Audit Computer Account Management

This security policy setting determines whether the operating system generates audit events when a computer account is created, changed, or deleted. This policy setting is useful for tracking account-related changes to computers that are members of a domain.

Event volume: Low

If this policy setting is configured, the following events are generated. The events appear on computers running Windows Server 2008 R2, Windows Server 2008, Windows 7, or Windows Vista.

  • 4741: A computer account was created.
  • 4742: A computer account was changed.
  • 4743: A computer account was deleted.

Scope: 

Computer

Default: 

Not configured

Related content