
Message
Event ID 16967 — Audit only mode is now disabled for remote calls to the SAM database.
Message
Event ID 16968 — Audit only mode is currently enabled for remote calls to the SAM database.
Message
Fields
| Name | Description |
|---|---|
ClientSID | — |
ClientNetworkAddress | — |
Event ID 16969 — %2 remote calls to the SAM database have been denied in the past %1 seconds throttling window.
Message
Fields
| Name | Description |
|---|---|
Throttle window: | — |
Suppressed Message Count: | — |
Throttlewindow | — |
SuppressedMessageCount | — |
Event ID 16976 — An error occurred while configuring one or more well-known accounts for this domain.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 16977 — The domain is configured with the following minimum password length-related settings.
Message
Fields
| Name | Description |
|---|---|
Name | — |
MinimumPasswordLength | — |
RelaxMinimumPasswordLengthLimits | — |
MinimumPasswordLengthAudit | — |
Example Event
system:
provider: Microsoft-Windows-Directory-Services-SAM
guid: 0D4FDC09-8C27-494A-BDA0-505E4FD8ADAE
event_source_name: ''
event_id: 16977
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854775808
time_created: '2023-11-06T06:25:34.991632+00:00'
event_record_id: 1669
correlation:
ActivityID: F590C418-1079-0001-5BC5-90F57910DA01
execution:
process_id: 808
thread_id: 896
channel: System
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
Name: SAMMSG_MINPWDLEN_SETTINGS_IN_EFFECT
MinimumPasswordLength: 0
RelaxMinimumPasswordLengthLimits: 0
MinimumPasswordLengthAudit: -1
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 16978 — The following account has been configured with a password whose length is shorter than the current MinimumPasswordLengthAudit setting.
Message
Fields
| Name | Description |
|---|---|
AccountName | — |
MinimumPasswordLength | — |
MinimumPasswordLengthAudit | — |
Event ID 16979 — The domain is incorrectly configured with a MinimumPasswordLength setting that is greater than 14 while RelaxMinimumPasswordLengthLimits is either ...
Message
Fields
| Name | Description |
|---|---|
Currently_configured_MinimumPasswordLength_value | — |
MinimumPasswordLength | — |
Event ID 16980 — The security account manager has detected the use of a ROCA-vulnerable Windows Hello for Business key during authentication by the following account.
Message
Fields
| Name | Description |
|---|---|
Account_DN | — |
Account_SID | — |
KeyHash | — |
AccountDN | — |
AccountSID | — |
Event ID 16981 — The security account manager has detected and blocked the use of a ROCA-vulnerable Windows Hello for Business key during authentication by the foll...
Message
Fields
| Name | Description |
|---|---|
Account_DN | — |
Account_SID | — |
KeyHash | — |
AccountDN | — |
AccountSID | — |
Event ID 16982 — The security account manager is now logging verbose events for remote clients that call legacy password change or set RPC methods.
Message
Event ID 16983 — The security account manager is now logging periodic summary events for remote clients that call legacy password change or set RPC methods.
Message
Fields
| Name | Description |
|---|---|
Name | — |
Example Event
system:
provider: Microsoft-Windows-Directory-Services-SAM
guid: 0D4FDC09-8C27-494A-BDA0-505E4FD8ADAE
event_source_name: ''
event_id: 16983
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854775808
time_created: '2023-11-06T06:25:28.084211+00:00'
event_record_id: 1668
correlation:
ActivityID: F590C418-1079-0001-5BC5-90F57910DA01
execution:
process_id: 808
thread_id: 812
channel: System
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
Name: SAMMSG_AUDIT_LEGACY_PWD_RPC_METHODS_OFF
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 16984 — The security account manager detected %1 legacy password change or set RPC method calls in the past %2 minutes.
Message
Fields
| Name | Description |
|---|---|
Number of RPC methods: | — |
Throttle Window: | — |
NumberofRPCmethods | — |
ThrottleWindow | — |
Event ID 16985 — The security account manager detected the use of a legacy password change or set RPC method from a network client.
Message
Fields
| Name | Description |
|---|---|
RPC_Method | [Details] RPC Method. |
Username | [Details] Username. |
Client_SID | [Details] Client SID. |
Client_Network_Address | [Details] Client Network Address. |
RPCMethod | — |
UserAccountName | — |
ClientSID | — |
ClientNetworkAddress | — |
Event ID 16986 — The security account manager has detected one or more duplicated names for a local account.
Message
Fields
| Name | Description |
|---|---|
Retained_account_name | — |
Deleted_account_names | — |
AccountRidHex | — |
AccountRid | — |
SavedAccountName | — |
DeletedAccountNames | — |
Event ID 16987 — The security account manager has detected one or more duplicated names for a local account.
Message
Fields
| Name | Description |
|---|---|
AccountRidHex | — |
AccountRid | — |
DuplicatedAccountNames | — |
RetainedAccountName | — |
Event ID 16988 — The security account manager encountered one or more fatal errors on startup which will not allow the machine to start.
Message
Fields
| Name | Description |
|---|---|
Service_startup_error_status | — |
StatusHex | — |
__binLength | — |
DiagnosticInfo | — |
Event ID 16989 — The security account manager encountered one or more non-fatal errors on startup.
Message
Fields
| Name | Description |
|---|---|
DiagnosticInfo | — |
__binLength | — |
Event ID 16990 — The security account manager blocked a non-administrator from creating an Active Directory account in this domain with mismatched objectClass and u...
Message
Fields
| Name | Description |
|---|---|
Account_name | [Details] Account name. |
Account_objectClass | [Details] Account objectClass. |
userAccountControl | [Details] userAccountControl. |
Caller_address | [Details] Caller address. |
Caller_SID | [Details] Caller SID. |
Accountname | — |
AccountobjectClass | — |
userAccountcontrol | — |
Calleraddress | — |
CallerSID | — |
Event ID 16991 — The security account manager blocked a non-administrator from creating or renaming a computer account using an invalid sAMAccountName.
Message
Fields
| Name | Description |
|---|---|
Attempted_sAMAccountName | — |
SamAccountName | — |
Event ID 16992 — The security account manager is now configuring the local password and lockout policies in accordance with regional policy.
Message
Event ID 16993 — The security account manager successfully initialized the Local Administrator Password Solution (LAPS) extension dll.
Message
Event ID 16994 — The security account manager failed to initialize the Local Administrator Password Solution (LAPS) extension dll.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 16995 — The security account manager is using the specified security descriptor for validation of computer account re-use attempts during domain join.
Message
Fields
| Name | Description |
|---|---|
SDDL_Value | — |
RegistrySDString | — |
Event ID 16996 — The security descriptor that contains the computer account re-use allow list being used to validate client requests during domain join is malformed.
Message
Fields
| Name | Description |
|---|---|
SDDL_Value | — |
RegistrySDString | — |
Event ID 16997 — The security account manager found a computer account that appears to be orphaned and does not have an existing owner.
Message
Fields
| Name | Description |
|---|---|
Computer_Account | — |
Computer_Account_Owner | — |
ComputerAccountSID | — |
ComputerAccountOwnerSID | — |
Event ID 16998 — The security account manager rejected a client request to re-use a computer account during domain join.
Message
Fields
| Name | Description |
|---|---|
Computer_Account | — |
Computer_Account_Owner | — |
Client_Account | — |
ComputerAccountSID | — |
ComputerAccountOwnerSID | — |
ClientUserAccountSID | — |
__binLength | — |
ErrorCode | — |