The Windows security log event IDs worth knowing: logons, lockouts, Kerberos, Get-WinEvent queries and how to turn auditing on!
Windows
Published on
Karl Certa Systems & network administrator5 years in IT, from support to sysadmin, now Ops. Learning cloud, and writing everything down here. Focused on IaC & cloud AWS SAA, Kubernetes next LinkedIn karlcerta.fr GitHub Karl Certa
The Windows security log records every authentication, account change and access attempt. The hard part is knowing which ID to look at. The IDs below apply to Windows Server 2016 through 2025.
🔐 Logons and sessions
📌 ID
🧠 Meaning
📊 When to look at it
4624
Successful logon
Track who connected and from where
4625
Failed logon
Brute force, wrong password
4634
Logoff
Work out a session duration
4647
User-initiated logoff
Tell a real RDP disconnect apart
4648
Logon with explicit credentials
runas, elevation, lateral movement
4672
Special privileges assigned
An administrative session just opened
4776
NTLM credential validation
On the DC, when the 4625 says nothing
🚪 Logon types
The “Logon Type” field on 4624 and 4625 tells you how the connection happened.
📌 Type
🧠 Origin
📊 Concrete example
2
Interactive
Keyboard, physical console
3
Network
SMB share, remote access
4
Batch
Scheduled task
5
Service
Service startup
7
Unlock
Back from sleep
8
Network cleartext
IIS basic authentication
9
New credentials
runas /netonly
10
Remote interactive
RDP
11
Cached interactive
Laptop off the domain
❌ 4625 failure codes
The Sub Status field carries the real reason, the Status field usually showing the generic 0xC000006D.
📌 Code
🧠 Actual cause
0xC0000064
The account does not exist
0xC000006A
Wrong password
0xC0000072
Account disabled
0xC0000234
Account locked out
0xC0000070
Workstation not allowed
0xC000006F
Logon outside allowed hours
0xC0000071
Password expired
0xC0000193
Account expired
0xC0000133
Clock skew between client and DC
🔒 Account lockout
📌 ID
🧠 Meaning
📊 Where to look
4740
Account locked out
On the domain’s PDC emulator
4767
Account unlocked
Who unblocked it, and when
4771
Kerberos pre-auth failure
The guilty host when 4740 is bare
👤 Accounts and groups
📌 ID
🧠 Meaning
4720
Account created
4722
Account enabled
4725
Account disabled
4726
Account deleted
4738
Account changed
4723
Password changed by the user
4724
Password reset by an administrator
4728
Member added to a global group
4732
Member added to a local group
4756
Member added to a universal group
🎫 Kerberos
📌 ID
🧠 Meaning
4768
Authentication ticket requested (TGT)
4769
Service ticket requested (TGS)
4771
Pre-authentication failed
📌 Failure code
🧠 Cause
0x6
User unknown to the domain
0x12
Account disabled, locked or expired
0x17
Password expired
0x18
Wrong password
0x25
Clock skew over 5 minutes
🚨 Signals that should raise an eyebrow
📌 ID
🧠 Meaning
📊 Log
1102
The audit log was cleared
Security
4697
A service was installed
Security, 2016 and up
7045
A service was installed
System, on by default
4688
New process created
Security
4719
Audit policy was changed
Security
4798
Local group membership enumerated
Security, 2016 and up
5136
An Active Directory object changed
Security
4104
PowerShell script block executed
PowerShell/Operational
4697 and 7045 describe the same service installation seen from two subsystems. 7045 is on by default but does not say who did it, while 4697 needs auditing enabled and carries the account behind it.
Through group policy it all lives in Computer Configuration > Policies > Windows Settings > Security Settings > Advanced Audit Policy Configuration. To get the command line inside 4688 events, you also need to enable “Include command line in process creation events”.
🛠️ Common troubleshooting
🆘 Problem
🧠 Solution
❌ The ID never shows up
Subcategory not enabled, check with auditpol /get
🔍 No 4740 on the controller you queried
Query the PDC emulator, it alone records it
📭 Events vanish quickly
Log full and wrapping, increase its size
🖥️ 4625 with no source machine
Network logon, cross-check with 4776 on the DC
🌐 auditpol rejects a subcategory
Names are translated on a localised Windows
⏰ Unexplained Kerberos failures
Clock skew, compare with w32tm /query /status
⚰️ IDs still quoted online that no longer exist
Plenty of guides still list three-digit identifiers. They belong to Windows Server 2003 and have not been generated since Vista and Server 2008. The conversion is mechanical: old identifier plus 4096.