Skip to main content

About Identity Behavioral Insights

Use this article to learn about the key terminologies of Identity Behavioral Insights and supported identity provider objects types.

Overview

Identity Behavioral Insights enables you to investigate the activity of a specific identity, whether a user or a service principal/NHI, over a defined time window.

Druva analyzes identity audit events from your connected identity provider, maps them to MITRE Tactics, Techniques, and Procedures (TTPs), and generates a detailed activity timeline. This timeline shows what changed, when it changed, and how the impact propagated, including objects that were created, modified, or deleted by the identity.

Identity Behavioural Insights

Provides compromised identity blast radius visibility to reduce investigation time from days to hours:

  • Timeline and table view of created, modified, or deleted objects.

  • Visualizes full blast radius, propagated impacts, and affected relationships.

  • Contextualizes changes using MITRE Tactics, Techniques, and Procedures (TTPs)

Guided Recovery

Delivers curated, granular recovery workflows ensuring a clean post-recovery state:

  • Generates recovery recommendations for each change detected by Identity Recovery Intelligence.

  • Offers flexibility to execute full recovery plans or selectively restore objects.

  • Eliminates attacker persistence with minimal business disruption.

Key Terminologies

Activity timeline

A chronological record of all events involving the analyzed identity during the investigation window. Events are displayed in a graph view (nodes connected by action edges) or a list view (event table). Each event shows the actor identity, the action taken, the target identity, and the mapped MITRE Tactics, Techniques, and Procedures (TTPs).

MITRE ATT&CK mapping

Druva maps each event to MITRE Tactics, Techniques, and Procedures (TTPs). The activity timeline summarizes event counts by tactic. The following MITRE ATT&CK tactics are used for mapping:

  • Persistence

  • Privilege Escalation

  • Defense Evasion

  • Credential Access

  • Impact

To learn more about these, see MITRE ATT&CK.

Recovery snapshot

A point-in-time backup of an identity's configuration. Druva uses snapshots to identify a clean pre-compromise state and to restore identities during a cyber recovery plan.

Recovery type

Suggested recovery options to restore the selected objects and the compromised identity back to a known, trusted state, ensuring business continuity by eliminating the attackers persistence. The guided recovery type can be either Recover, Rollback, or Delete.

  • Delete is recommended when there is suspicious create event action on identity. For example, a new user or application is created using a compromised identity to establish persistence.

  • Rollback is recommended when there is suspicious modified event action on identity. For example, an existing user, group, or policy is modified by a compromised identity.

  • Recover is recommended when there is suspicious delete event action on identity. For example, an existing user, group, or policy is deleted by a compromised identity.

Time Range

You can investigate events within a window of up to 30 days. The start date can go back up to 12 months from the current date.

At initial availability, the earliest start date is one month before Identity Resiliency was enabled in your region. This lookback window expands as backup data accumulates over time.

Analysis history

Each analysis is saved automatically. Reopening a saved analysis loads the previously generated results without re-running the computation.

You can reopen analyses from Analysis History on the results page or from the Recent Analyses list on the main Identity Behavioral Insights page.

Supported object types

The activity timeline tracks events across all the supported object types backed up by Identity Workloads - Okta, Entra ID, and Microsoft Active Directory.

Supported audit actions for Identity Behavioral Insights

Entra ID

Add administrative unit

Add member to administrative unit

Add member to restricted management administrative unit

Bulk remove members to administrative unit - finished (bulk)

Delete administrative unit

Hard Delete administrative unit

Remove member from administrative unit

Remove member from restricted management administrative unit

Update administrative unit

Add application

Delete application

Update application

Add app role assignment to service principal

Add application (Core Directory)

Add member to role in PIM completed (timebound)

Add owner to application

Add owner to service principal

Add policy to application

Add policy to service principal

Add service principal

Add service principal credentials

Authentication Methods Policy Reset

Authentication Methods Policy Update

Authentication Strength Combination Configuration Create

Authentication Strength Combination Configuration Delete

Authentication Strength Combination Configuration Update

Authentication Strength Policy Create

Authentication Strength Policy Delete

Authentication Strength Policy Update

Delete application (Core Directory)

