Changes to AD objects (e.g., users, groups, OUs) are logged as Event ID 5136 (Object Modification) or 5163 (Attribute Changes). Examples:
| Name | Channel |
|---|---|
| azure:activity | Update conditionalAccessPolicy |
| azure:signinlogs | Add certificate credential, Update certificate credential |
| esxi:vpxa | vim.SessionManager.login / vim.AccountManager.createUser |
| esxi:vpxd | permission change operations on datastores or VMs |
| m365:dirsync | Replication cookie changes involving Configuration partition with new server/nTDSDSA objects. |
| m365:unified | Set-Mailbox, Set-AppPassword, Add-MailboxPermission |
| m365:unified | Add app role assignment grant to user: Consent to application by privileged or unexpected accounts |
| WinEventLog:Security | EventCode=5163 |
| WinEventLog:Security | EventCode=4739 |
| WinEventLog:Security | EventCode=5136 |
| WinEventLog:Security | EventCode=4663, 4670, 4656 |