Identity Security uses data from Active Directory (on-premises) for identity-related
threat detection and identity asset discovery.
The following table lists the Windows event data used by Identity Security for identity-related
threat detection.
Category
|
Event ID
|
Description
|
4624
|
An account was successfully logged on.
|
|
4625
|
An account failed to log on.
|
|
4634
|
An account was logged off.
|
|
4672
|
Special privileges assigned to new logon.
|
|
4661
|
A handle to an object was requested.
|
|
4662
|
An operation was performed on an object.
|
|
4720
|
A user account was created.
|
|
4726
|
A user account was deleted.
|
|
4728
|
A member was added to a security-enabled global group.
|
|
4732
|
A member was added to a security-enabled local group
|
|
4769
|
A Kerberos service ticket was requested.
|
|
4776
|
The computer attempted to validate the credentials for an account.
|
The following table lists the Active Directory data used by Identity Security for
identity asset discovery.
Category
|
Data
|
User information
|
|
Group information
|
|
Computer information
|
|
Event log
|
|