Delete application collection

Hard Delete application

Hard delete service principal

MFA Service Policy Update

PIM policy removed

Remove app role assignment from service principal

Remove member from role in PIM completed (timebound)

Remove owner from application

Remove owner from service principal

Remove policy from application

Remove policy from service principal

Remove service principal

Remove service principal credentials

Role definition created

Set verified publisher

Unset verified publisher

Update application (Core Directory)

Update application - Certificates and secrets management

Update external secrets

Update role setting in PIM

Update service principal

Add a group to feature rollout

Add user to feature rollout

Create rollout policy for feature

Delete rollout policy of feature

Federate with an identity provider

Remove a group from feature rollout

Remove user from feature rollout

Remove user from feature rollout (Hybrid)

Update rollout policy of feature

Add v2 application permissions

Create Identity Provider

Create custom identity provider

Create custom policy

Create policy key

Create user flow

Create v2 application

Delete B2C Tenant where the caller is an administrator

Delete B2C directory resource

Delete CIAM directory resource

Delete Identity Provider

Delete custom policy

Delete policy key

Delete user flow

Delete v2 application

Delete v2 application permission grant

Update Identity Provider

Update age gating configuration

Update authentication flows policy

Update authenticationEventsPolicy

Update custom identity provider

Update custom policy

Update local identity provider

Update policy key

Update tenant metadata

Update user flow

Update authorization policy

The role assignment of User Access Administrator has been removed from the user

Add CertBasedAuthConfiguration

Hard delete CertificationBasedAuthConfiguration

Add CertificateBasedAuthConfiguration

Delete CertificateBasedAuthConfiguration

Update CertificateBasedAuthConfiguration

Delete Branding Theme

Hard Delete Branding Theme

Delete Branding Theme Localization

Hard Delete Branding Theme Localization

Add a domain-based partner to cross-tenant access setting

Add a partner to cross-tenant access setting

Delete a domain-based partner to cross-tenant access setting

Delete partner specific cross-tenant access setting

Reset the cross-tenant access default setting

Update a domain-based partner to cross-tenant access setting

Update a partner cross-tenant access setting

Update the company default cross-tenant access setting

Create a partner cross-tenant identity sync setting

Delete a partner cross-tenant identity sync setting

Update a partner cross-tenant identity sync setting

Adding allowed assignable roles

Updating allowed assignable roles

Add device configuration

Delete device configuration

Update device configuration

Add DeviceTemplate

Add device from DeviceTemplate

Add owner to DeviceTemplate

Add partner to company

Add sharedEmailDomainInvitation

Add unverified domain

Add verified domain

DELETE Subscription.DeleteProviders

Delete company allowed data location

Delete company settings

Delete subscription

Deleting Source Tenant subscriptions

Directory deleted

Directory scheduled for deletion (Lifecycle)

Disable Desktop Sso

Disable Desktop Sso for a specific domain

Disable application proxy

Disable passthrough authentication

Disable password writeback for directory

Hard Delete Domain

PATCH Tenant.Patch

Promote sub domain to root domain

Remove partner from company

Remove unverified domain

Remove verified domain

Schedule Add sharedEmailDomain

Schedule Remove sharedEmailDomain

Set DirSync feature

Set DirSyncEnabled flag

Set directory feature on tenant

Set domain authentication

Set federation settings on domain

Set password policy

Soft Delete Domain

Suspending Source Tenant Subscriptions

Update Domain

Update sharedEmailDomain

Update sharedEmailDomainInvitation

Delete incompatible group

Remove user as external sponsor

Remove user as internal sponsor

Update tenant setting

Add app role assignment to group

Add eligible member to role in PIM completed (permanent)

Add eligible member to role in PIM completed (timebound)

Add group

Add group (MIM)

Add member to group

Add member to group (MIM)

Add owner to group

Add owner to group (MIM)

Assign label to group

Bulk remove group members - finished (bulk)

Create group settings

Create lifecycle management policy

Delete group

Delete group (MIM)

Delete group settings

Delete lifecycle management policy

Features_UpdateFeaturesAsync

GroupLifecyclePolicies_addGroup

GroupLifecyclePolicies_removeGroup

Group_AddMember

Group_AddOwner

Group_Create

Group_Delete

Group_RemoveMember

Group_RemoveOwner

Group_Update

Groups_CreateLink

Hard Delete group

PIM policy removed (Group)

