Overview
Identity Behavioral Insights enables you to investigate the activity of a specific identity, whether a user or a service principal/NHI, over a defined time window.
Druva analyzes identity audit events from your connected identity provider, maps them to MITRE Tactics, Techniques, and Procedures (TTPs), and generates a detailed activity timeline. This timeline shows what changed, when it changed, and how the impact propagated, including objects that were created, modified, or deleted by the identity.
Identity Behavioural Insights
Provides compromised identity blast radius visibility to reduce investigation time from days to hours:
Timeline and table view of created, modified, or deleted objects.
Visualizes full blast radius, propagated impacts, and affected relationships.
Contextualizes changes using MITRE Tactics, Techniques, and Procedures (TTPs)
Guided Recovery
Delivers curated, granular recovery workflows ensuring a clean post-recovery state:
Generates recovery recommendations for each change detected by Identity Recovery Intelligence.
Offers flexibility to execute full recovery plans or selectively restore objects.
Eliminates attacker persistence with minimal business disruption.
Key Terminologies
Activity timeline
A chronological record of all events involving the analyzed identity during the investigation window. Events are displayed in a graph view (nodes connected by action edges) or a list view (event table). Each event shows the actor identity, the action taken, the target identity, and the mapped MITRE Tactics, Techniques, and Procedures (TTPs).
MITRE ATT&CK mapping
Druva maps each event to MITRE Tactics, Techniques, and Procedures (TTPs). The activity timeline summarizes event counts by tactic. The following MITRE ATT&CK tactics are used for mapping:
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Impact
To learn more about these, see MITRE ATT&CK.
Recovery snapshot
A point-in-time backup of an identity's configuration. Druva uses snapshots to identify a clean pre-compromise state and to restore identities during a cyber recovery plan.
Recovery type
Suggested recovery options to restore the selected objects and the compromised identity back to a known, trusted state, ensuring business continuity by eliminating the attackers persistence. The guided recovery type can be either Recover, Rollback, or Delete.
Delete is recommended when there is suspicious create event action on identity. For example, a new user or application is created using a compromised identity to establish persistence.
Rollback is recommended when there is suspicious modified event action on identity. For example, an existing user, group, or policy is modified by a compromised identity.
Recover is recommended when there is suspicious delete event action on identity. For example, an existing user, group, or policy is deleted by a compromised identity.
Time Range
You can investigate events within a window of up to 30 days. The start date can go back up to 12 months from the current date.
At initial availability, the earliest start date is one month before Identity Resiliency was enabled in your region. This lookback window expands as backup data accumulates over time.
Analysis history
Each analysis is saved automatically. Reopening a saved analysis loads the previously generated results without re-running the computation.
You can reopen analyses from Analysis History on the results page or from the Recent Analyses list on the main Identity Behavioral Insights page.
Supported object types
The activity timeline tracks events across all the supported object types backed up by Identity Workloads - Okta, Entra ID, and Microsoft Active Directory.
Supported audit actions for Identity Behavioral Insights
Entra ID
Add administrative unit
Add member to administrative unit
Add member to restricted management administrative unit
Bulk remove members to administrative unit - finished (bulk)
Delete administrative unit
Hard Delete administrative unit
Remove member from administrative unit
Remove member from restricted management administrative unit
Update administrative unit
Add application
Delete application
Update application
Add app role assignment to service principal
Add application (Core Directory)
Add member to role in PIM completed (timebound)
Add owner to application
Add owner to service principal
Add policy to application
Add policy to service principal
Add service principal
Add service principal credentials
Authentication Methods Policy Reset
Authentication Methods Policy Update
Authentication Strength Combination Configuration Create
Authentication Strength Combination Configuration Delete
