Microsoft-Windows-Directory-Services-SAM
112 events across 1 channel
Event ID 12288 — SAM failed to write changes to the database.
Event ID 12289 — SAM failed to restore the database to an earlier state.
Event ID 12290 — SAM failed to update the SAM database.
Description
SAM failed to update the SAM database. It will try again next time you reboot the machine.
Message #
Event ID 12291 — SAM failed to start the TCP/IP or SPX/IPX listening thread
Event ID 12292 — There are two or more objects that have the same account name attribute in the SAM database.
Event ID 12293 — There are two or more objects that have the same SID attribute in the SAM database.
Event ID 12294 — The SAM database was unable to lockout the account of UserName due to a resource error, such as a hard disk write failure.
Event ID 12295 — The SAM database attempted to delete the file FilePath as it contains account information that is no longer used.
Event ID 12296 — The SAM database attempted to clear the directory DirectoryPath in order to remove files that were once used by the Directory Service.
Description
The SAM database attempted to clear the directory DirectoryPath in order to remove files that were once used by the Directory Service. The error is in record data. Please have an admin delete these files.
Message #
Fields #
| Name | Description |
|---|---|
DirectoryPath UnicodeString | — |
WinError Binary | — |
__binLength UInt32 | — |
Event ID 12297 — ComputerName is now the primary domain controller for the domain.
Event ID 12298 — The account ComputerName cannot be converted to be a domain controller account as its object class attribute in the directory is not computer or is not deriv...
Event ID 12299 — The attempt to check whether group caching has been enabled in the Security Accounts Manager has failed, most likely due to lack of resources.
Event ID 12300 — The group caching option in the Security Accounts Manager has now been properly updated.
Description
The group caching option in the Security Accounts Manager has now been properly updated. Group caching is enabled.
Message #
Event ID 12301 — The group caching option in the Security Accounts Manager has now been properly updated.
Description
The group caching option in the Security Accounts Manager has now been properly updated. Group caching is disabled.
Message #
Event ID 12302 — The SecurityPackage package failed to update additional credentials for user UserName.
Event ID 12303 — There are two or more well known objects that have the same SID attribute in the SAM database.
Event ID 12304 — There are two or more objects that have the same account name attribute in the SAM database.
Description
There are two or more objects that have the same account name attribute in the SAM database. The system has automatically renamed object AccountDistinguishedName to a system assigned account name SystemAssignedAccountName.
Message #
Fields #
| Name | Description |
|---|---|
AccountDistinguishedName UnicodeString | — |
SystemAssignedAccountName UnicodeString | — |
Event ID 12305 — An error occurred while creating new default accounts for this domain.
Event ID 16384 — The account AccountName could not be upgraded since there is an account with an equivalent name.
Event ID 16385 — An error occurred upgrading user UserName.
Event ID 16386 — An error occurred trying to read a user object from the old database.
Event ID 16387 — An error occurred upgrading alias GroupName.
Event ID 16388 — An error occurred trying to read an alias object from the old database.
Event ID 16389 — An error occurred upgrading group GroupName.
Event ID 16390 — An error occurred trying to read a group object from the old database.
Event ID 16391 — An error occurred trying to add account AccountDistinguishedName to alias GroupName.
Event ID 16392 — The account with the sid AccountSID could not be added to group AccountDistinguishedName.
Event ID 16393 — An error occurred trying to add account AccountDistinguishedName to group GroupName.
Event ID 16394 — The account with the rid AccountRID could not be added to group GroupName.
Event ID 16395 — A fatal error occurred trying to transfer the SAM account database into the directory service.
Event ID 16397 — Setting the administrator's password to the string you specified failed.
Description
Setting the administrator's password to the string you specified failed. Upon reboot the password will be blank; please reset once logged on.
Message #
Event ID 16398 — An error occurred trying to upgrade a SAM user's User_Parameters attribute.
Event ID 16399 — An error occured trying to set User Parameters attribute for this user This operation is failed.
Event ID 16400 — An error occured trying to upgrade the following SAM User Object - UserName.