Remove app role assignment from group

Remove eligible member from group

Remove eligible owner from group

Remove label from group

Remove member from group

Remove member from group (MIM)

Remove owner from group

Remove owner from group (MIM)

Remove permanent direct role assignment

Remove permanent eligible role assignment

Set group to be managed by user

Update group

Update group (MIM)

Update group settings

Update lifecycle management policy

Update member in PIM approved by admin (extend/renew)

Update role setting in PIM

User_Create

User_Delete

set dynamic group properties

Update IdentityProtectionPolicy

Add kerberos domain

Delete kerberos domain

Update kerberos domain

Add label

Delete label

Create a MultiTenantOrg

Hard Delete MultiTenantOrg

Update a MultiTenantOrg

Reset a multi tenant org identity sync policy template

Update a multi tenant org identity sync policy template

Reset a multi tenant org partner configuration template

Update a multi tenant org partner configuration template

Add MultiTenantOrg tenant

Delete MultiTenantOrg tenant

Hard Delete MultiTenantOrg tenant

Tenant joining MultiTenantOrg tenant

Update MultiTenantOrg tenant

Update Adaptive Access Policy

Update Enriched Audit Logs Settings

Update Forwarding Options Policy

Delete PendingExternalUserProfile

Hard Delete PendingExternalUserProfile

Add permission grant policy

Delete permission grant policy

Update permission grant policy

Add AuthenticationContextClassReference

Add Conditional Access policy

Add blocked user

Add bypass user

Add owner to policy

Add policy

Delete AuthenticationContextClassReference

Delete Conditional Access policy

Delete policy

Hard Delete policy

Remove bypassed user

Remove owner from policy

Remove policy credentials

Set device registration policies

Update AuthenticationContextClassReference

Update Conditional Access policy

Update Sign-In Risk Policy

Update User Risk and MFA Registration Policy

Update continuous access evaluation

Update partner directory settings

Update policy

Create Filtering Policy

Create Filtering Policy Profile

Create Security Provider Policy

Delete Filtering Policy

Delete Filtering Policy Profile

Delete Forwarding Policy

Delete Private Access Policy

Delete Remote Network

Delete Security Provider Policy

Update Filtering Policy

Update Filtering Policy Profile

Update Filtering Profile

Update Forwarding Policy

Update Forwarding Profile

Update Forwarding Rule

Update Private Access Policy

Update Remote Network

Update Security Provider Policy

Add provisioning configuration

Delete provisioning configuration

Disable/pause provisioning configuration

Update attribute mappings or scope

Update provisioning setting or credentials

Create PublicKeyInfrastructure

Delete PublicKeyInfrastructure

Hard Delete PublicKeyInfrastructure

Update PublicKeyInfrastructure

Add a Connector to Connector Group

Add application SSL certificate

Add connector Group

Add member to role outside of PIM (permanent)

Create Identity Provider (B2C)

Create Registration of Security Provider

Create authority

Create authorization policy

Create custom identity provider (B2C)

Create custom policy (B2C)

Create issuance policy

Create or update a localized resource (B2C)

Create user attribute (B2C)

Delete B2C Tenant where the caller is an administrator (B2C)

Delete B2C directory resource (B2C)

Delete CIAM directory resource (B2C)

Delete Connector Group

Delete Identity Provider (B2C)

Delete SSL binding

Delete custom policy (B2C)

Delete issuance policy

Delete policy key (B2C)

Delete user attribute (B2C)

Delete user flow (B2C)

Disable PIM alert

Move resources (B2C)

PIM policy removed (Resource)

Remove permanent direct role assignment (Resource)

Remove permanent eligible role assignment (Resource)

Rotate signing key

Update Connector Group

Update authentication flows policy (B2C)

Update authority

Update certificate to policy key (B2C)

Update custom identity provider (B2C)

Update custom policy (B2C)

Update identity provider (B2C)

Update issuance policy

Update linked domains

Update local identity provider (B2C)

Update policy key (B2C)

Update role setting in PIM (Resource)

Update secret into policy key (B2C)

Update user flow (B2C)

Add EligibleRoleAssignment to RoleDefinition

Add eligible member to role

Add eligible member to role in PIM completed (permanent) (Role)