Authentication Strength Combination Configuration Update
Authentication Strength Policy Create
Authentication Strength Policy Delete
Authentication Strength Policy Update
Delete application (Core Directory)
Delete application collection
Hard Delete application
Hard delete service principal
MFA Service Policy Update
PIM policy removed
Remove app role assignment from service principal
Remove member from role in PIM completed (timebound)
Remove owner from application
Remove owner from service principal
Remove policy from application
Remove policy from service principal
Remove service principal
Remove service principal credentials
Role definition created
Set verified publisher
Unset verified publisher
Update application (Core Directory)
Update application - Certificates and secrets management
Update external secrets
Update role setting in PIM
Update service principal
Add a group to feature rollout
Add user to feature rollout
Create rollout policy for feature
Delete rollout policy of feature
Federate with an identity provider
Remove a group from feature rollout
Remove user from feature rollout
Remove user from feature rollout (Hybrid)
Update rollout policy of feature
Add v2 application permissions
Create Identity Provider
Create custom identity provider
Create custom policy
Create policy key
Create user flow
Create v2 application
Delete B2C Tenant where the caller is an administrator
Delete B2C directory resource
Delete CIAM directory resource
Delete Identity Provider
Delete custom policy
Delete policy key
Delete user flow
Delete v2 application
Delete v2 application permission grant
Update Identity Provider
Update age gating configuration
Update authentication flows policy
Update authenticationEventsPolicy
Update custom identity provider
Update custom policy
Update local identity provider
Update policy key
Update tenant metadata
Update user flow
Update authorization policy
The role assignment of User Access Administrator has been removed from the user
Add CertBasedAuthConfiguration
Hard delete CertificationBasedAuthConfiguration
Add CertificateBasedAuthConfiguration
Delete CertificateBasedAuthConfiguration
Update CertificateBasedAuthConfiguration
Delete Branding Theme
Hard Delete Branding Theme
Delete Branding Theme Localization
Hard Delete Branding Theme Localization
Add a domain-based partner to cross-tenant access setting
Add a partner to cross-tenant access setting
Delete a domain-based partner to cross-tenant access setting
Delete partner specific cross-tenant access setting
Reset the cross-tenant access default setting
Update a domain-based partner to cross-tenant access setting
Update a partner cross-tenant access setting
Update the company default cross-tenant access setting
Create a partner cross-tenant identity sync setting
Delete a partner cross-tenant identity sync setting
Update a partner cross-tenant identity sync setting
Adding allowed assignable roles
Updating allowed assignable roles
Add device configuration
Delete device configuration
Update device configuration
Add DeviceTemplate
Add device from DeviceTemplate
Add owner to DeviceTemplate
Add partner to company
Add sharedEmailDomainInvitation
Add unverified domain
Add verified domain
DELETE Subscription.DeleteProviders
Delete company allowed data location
Delete company settings
Delete subscription
Deleting Source Tenant subscriptions
Directory deleted
Directory scheduled for deletion (Lifecycle)
Disable Desktop Sso
Disable Desktop Sso for a specific domain
Disable application proxy
Disable passthrough authentication
Disable password writeback for directory
Hard Delete Domain
PATCH Tenant.Patch
Promote sub domain to root domain
Remove partner from company
Remove unverified domain
Remove verified domain
Schedule Add sharedEmailDomain
Schedule Remove sharedEmailDomain
Set DirSync feature
Set DirSyncEnabled flag
Set directory feature on tenant
Set domain authentication
Set federation settings on domain
Set password policy
Soft Delete Domain
Suspending Source Tenant Subscriptions
Update Domain
Update sharedEmailDomain
Update sharedEmailDomainInvitation
Delete incompatible group
Remove user as external sponsor
Remove user as internal sponsor
Update tenant setting
Add app role assignment to group
Add eligible member to role in PIM completed (permanent)
Add eligible member to role in PIM completed (timebound)
Add group
Add group (MIM)
Add member to group
Add member to group (MIM)
Add owner to group
Add owner to group (MIM)
Assign label to group
Bulk remove group members - finished (bulk)
Create group settings
Create lifecycle management policy
Delete group