Event ID 16401 — An error occurred when trying to add the account Name to the group AccountName.
#Description
An error occurred when trying to add the account Name to the group AccountName. The problem, "GroupName", occurred when trying to open the group. Please add the account manually.
Message #
Fields #
| Name | Description |
|---|---|
Name | — |
AccountName UnicodeString | — |
GroupName UnicodeString | — |
ErrorMessage UnicodeString | — |
Binary | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Directory-Services-SAM",
"guid": "0D4FDC09-8C27-494A-BDA0-505E4FD8ADAE",
"event_source_name": "",
"event_id": 16401,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2022-04-07T08:14:31.641248+00:00",
"event_record_id": 628,
"correlation": {},
"execution": {
"process_id": 648,
"thread_id": 652
},
"channel": "System",
"computer": "WIN-FPV0DSIC9O6.lab.local",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Name": "SAMMSG_MEMBERSHIP_SETUP_ERROR_NO_GROUP",
"AccountName": "INTERNET USER",
"GroupName": "IIS_IUSRS",
"ErrorMessage": "The specified local group does not exist.\r\n",
"Binary": "60050000"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 16402 — An error occurred when trying to add the account AccountName to the group GroupName.
Description
An error occurred when trying to add the account AccountName to the group GroupName. The problem, "ErrorMessage", occurred when trying to add the account to the group. Please add the account manually.
Message #
Fields #
| Name | Description |
|---|---|
AccountName UnicodeString | — |
GroupName UnicodeString | — |
ErrorMessage UnicodeString | — |
ErrorCode Binary | — |
__binLength UInt32 | — |
Event ID 16403 — The error "AccountName" occurred when trying to create the well known account Name.
#Description
The error "AccountName" occurred when trying to create the well known account Name. Please contact PSS to recover.
Message #
Fields #
| Name | Description |
|---|---|
Name | — |
AccountName UnicodeString | — |
ErrorMessage UnicodeString | — |
Binary | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Directory-Services-SAM",
"guid": "0D4FDC09-8C27-494A-BDA0-505E4FD8ADAE",
"event_source_name": "",
"event_id": 16403,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2022-04-07T08:14:31.644632+00:00",
"event_record_id": 638,
"correlation": {},
"execution": {
"process_id": 648,
"thread_id": 652
},
"channel": "System",
"computer": "WIN-FPV0DSIC9O6.lab.local",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Name": "SAMMSG_USER_SETUP_ERROR",
"AccountName": "WDAGUtilityAccount",
"ErrorMessage": "The specified network password is not correct.\r\n",
"Binary": "56000000"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 16404 — The Security Accounts Manager failed to add the Enterprise Admins group to the local Administrators alias.
Description
The Security Accounts Manager failed to add the Enterprise Admins group to the local Administrators alias. To ensure proper functioning of the domain; please add the account manually.
Message #
Event ID 16405 — During the installation of the Directory Service, this server's machine account was deleted hence preventing this Domain Controller from starting up.
Event ID 16406 — The Security Account Database detected that the well known account UserName does not exist.
Event ID 16407 — The Security Account Database detected that the well known group or local group GroupName does not exist.
Event ID 16408 — Domain operation mode has been changed to Native Mode.
Description
Domain operation mode has been changed to Native Mode. The change cannot be reversed.
Message #
Event ID 16409 — Active Directory Domain Services failed to add a security principal to well known security principals container.
Event ID 16410 — Active Directory Domain Services failed to add all of the new security principals to well known security principals container.
Event ID 16411 — Active Directory Domain Services failed to rename a security principal in well known security principals container.
Event ID 16412 — Active Directory Domain Services failed to rename some of the security principals in well known security principals container.
Event ID 16413 — An error occurred when trying to remove the account Name from the group AccountName.
#Description
An error occurred when trying to remove the account Name from the group AccountName. The problem, "GroupName", occurred when trying to remove the account from the group. Please remove the member manually.