Add eligible member to role in PIM completed (timebound) (Role)

Add member to role

Add member to role outside of PIM (permanent) (Role)

Add member to role scoped over Restricted Management Administrative Unit

Add role assignment to role definition

Add role definition

Add role from template

Add scoped member to role

Delete role definition

Disable PIM alert (Role)

PIM policy removed (Role)

Remove EligibleRoleAssignment from RoleDefinition

Remove eligible member from role

Remove member from role

Remove member from role scoped over Restricted Management Administrative Unit

Remove permanent direct role assignment (Role)

Remove permanent eligible role assignment (Role)

Remove role assignment from role definition

Remove scoped member from role

Update PIM alert setting

Update role

Update role definition

Update role setting in PIM (Role)

Add app role assignment to group (UserManagement)

Add user

Add user sponsor

Bulk delete users - finished (bulk)

Delete external user

Delete user

Disable Strong Authentication

Disable account

Hard Delete user

Remove app role assignment from user

Remove user sponsor

Update per-user multifactor authentication state

Update user

Update tenant settings

Admin deleted security info

Admin registered security info

Admin updated security info

User changed default security info

User deleted security info

User registered all required security info

User registered security info

User updated security info

Update PasswordProfile

Okta

account.org.status.update

account.org_group.create

account.org_group.delete

account.org_group.org.assign

account.org_group.org.revoke

account.org_group.update

app.ad.password_migration_campaign.group.add

app.cross_app_access.connection.create

app.cross_app_access.connection.delete

app.cross_app_access.connection.update

app.interclient_mapping.create

app.interclient_mapping.delete

app.interclient_mapping.delete_all

app.oauth2.as.resource_server.credentials.lifecycle.delete

app.oauth2.client.lifecycle.delete

app.oauth2.admin.consent.revoke

app.oauth2.as.consent.revoke

app.oauth2.as.consent.revoke.implicit.as

app.oauth2.as.consent.revoke.implicit.client

app.oauth2.as.consent.revoke.implicit.scope

app.oauth2.as.consent.revoke.implicit.user

app.oauth2.as.consent.revoke.user

app.oauth2.as.consent.revoke.user.client

app.oauth2.as.resource_server.credentials.lifecycle.create

app.oauth2.as.resource_server.credentials.lifecycle.deactivate

app.oauth2.credentials.lifecycle.delete

app.oauth2.trusted_server.delete

oauth2.as.deleted

resource_servers.client_authentication_settings.delete

app.oauth2.client.lifecycle.create

app.oauth2.client.lifecycle.deactivate

app.oauth2.client.lifecycle.update

app.oauth2.client.privilege.revoke

app.oauth2.credentials.lifecycle.deactivate

app.oauth2.trusted_server.add

app.office365.user.delete.success

app.office365.user.remove.licenses.success

app.policy.sign_on.update

app.saml.sensitive.attribute.update

app.user_management.grouppush.mapping.created.from.rule

app.user_management.user_group_import.delete_success

application.configuration.disable_delauth_outbound

application.configuration.disable_fed_broker_mode

application.configuration.update

application.configuration.update_rate_limits

application.lifecycle.create

application.lifecycle.deactivate

application.lifecycle.delete

application.lifecycle.update

application.policy.sign_on.rule.create

application.policy.sign_on.rule.delete

application.policy.sign_on.update

application.provision.field_mapping_rule.change

application.provision.group.add

application.provision.group.remove

application.provision.group.update

application.provision.group_membership.add

application.provision.group_membership.remove

application.provision.group_membership.update

application.provision.group_push.deactivate_mapping

application.provision.group_push.delete_appgroup

application.provision.group_push.mapping.and.groups.deleted.rule.deleted

application.provision.group_push.mapping.app.group.renamed

application.provision.group_push.mapping.created

application.provision.group_push.mapping.deactivated.source.group.renamed

application.provision.group_push.removed

application.provision.group_push.updated

application.provision.user.deactivate

application.provision.user.deprovision

application.registration_policy.lifecycle.create

application.registration_policy.lifecycle.update

application.user_membership.add