Delete group (MIM)
Delete group settings
Delete lifecycle management policy
Features_UpdateFeaturesAsync
GroupLifecyclePolicies_addGroup
GroupLifecyclePolicies_removeGroup
Group_AddMember
Group_AddOwner
Group_Create
Group_Delete
Group_RemoveMember
Group_RemoveOwner
Group_Update
Groups_CreateLink
Hard Delete group
PIM policy removed (Group)
Remove app role assignment from group
Remove eligible member from group
Remove eligible owner from group
Remove label from group
Remove member from group
Remove member from group (MIM)
Remove owner from group
Remove owner from group (MIM)
Remove permanent direct role assignment
Remove permanent eligible role assignment
Set group to be managed by user
Update group
Update group (MIM)
Update group settings
Update lifecycle management policy
Update member in PIM approved by admin (extend/renew)
Update role setting in PIM
User_Create
User_Delete
set dynamic group properties
Update IdentityProtectionPolicy
Add kerberos domain
Delete kerberos domain
Update kerberos domain
Add label
Delete label
Create a MultiTenantOrg
Hard Delete MultiTenantOrg
Update a MultiTenantOrg
Reset a multi tenant org identity sync policy template
Update a multi tenant org identity sync policy template
Reset a multi tenant org partner configuration template
Update a multi tenant org partner configuration template
Add MultiTenantOrg tenant
Delete MultiTenantOrg tenant
Hard Delete MultiTenantOrg tenant
Tenant joining MultiTenantOrg tenant
Update MultiTenantOrg tenant
Update Adaptive Access Policy
Update Enriched Audit Logs Settings
Update Forwarding Options Policy
Delete PendingExternalUserProfile
Hard Delete PendingExternalUserProfile
Add permission grant policy
Delete permission grant policy
Update permission grant policy
Add AuthenticationContextClassReference
Add Conditional Access policy
Add blocked user
Add bypass user
Add owner to policy
Add policy
Delete AuthenticationContextClassReference
Delete Conditional Access policy
Delete policy
Hard Delete policy
Remove bypassed user
Remove owner from policy
Remove policy credentials
Set device registration policies
Update AuthenticationContextClassReference
Update Conditional Access policy
Update Sign-In Risk Policy
Update User Risk and MFA Registration Policy
Update continuous access evaluation
Update partner directory settings
Update policy
Create Filtering Policy
Create Filtering Policy Profile
Create Security Provider Policy
Delete Filtering Policy
Delete Filtering Policy Profile
Delete Forwarding Policy
Delete Private Access Policy
Delete Remote Network
Delete Security Provider Policy
Update Filtering Policy
Update Filtering Policy Profile
Update Filtering Profile
Update Forwarding Policy
Update Forwarding Profile
Update Forwarding Rule
Update Private Access Policy
Update Remote Network
Update Security Provider Policy
Add provisioning configuration
Delete provisioning configuration
Disable/pause provisioning configuration
Update attribute mappings or scope
Update provisioning setting or credentials
Create PublicKeyInfrastructure
Delete PublicKeyInfrastructure
Hard Delete PublicKeyInfrastructure
Update PublicKeyInfrastructure
Add a Connector to Connector Group
Add application SSL certificate
Add connector Group
Add member to role outside of PIM (permanent)
Create Identity Provider (B2C)
Create Registration of Security Provider
Create authority
Create authorization policy
Create custom identity provider (B2C)
Create custom policy (B2C)
Create issuance policy
Create or update a localized resource (B2C)
Create user attribute (B2C)
Delete B2C Tenant where the caller is an administrator (B2C)
Delete B2C directory resource (B2C)
Delete CIAM directory resource (B2C)
Delete Connector Group
Delete Identity Provider (B2C)
Delete SSL binding
Delete custom policy (B2C)
Delete issuance policy
Delete policy key (B2C)
Delete user attribute (B2C)
Delete user flow (B2C)
Disable PIM alert
Move resources (B2C)
PIM policy removed (Resource)
Remove permanent direct role assignment (Resource)
Remove permanent eligible role assignment (Resource)
Rotate signing key
Update Connector Group
Update authentication flows policy (B2C)
Update authority
Update certificate to policy key (B2C)
Update custom identity provider (B2C)
Update custom policy (B2C)
Update identity provider (B2C)
Update issuance policy
Update linked domains
Update local identity provider (B2C)
Update policy key (B2C)
Update role setting in PIM (Resource)
Update secret into policy key (B2C)
Update user flow (B2C)
Add EligibleRoleAssignment to RoleDefinition
Add eligible member to role
Add eligible member to role in PIM completed (permanent) (Role)