Message #
Fields #
| Name | Description |
|---|---|
Name | — |
AccountName UnicodeString | — |
GroupName UnicodeString | — |
ErrorString UnicodeString | — |
Binary | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Directory-Services-SAM",
"guid": "0D4FDC09-8C27-494A-BDA0-505E4FD8ADAE",
"event_source_name": "",
"event_id": 16413,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2022-04-07T08:14:31.656794+00:00",
"event_record_id": 639,
"correlation": {},
"execution": {
"process_id": 648,
"thread_id": 652
},
"channel": "System",
"computer": "WIN-FPV0DSIC9O6.lab.local",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Name": "SAMMSG_MEMBERSHIP_REMOVAL_SETUP_ERROR",
"AccountName": "Network Service",
"GroupName": "Performance Log Users",
"ErrorString": "The system cannot find the file specified.\r\n",
"Binary": "02000000"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 16640 — The account-identifier allocator finished initializing.
Event ID 16641 — The account-identifier pool for this domain controller could not be updated.
Message #
Event ID 16642 — The account-identifier allocator was unable to assign a new identifier.
Event ID 16643 — An initial account-identifier pool has not yet been allocated to this domain controller.
Event ID 16644 — The maximum domain account identifier value has been reached.
Event ID 16645 — The maximum account identifier allocated to this domain controller has been assigned.
Event ID 16646 — The computed account identifier is invalid because it is out of the range of the current account-identifier pool belonging to this domain controller.
Event ID 16647 — The domain controller is starting a request for a new account-identifier pool.
#Description
The domain controller is starting a request for a new account-identifier pool.
Message #
Fields #
| Name | Description |
|---|---|
Name | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Directory-Services-SAM",
"guid": "0D4FDC09-8C27-494A-BDA0-505E4FD8ADAE",
"event_source_name": "",
"event_id": 16647,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2022-04-07T08:14:41.496467+00:00",
"event_record_id": 696,
"correlation": {},
"execution": {
"process_id": 648,
"thread_id": 856
},
"channel": "System",
"computer": "WIN-FPV0DSIC9O6.lab.local",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Name": "SAMMSG_REQUESTING_NEW_RID_POOL"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 16648 — The request for a new account-identifier pool has completed successfully.
#Description
The request for a new account-identifier pool has completed successfully.
Message #
Fields #
| Name | Description |
|---|---|
Name | — |
Binary | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Directory-Services-SAM",
"guid": "0D4FDC09-8C27-494A-BDA0-505E4FD8ADAE",
"event_source_name": "",
"event_id": 16648,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2022-04-07T08:14:41.498371+00:00",
"event_record_id": 697,
"correlation": {},
"execution": {
"process_id": 648,
"thread_id": 856
},
"channel": "System",
"computer": "WIN-FPV0DSIC9O6.lab.local",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Name": "SAMMSG_RID_REQUEST_STATUS_SUCCESS",
"Binary": "00000000"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 16649 — The account-identifier-manager object creation completed.
Event ID 16650 — The account-identifier allocator failed to initialize properly.
Message #
Event ID 16651 — The request for a new account-identifier pool failed.
Event ID 16652 — The domain controller is booting to directory services restore mode.
Description
The domain controller is booting to directory services restore mode.
Message #
Event ID 16653 — A pool size for account-identifiers (RIDs) that was configured by an Administrator is greater than the supported maximum.
Event ID 16654 — A pool of account-identifiers (RIDs) has been invalidated.
Description
A pool of account-identifiers (RIDs) has been invalidated. This may occur in the following expected cases.
Message #
Event ID 16655 — The global maximum for account-identifiers (RIDs) has been increased to NewValue.
Event ID 16658 — This event is a periodic update on the remaining total quantity of available account-identifiers (RIDs).
Event ID 16935 — Failed to secure the machine account ComputerName.
Event ID 16936 — Failed to secure the machine account ComputerName.
Event ID 16937 — Secured the machine account Name.
#Description
Secured the machine account Name. The builtin\account operators full control Access Control Entry was removed from the security descriptor on this object.