application.user_membership.change_username

application.user_membership.deprovision

application.user_membership.remove

application.user_membership.revoke

application.user_membership.update

device.assurance.policy.add

device.assurance.policy.delete

device.assurance.policy.update

device.desktop_mfa.configuration.update

device.local_account.create

device.platform.add

device.platform.delete

device.platform.update

device.push.provider.create

device.push.provider.delete

device.push.provider.update

directory.app_user_profile.update

directory.external.group.membership.add

directory.external.group.membership.remove

directory.linked_object.create

directory.linked_object.delete

directory.mapping.update

directory.user_profile.update

event_hook.created

event_hook.deactivated

event_hook.deleted

event_hook.updated

group.application_assignment.add

group.application_assignment.remove

group.application_assignment.update

group.lifecycle.create

group.lifecycle.delete

group.privilege.revoke

group.profile.update

group.user_membership.add

group.user_membership.remove

group.user_membership.rule.add_exclusion

group.user_membership.rule.deactivated

group.user_membership.rule.invalidate

iam.policy.assignee_configuration.update

iam.policy.configuration.update

iam.resourceset.bindings.add

iam.resourceset.bindings.delete

iam.resourceset.create

iam.resourceset.delete

iam.resourceset.resources.add

iam.resourceset.resources.delete

iam.resourceset.resources.update

iam.resourceset.update

iam.role.create

iam.role.delete

iam.role.permission.conditions.add

iam.role.permission.conditions.delete

iam.role.permissions.add

iam.role.permissions.delete

iam.role.subscriptions.update

iam.role.update

inline_hook.created

inline_hook.deactivated

inline_hook.deleted

master_application.user_membership.add

network_zone.rule.disabled

oauth2.as.created

oauth2.as.deactivated

oauth2.as.updated

pam.active_directory.account_rule.update

pam.ad_connection.create

pam.ad_connection.update

pam.cloud_account.create

pam.group.bulk_membership_change

pam.member.add

pam.member.remove

pam.project.add_group

pam.project.remove_group

pam.security_policy.create

pam.security_policy.delete

pam.security_policy.update

pam.service_account.create

pam.team_group_attribute.create

pam.team_project_group_attribute.create

pam.team_project_user_attribute.create

pam.team_project_user_attribute.delete

pam.team_project_user_attribute.update

pam.team_user_attribute.create

pam.team_user_attribute.delete

pam.team_user_attribute.update

pam.user.create

pam.user.remove

pam.user.update

pam.workload_role.create

personal.admin.configuration.update

policy.lifecycle.create

policy.lifecycle.deactivate

policy.lifecycle.delete

policy.lifecycle.overwrite

policy.lifecycle.update

policy.rule.add

policy.rule.deactivate

policy.rule.delete

policy.rule.invalidate

policy.rule.update

resource_servers.client_authentication_settings.create

oauth2.claim.deleted

resource_servers.client_authentication_settings.update

resource_servers.mcp_server.auth_server.create

resource_servers.mcp_server.auth_server.delete

resource_servers.mcp_server.auth_server.update

resource_servers.mcp_server.deactivate

resource_servers.mcp_server.delete

resource_servers.mcp_server.register

resource_servers.mcp_server.update

security.attack_protection.settings.update

security.authenticator.lifecycle.create

security.authenticator.lifecycle.deactivate

security.authenticator.lifecycle.update

security.behavior.settings.create

security.behavior.settings.delete

security.behavior.settings.update

oauth2.scope.deleted

security.device.add_request_blacklist_policy

security.device.remove_request_blacklist_policy

security.device.temporarily_disable_blacklisting

security.events.provider.create

security.events.provider.deactivate

security.events.provider.delete

security.events.provider.update

security.events.transmitter.create

security.events.transmitter.delete

security.events.transmitter.update

security.protected_action.settings.update

security.session_protection.status.update

security.threat.configuration.update

security.trusted_origin.create

security.trusted_origin.deactivate

security.trusted_origin.delete

security.trusted_origin.update

security.voice.add_country_blacklist

security.voice.remove_country_blacklist

security.zone.remove_blacklist

self_service.disabled

support.org.update

system.agent.ad.create

