Microsoft-Windows-Security-Auditing › Event 5139

Event ID 5139 — A directory service object was moved.

Provider
Microsoft-Windows-Security-Auditing
Channel
Security
Audit Policy
DS Access → Directory Service Changes
Collection Priority
Recommended (NSA, others)
Opcode
Info

Description

A directory service object was moved.

Message #

A directory service object was moved.
	
Subject:
	Security ID: %3
	Account Name: %4
	Account Domain: %5
	Logon ID: %6
	
Directory Service:
	Name: %7
	Type: %8
	
Object:
	Old DN: %9
	New DN: %10
	GUID: %11
	Class: %12
	
Operation:
	Correlation ID: %1
	Application Correlation ID: %2

Fields #

NameDescription
OpCorrelationID GUID[Operation] Correlation ID
AppCorrelationID UnicodeString[Operation] Application Correlation ID
SubjectUserSid SID[Subject] Security ID
SubjectUserName UnicodeString[Subject] Account Name
SubjectDomainName UnicodeString[Subject] Account Domain
SubjectLogonId HexInt64[Subject] Logon ID
DSName UnicodeString[Directory Service] Name
DSType UnicodeString[Directory Service] Type
Known values
%%14676
Active Directory Domain Services
%%14677
Active Directory Lightweight Directory Services
OldObjectDN UnicodeString[Object] Old DN
NewObjectDN UnicodeString[Object] New DN
ObjectGUID GUID[Object] GUID
ObjectClass UnicodeString[Object] Class

Community Notes #

May indicate high-impact changes in AD.

References #