Message #
Fields #
| Name | Description |
|---|---|
Name | — |
ComputerName UnicodeString | — |
Binary | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Directory-Services-SAM",
"guid": "0D4FDC09-8C27-494A-BDA0-505E4FD8ADAE",
"event_source_name": "",
"event_id": 16937,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2022-04-07T08:14:31.637430+00:00",
"event_record_id": 624,
"correlation": {},
"execution": {
"process_id": 648,
"thread_id": 652
},
"channel": "System",
"computer": "WIN-FPV0DSIC9O6.lab.local",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Name": "SAMMSG_MACHINE_ACCOUNT_SECURE",
"ComputerName": "",
"Binary": "00000000"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 16944 — The certificate that is used for authentication does not have an issuance policy descriptor corresponding to OID OID in the Active Directory database.
Event ID 16945 — The certificate issuance policy that is represented by OID OID Object DN does not have a link to a security identifier (SID), or this link cannot be read.
Event ID 16946 — Multiple certificate issuance policy descriptors were found in the Active Directory database.
Event ID 16947 — The certificate issuance policy descriptor OID Object DN is linked through its attribute msDS-OIDToGroupLink to a group that is not a security group, has memb...
Description
The certificate issuance policy descriptor OID Object DN is linked through its attribute msDS-OIDToGroupLink to a group that is not a security group, has members, or is not universal. The error is ErrorCode.
Message #
Fields #
| Name | Description |
|---|---|
OID UnicodeString | — |
OID Object DN UnicodeString | — |
Group DN UnicodeString | — |
Group GUID UnicodeString | — |
Group SID UnicodeString | — |
ErrorCode UInt32 | — |
OIDObjectDN UnicodeString | — |
GroupDN UnicodeString | — |
GroupGUID UnicodeString | — |
GroupSID UnicodeString | — |
Event ID 16948 — The requested modification for group Group DN could not be performed.
Message #
Fields #
| Name | Description |
|---|---|
Group DN UnicodeString | — |
Group GUID UnicodeString | — |
Group SID UnicodeString | — |
Operation UnicodeString | — Known values
|
ErrorCode UInt32 | — |
GroupDN UnicodeString | — |
GroupGUID UnicodeString | — |
GroupSID UnicodeString | — |
Event ID 16949 — The certificate issuance policy descriptor OID Name cannot be linked to group Group Name.
Event ID 16950 — The following invalid claims issued to user User have been dropped: DroppedClaims.
Event ID 16951 — Claims issued to user User could not be validated and have been dropped.
Event ID 16952 — Claims issued to user User could not be validated and have been dropped.
Event ID 16953 — The password notification DLL NotificationPackage: failed to load with error Error code:.
Event ID 16960 — SAM was configured to not listen on the TCP protocol.
Description
SAM was configured to not listen on the TCP protocol.
Message #
Event ID 16961 — Legacy password validation mode has been enabled on this machine.
Description
Legacy password validation mode has been enabled on this machine. If an Exchange ActiveSync policy is configured it will not be enforced for password validation requests.
Message #
Event ID 16962 — Remote calls to the SAM database are being restricted using the default security descriptor: Name.
#Description
Remote calls to the SAM database are being restricted using the default security descriptor: Name.
Message #
Fields #
| Name | Description |
|---|---|
Name | Remote calls to the SAM database are being restricted using the default security descriptor. |
Default SD String: UnicodeString | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Directory-Services-SAM",
"guid": "0D4FDC09-8C27-494A-BDA0-505E4FD8ADAE",
"event_source_name": "",
"event_id": 16962,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2023-11-06T06:25:28.054783+00:00",
"event_record_id": 1666,
"correlation": {
"ActivityID": "F590C418-1079-0001-5BC5-90F57910DA01"
},
"execution": {
"process_id": 808,
"thread_id": 812
},
"channel": "System",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Name": "SAMMSG_RESTRICT_REMOTE_SAM_DEFAULT_SD",
"Default SD String:": "O:SYG:SYD:(A;;RC;;;BA)"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 16963 — Remote calls to the SAM database are being restricted using the configured registry security descriptor: RegistrySDString.
Event ID 16964 — The registry security descriptor is malformed: MalformedSDString.