Add eligible member to role in PIM completed (timebound) (Role)
Add member to role
Add member to role outside of PIM (permanent) (Role)
Add member to role scoped over Restricted Management Administrative Unit
Add role assignment to role definition
Add role definition
Add role from template
Add scoped member to role
Delete role definition
Disable PIM alert (Role)
PIM policy removed (Role)
Remove EligibleRoleAssignment from RoleDefinition
Remove eligible member from role
Remove member from role
Remove member from role scoped over Restricted Management Administrative Unit
Remove permanent direct role assignment (Role)
Remove permanent eligible role assignment (Role)
Remove role assignment from role definition
Remove scoped member from role
Update PIM alert setting
Update role
Update role definition
Update role setting in PIM (Role)
Add app role assignment to group (UserManagement)
Add user
Add user sponsor
Bulk delete users - finished (bulk)
Delete external user
Delete user
Disable Strong Authentication
Disable account
Hard Delete user
Remove app role assignment from user
Remove user sponsor
Update per-user multifactor authentication state
Update user
Update tenant settings
Admin deleted security info
Admin registered security info
Admin updated security info
User changed default security info
User deleted security info
User registered all required security info
User registered security info
User updated security info
Update PasswordProfile
Okta
account.org.status.update
account.org_group.create
account.org_group.delete
account.org_group.org.assign
account.org_group.org.revoke
account.org_group.update
app.ad.password_migration_campaign.group.add
app.cross_app_access.connection.create
app.cross_app_access.connection.delete
app.cross_app_access.connection.update
app.interclient_mapping.create
app.interclient_mapping.delete
app.interclient_mapping.delete_all
app.oauth2.as.resource_server.credentials.lifecycle.delete
app.oauth2.client.lifecycle.delete
app.oauth2.admin.consent.revoke
app.oauth2.as.consent.revoke
app.oauth2.as.consent.revoke.implicit.as
app.oauth2.as.consent.revoke.implicit.client
app.oauth2.as.consent.revoke.implicit.scope
app.oauth2.as.consent.revoke.implicit.user
app.oauth2.as.consent.revoke.user
app.oauth2.as.consent.revoke.user.client
app.oauth2.as.resource_server.credentials.lifecycle.create
app.oauth2.as.resource_server.credentials.lifecycle.deactivate
app.oauth2.credentials.lifecycle.delete
app.oauth2.trusted_server.delete
oauth2.as.deleted
resource_servers.client_authentication_settings.delete
app.oauth2.client.lifecycle.create
app.oauth2.client.lifecycle.deactivate
app.oauth2.client.lifecycle.update
app.oauth2.client.privilege.revoke
app.oauth2.credentials.lifecycle.deactivate
app.oauth2.trusted_server.add
app.office365.user.delete.success
app.office365.user.remove.licenses.success
app.policy.sign_on.update
app.saml.sensitive.attribute.update
app.user_management.grouppush.mapping.created.from.rule
app.user_management.user_group_import.delete_success
application.configuration.disable_delauth_outbound
application.configuration.disable_fed_broker_mode
application.configuration.update
application.configuration.update_rate_limits
application.lifecycle.create
application.lifecycle.deactivate
application.lifecycle.delete
application.lifecycle.update
application.policy.sign_on.rule.create
application.policy.sign_on.rule.delete
application.policy.sign_on.update
application.provision.field_mapping_rule.change
application.provision.group.add
application.provision.group.remove
application.provision.group.update
application.provision.group_membership.add
application.provision.group_membership.remove
application.provision.group_membership.update
application.provision.group_push.deactivate_mapping
application.provision.group_push.delete_appgroup
application.provision.group_push.mapping.and.groups.deleted.rule.deleted
application.provision.group_push.mapping.app.group.renamed
application.provision.group_push.mapping.created
application.provision.group_push.mapping.deactivated.source.group.renamed
application.provision.group_push.removed
application.provision.group_push.updated
application.provision.user.deactivate
application.provision.user.deprovision
application.registration_policy.lifecycle.create
application.registration_policy.lifecycle.update
application.user_membership.add
application.user_membership.change_username
application.user_membership.deprovision
application.user_membership.remove
application.user_membership.revoke
application.user_membership.update
device.assurance.policy.add
device.assurance.policy.delete
device.assurance.policy.update
