Windows Security Log Event ID 639
Operating Systems |
Windows Server 2000
Windows 2003 and XP
|
Category | Account Management |
Type
|
Success
|
Corresponding events
in Windows
2008 and Vista |
4735
|
639: Security Enabled Local Group Changed
On this page
Security local group changed.Type:
AD has 2 types of groups: Security and Distribution. Distribution (security disabled) groups are for distribution lists in Exchange and cannot be assigned permissions or rights. Security (security enabled) groups can be used for permissions, rights and as distribution lists.
Scope:
AD has 3 scopes of groups: Local, Global, Universal. See knowledge base article 326265.
This event does include group member additions and deletions for which there are other event IDs.
Free Security Log Resources by Randy
- Target Account Name: %1
- Target Domain: %2
- Target Account ID: %3
- Caller User Name: %4
- Caller Domain: %5
- Caller Logon ID: %6
- Privileges: %7
Windows Server 2003 adds these fields:
- Changed Attributes: (the following two fields are on Server 2008 only)
- Sam Account Name: %8
- Sid History: %9
Supercharger Free Edition
Event Type: Success Audit
Event Source: Security
Event Category: Account Management
Event ID: 639
Date: 1/7/2009
Time: 7:47:52 PM
User: STG\wsmith
Computer: STG
Description:
Security Enabled Local Group Changed:
Target Account Name: Accounting
Target Domain: STG
Target Account ID: STG\Accounting
Caller User Name: wsmith
Caller Domain: STG
Caller Logon ID: (0x0,0x31AA8)
Privileges: -
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Windows Server 2003 adds these fields:
Changed Attributes:
Sam Account Name:-
Sid History:-
Top 10 Windows Security Events to Monitor
Free Tool for Windows Event Collection