Event ID 16965 — A remote call to the SAM database has been denied.
Event ID 16966 — Audit only mode is now enabled for remote calls to the SAM database.
Description
Audit only mode is now enabled for remote calls to the SAM database. SAM will log an event for clients who would have been denied access in normal mode.
Message #
Event ID 16967 — Audit only mode is now disabled for remote calls to the SAM database.
Description
Audit only mode is now disabled for remote calls to the SAM database.
Message #
Event ID 16968 — Audit only mode is currently enabled for remote calls to the SAM database.
Event ID 16969 — Suppressed Message Count: remote calls to the SAM database have been denied in the past Throttle window: seconds throttling window.
Event ID 16976 — An error occurred while configuring one or more well-known accounts for this domain.
Message #
Fields #
| Name | Description |
|---|---|
Status HexInt32 | — NTSTATUS reference |
Event ID 16977 — The domain is configured with the following minimum password length-related settings.
#Description
The domain is configured with the following minimum password length-related settings.
Message #
Fields #
| Name | Description |
|---|---|
Name | — |
MinimumPasswordLength Int32 | — |
RelaxMinimumPasswordLengthLimits Int32 | — |
MinimumPasswordLengthAudit Int32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Directory-Services-SAM",
"guid": "0D4FDC09-8C27-494A-BDA0-505E4FD8ADAE",
"event_source_name": "",
"event_id": 16977,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2023-11-06T06:25:34.991632+00:00",
"event_record_id": 1669,
"correlation": {
"ActivityID": "F590C418-1079-0001-5BC5-90F57910DA01"
},
"execution": {
"process_id": 808,
"thread_id": 896
},
"channel": "System",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Name": "SAMMSG_MINPWDLEN_SETTINGS_IN_EFFECT",
"MinimumPasswordLength": 0,
"RelaxMinimumPasswordLengthLimits": 0,
"MinimumPasswordLengthAudit": -1
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 16978 — The following account has been configured with a password whose length is shorter than the current MinimumPasswordLengthAudit setting.
Event ID 16979 — The domain is incorrectly configured with a MinimumPasswordLength setting that is greater than 14 while RelaxMinimumPasswordLengthLimits is either ...
Event ID 16980 — The security account manager has detected the use of a ROCA-vulnerable Windows Hello for Business key during authentication by the following account.
Event ID 16981 — The security account manager has detected and blocked the use of a ROCA-vulnerable Windows Hello for Business key during authentication by the foll...
Description
The security account manager has detected and blocked the use of a ROCA-vulnerable Windows Hello for Business key during authentication by the following account.
Message #
Fields #
| Name | Description |
|---|---|
Account_DN UnicodeString | — |
Account_SID UnicodeString | — |
KeyHash UnicodeString | — |
AccountDN UnicodeString | — |
AccountSID UnicodeString | — |
Event ID 16982 — The security account manager is now logging verbose events for remote clients that call legacy password change or set RPC methods.
Message #
Event ID 16983 — The security account manager is now logging periodic summary events for remote clients that call legacy password change or set RPC methods.
#Description
The security account manager is now logging periodic summary events for remote clients that call legacy password change or set RPC methods.
Message #
Fields #
| Name | Description |
|---|---|
Name | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Directory-Services-SAM",
"guid": "0D4FDC09-8C27-494A-BDA0-505E4FD8ADAE",
"event_source_name": "",
"event_id": 16983,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2023-11-06T06:25:28.084211+00:00",
"event_record_id": 1668,
"correlation": {
"ActivityID": "F590C418-1079-0001-5BC5-90F57910DA01"
},
"execution": {
"process_id": 808,
"thread_id": 812
},
"channel": "System",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Name": "SAMMSG_AUDIT_LEGACY_PWD_RPC_METHODS_OFF"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 16984 — The security account manager detected Number of RPC methods: legacy password change or set RPC method calls in the past Throttle Window: minutes.
Event ID 16985 — The security account manager detected the use of a legacy password change or set RPC method from a network client.
Description
The security account manager detected the use of a legacy password change or set RPC method from a network client.