device.desktop_mfa.configuration.update
device.local_account.create
device.platform.add
device.platform.delete
device.platform.update
device.push.provider.create
device.push.provider.delete
device.push.provider.update
directory.app_user_profile.update
directory.external.group.membership.add
directory.external.group.membership.remove
directory.linked_object.create
directory.linked_object.delete
directory.mapping.update
directory.user_profile.update
event_hook.created
event_hook.deactivated
event_hook.deleted
event_hook.updated
group.application_assignment.add
group.application_assignment.remove
group.application_assignment.update
group.lifecycle.create
group.lifecycle.delete
group.privilege.revoke
group.profile.update
group.user_membership.add
group.user_membership.remove
group.user_membership.rule.add_exclusion
group.user_membership.rule.deactivated
group.user_membership.rule.invalidate
iam.policy.assignee_configuration.update
iam.policy.configuration.update
iam.resourceset.bindings.add
iam.resourceset.bindings.delete
iam.resourceset.create
iam.resourceset.delete
iam.resourceset.resources.add
iam.resourceset.resources.delete
iam.resourceset.resources.update
iam.resourceset.update
iam.role.create
iam.role.delete
iam.role.permission.conditions.add
iam.role.permission.conditions.delete
iam.role.permissions.add
iam.role.permissions.delete
iam.role.subscriptions.update
iam.role.update
inline_hook.created
inline_hook.deactivated
inline_hook.deleted
master_application.user_membership.add
network_zone.rule.disabled
oauth2.as.created
oauth2.as.deactivated
oauth2.as.updated
pam.active_directory.account_rule.update
pam.ad_connection.create
pam.ad_connection.update
pam.cloud_account.create
pam.group.bulk_membership_change
pam.member.add
pam.member.remove
pam.project.add_group
pam.project.remove_group
pam.security_policy.create
pam.security_policy.delete
pam.security_policy.update
pam.service_account.create
pam.team_group_attribute.create
pam.team_project_group_attribute.create
pam.team_project_user_attribute.create
pam.team_project_user_attribute.delete
pam.team_project_user_attribute.update
pam.team_user_attribute.create
pam.team_user_attribute.delete
pam.team_user_attribute.update
pam.user.create
pam.user.remove
pam.user.update
pam.workload_role.create
personal.admin.configuration.update
policy.lifecycle.create
policy.lifecycle.deactivate
policy.lifecycle.delete
policy.lifecycle.overwrite
policy.lifecycle.update
policy.rule.add
policy.rule.deactivate
policy.rule.delete
policy.rule.invalidate
policy.rule.update
resource_servers.client_authentication_settings.create
oauth2.claim.deleted
resource_servers.client_authentication_settings.update
resource_servers.mcp_server.auth_server.create
resource_servers.mcp_server.auth_server.delete
resource_servers.mcp_server.auth_server.update
resource_servers.mcp_server.deactivate
resource_servers.mcp_server.delete
resource_servers.mcp_server.register
resource_servers.mcp_server.update
security.attack_protection.settings.update
security.authenticator.lifecycle.create
security.authenticator.lifecycle.deactivate
security.authenticator.lifecycle.update
security.behavior.settings.create
security.behavior.settings.delete
security.behavior.settings.update
oauth2.scope.deleted
security.device.add_request_blacklist_policy
security.device.remove_request_blacklist_policy
security.device.temporarily_disable_blacklisting
security.events.provider.create
security.events.provider.deactivate
security.events.provider.delete
security.events.provider.update
security.events.transmitter.create
security.events.transmitter.delete
security.events.transmitter.update
security.protected_action.settings.update
security.session_protection.status.update
security.threat.configuration.update
security.trusted_origin.create
security.trusted_origin.deactivate
security.trusted_origin.delete
security.trusted_origin.update
security.voice.add_country_blacklist
security.voice.remove_country_blacklist
security.zone.remove_blacklist
self_service.disabled
support.org.update
system.agent.ad.create
system.agent.ad.update_user
system.agent.ldap.update_user
system.brand.create
system.brand.delete
system.brand.update
system.custom_url_domain.update
system.identity_sources.bulk_delete
system.identity_sources.bulk_group_delete
system.identity_sources.bulk_group_membership_delete
system.identity_sources.group.create
system.identity_sources.group.delete
system.identity_sources.group.update
system.identity_sources.group.user.assign
system.identity_sources.user.create
system.identity_sources.user.delete
system.identity_sources.user.update
system.idp.key.delete
system.idp.key.update
system.idp.lifecycle.create
system.idp.lifecycle.deactivate
system.idp.lifecycle.update
system.import.group.create
system.import.group.delete
system.import.user.create
system.import.user.delete
system.import.user.suspend
system.import.user.update
system.iwa.create
system.iwa.update
system.log_stream.lifecycle.deactivate
system.log_stream.lifecycle.delete
system.log_stream.lifecycle.update
system.mfa.factor.deactivate
system.org.lifecycle.create
user.account.update_primary_email
user.account.update_profile
user.account.update_secondary_email
user.account.update_user_type
user.lifecycle.create
user.lifecycle.deactivate
user.lifecycle.delete.completed
system.idp.key.create
user.lifecycle.suspend
user.mfa.factor.deactivate
user.mfa.factor.suspend
user.mfa.factor.update
workflows.user.role.group.add
workflows.user.role.user.add
workload_principal.sign_on_provider.add
workload_principal.sign_on_provider.remove
zone.create
user.lifecycle.delete.initiated
Microsoft Active Directory
4720 - User Account Created
4722 - User Account Enabled
4725 - User Account Disabled
4726 - User Account Deleted
4738 - User Account Changed
4780 - ACL Set on Admin Accounts
4781 - Account Renamed
4741 - Computer Account Created
4742 - Computer Account Changed
4743 - Computer Account Deleted
4727 - Security Global Group Created
4728 - Member Added to Security Global Group
4729 - Member Removed from Security Global Group
4730 - Security Global Group Deleted
4731 - Security Local Group Created
4732 - Member Added to Security Local Group
4733 - Member Removed from Security Local Group
4734 - Security Local Group Deleted
4735 - Security Local Group Changed
4737 - Security Global Group Changed
4754 - Security Universal Group Created
4755 - Security Universal Group Changed
4756 - Member Added to Security Universal Group
4757 - Member Removed from Security Universal Group
4758 - Security Universal Group Deleted
4764 - Group Type Changed
4744 - Distribution Local Group Created
4745 - Distribution Local Group Changed
4746 - Member Added to Distribution Local Group
4747 - Member Removed from Distribution Local Group
4748 - Distribution Local Group Deleted
4749 - Distribution Global Group Created
4750 - Distribution Global Group Changed
4751 - Member Added to Distribution Global Group
4752 - Member Removed from Distribution Global Group
4753 - Distribution Global Group Deleted
4759 - Distribution Universal Group Created
4760 - Distribution Universal Group Changed
4761 - Member Added to Distribution Universal Group
4762 - Member Removed from Distribution Universal Group
4763 - Distribution Universal Group Deleted
4783 - Basic Application Group Created
4784 - Basic Application Group Changed
4785 - Member Added to Application Group
4786 - Member Removed from Application Group
4787 - Non-Member Added to Application Group
4788 - Non-Member Removed from Application Group
4789 - Basic Application Group Deleted
4790 - LDAP Query Group Created
4791 - Basic Application Group Changed
4792 - LDAP Query Group Deleted
5136 - Directory Service Object Modified
5137 - Directory Service Object Created
5139 - Directory Service Object Moved
5141 - Directory Service Object Deleted
4715 - Audit Policy Changed on Object
4706 - New Trust Created to Domain
4739 - Domain Policy Changed
8000 - GPO Created
8001 - GPO Deleted
8002 - GPO Settings Changed
8003 - GPO Link Created
8004 - GPO Link Deleted
8005 - GPO Link Modified (enabled/disabled/enforced)
8006 - GPO WMI Filter Linked
8007 - GPO WMI Filter Unlinked
306 - AD FS Configuration Object Created
307 - AD FS Configuration Object Updated
308 - AD FS Configuration Object Deleted
318 - AD FS Configuration Object Created
319 - AD FS Configuration Object Updated
320 - AD FS Configuration Object Deleted
510 - Additional Information for AD FS Configuration Change
511 - Additional Information for AD FS Configuration Change
4928 - AD Replica Source Naming Context Established
4929 - AD Replica Source Naming Context Removed
4930 - AD Replica Source Naming Context Modified
4931 - AD Replica Destination Naming Context Modified
5136 - Schema or Configuration Attribute Modified
5136 - managedBy Attribute Modified on OU/Group/Computer
4890 - Certificate Revocation Policy Changed
4891 - Certificate Manager Settings Changed
5137 - Contact Object Created
5136 - Contact Attribute Modified
5141 - Contact Object Deleted
5137 - OU Created
5136 - OU Attribute Modified (Description, GPO Links, Managed By)
5139 - OU Moved
5141 - OU Deleted
5137 - Container Object Created
5136 - Container Attribute Modified
5141 - Container Deleted
Next Steps
Build a guided recovery plan based on the results