Message #
Fields #
| Name | Description |
|---|---|
RPC_Method UnicodeString | [Details] RPC Method. |
Username UnicodeString | [Details] Username. |
Client_SID UnicodeString | [Details] Client SID. |
Client_Network_Address UnicodeString | [Details] Client Network Address. |
RPCMethod UnicodeString | — |
UserAccountName UnicodeString | — |
ClientSID UnicodeString | — |
ClientNetworkAddress UnicodeString | — |
Event ID 16986 — The security account manager has detected one or more duplicated names for a local account.
Description
The security account manager has detected one or more duplicated names for a local account. This inconsistency was remediated by keeping one account name and deleting the remaining names.
Message #
Fields #
| Name | Description |
|---|---|
Retained_account_name | — |
Deleted_account_names | — |
AccountRidHex HexInt32 | — |
AccountRid Int32 | — |
SavedAccountName UnicodeString | — |
DeletedAccountNames UnicodeString | — |
Event ID 16987 — The security account manager has detected one or more duplicated names for a local account.
Event ID 16988 — The security account manager encountered one or more fatal errors on startup which will not allow the machine to start.
Event ID 16989 — The security account manager encountered one or more non-fatal errors on startup.
Event ID 16990 — The security account manager blocked a non-administrator from creating an Active Directory account in this domain with mismatched objectClass and u...
Description
The security account manager blocked a non-administrator from creating an Active Directory account in this domain with mismatched objectClass and userAccountControl account type flags.
Message #
Fields #
| Name | Description |
|---|---|
Account_name UnicodeString | [Details] Account name. |
Account_objectClass UnicodeString | [Details] Account objectClass. |
userAccountControl UInt32 | [Details] userAccountControl. |
Caller_address UnicodeString | [Details] Caller address. |
Caller_SID UnicodeString | [Details] Caller SID. |
Accountname UnicodeString | — |
AccountobjectClass UnicodeString | — |
userAccountcontrol UInt32 | — |
Calleraddress UnicodeString | — |
CallerSID UnicodeString | — |
Event ID 16991 — The security account manager blocked a non-administrator from creating or renaming a computer account using an invalid sAMAccountName.
Event ID 16992 — The security account manager is now configuring the local password and lockout policies in accordance with regional policy.
Description
The security account manager is now configuring the local password and lockout policies in accordance with regional policy.
Message #
Event ID 16993 — The security account manager successfully initialized the Local Administrator Password Solution (LAPS) extension dll.
Description
The security account manager successfully initialized the Local Administrator Password Solution (LAPS) extension dll.
Message #
Event ID 16994 — The security account manager failed to initialize the Local Administrator Password Solution (LAPS) extension dll.
Description
The security account manager failed to initialize the Local Administrator Password Solution (LAPS) extension dll.
Message #
Fields #
| Name | Description |
|---|---|
Status HexInt32 | — NTSTATUS reference |
Event ID 16995 — The security account manager is using the specified security descriptor for validation of computer account re-use attempts during domain join.
Event ID 16996 — The security descriptor that contains the computer account re-use allow list being used to validate client requests during domain join is malformed.
Event ID 16997 — The security account manager found a computer account that appears to be orphaned and does not have an existing owner.
Description
The security account manager found a computer account that appears to be orphaned and does not have an existing owner.
Message #
Fields #
| Name | Description |
|---|---|
Computer_Account UnicodeString | — |
Computer_Account_Owner UnicodeString | — |
ComputerAccountSID UnicodeString | — |
ComputerAccountOwnerSID UnicodeString | — |
Event ID 16998 — The security account manager rejected a client request to re-use a computer account during domain join.
Description
The security account manager rejected a client request to re-use a computer account during domain join.
Message #
Fields #
| Name | Description |
|---|---|
Computer_Account | — |
Computer_Account_Owner | — |
Client_Account | — |
ComputerAccountSID UnicodeString | — |
ComputerAccountOwnerSID UnicodeString | — |
ClientUserAccountSID UnicodeString | — |
__binLength UInt32 | — |
ErrorCode Binary | — |