system.agent.ad.update_user

system.agent.ldap.update_user

system.brand.create

system.brand.delete

system.brand.update

system.custom_url_domain.update

system.identity_sources.bulk_delete

system.identity_sources.bulk_group_delete

system.identity_sources.bulk_group_membership_delete

system.identity_sources.group.create

system.identity_sources.group.delete

system.identity_sources.group.update

system.identity_sources.group.user.assign

system.identity_sources.user.create

system.identity_sources.user.delete

system.identity_sources.user.update

system.idp.key.delete

system.idp.key.update

system.idp.lifecycle.create

system.idp.lifecycle.deactivate

system.idp.lifecycle.update

system.import.group.create

system.import.group.delete

system.import.user.create

system.import.user.delete

system.import.user.suspend

system.import.user.update

system.iwa.create

system.iwa.update

system.log_stream.lifecycle.deactivate

system.log_stream.lifecycle.delete

system.log_stream.lifecycle.update

system.mfa.factor.deactivate

system.org.lifecycle.create

user.account.update_primary_email

user.account.update_profile

user.account.update_secondary_email

user.account.update_user_type

user.lifecycle.create

user.lifecycle.deactivate

user.lifecycle.delete.completed

system.idp.key.create

user.lifecycle.suspend

user.mfa.factor.deactivate

user.mfa.factor.suspend

user.mfa.factor.update

workflows.user.role.group.add

workflows.user.role.user.add

workload_principal.sign_on_provider.add

workload_principal.sign_on_provider.remove

zone.create

user.lifecycle.delete.initiated

Microsoft Active Directory

4720 - User Account Created

4722 - User Account Enabled

4725 - User Account Disabled

4726 - User Account Deleted

4738 - User Account Changed

4780 - ACL Set on Admin Accounts

4781 - Account Renamed

4741 - Computer Account Created

4742 - Computer Account Changed

4743 - Computer Account Deleted

4727 - Security Global Group Created

4728 - Member Added to Security Global Group

4729 - Member Removed from Security Global Group

4730 - Security Global Group Deleted

4731 - Security Local Group Created

4732 - Member Added to Security Local Group

4733 - Member Removed from Security Local Group

4734 - Security Local Group Deleted

4735 - Security Local Group Changed

4737 - Security Global Group Changed

4754 - Security Universal Group Created

4755 - Security Universal Group Changed

4756 - Member Added to Security Universal Group

4757 - Member Removed from Security Universal Group

4758 - Security Universal Group Deleted

4764 - Group Type Changed

4744 - Distribution Local Group Created

4745 - Distribution Local Group Changed

4746 - Member Added to Distribution Local Group

4747 - Member Removed from Distribution Local Group

4748 - Distribution Local Group Deleted

4749 - Distribution Global Group Created

4750 - Distribution Global Group Changed

4751 - Member Added to Distribution Global Group

4752 - Member Removed from Distribution Global Group

4753 - Distribution Global Group Deleted

4759 - Distribution Universal Group Created

4760 - Distribution Universal Group Changed

4761 - Member Added to Distribution Universal Group

4762 - Member Removed from Distribution Universal Group

4763 - Distribution Universal Group Deleted

4783 - Basic Application Group Created

4784 - Basic Application Group Changed

4785 - Member Added to Application Group

4786 - Member Removed from Application Group

4787 - Non-Member Added to Application Group

4788 - Non-Member Removed from Application Group

4789 - Basic Application Group Deleted

4790 - LDAP Query Group Created

4791 - Basic Application Group Changed

4792 - LDAP Query Group Deleted

5136 - Directory Service Object Modified

5137 - Directory Service Object Created

5139 - Directory Service Object Moved

5141 - Directory Service Object Deleted

4715 - Audit Policy Changed on Object

4706 - New Trust Created to Domain

4739 - Domain Policy Changed

8000 - GPO Created

8001 - GPO Deleted

8002 - GPO Settings Changed

8003 - GPO Link Created

8004 - GPO Link Deleted

8005 - GPO Link Modified (enabled/disabled/enforced)

8006 - GPO WMI Filter Linked

8007 - GPO WMI Filter Unlinked

306 - AD FS Configuration Object Created

307 - AD FS Configuration Object Updated

308 - AD FS Configuration Object Deleted

318 - AD FS Configuration Object Created

319 - AD FS Configuration Object Updated

320 - AD FS Configuration Object Deleted

510 - Additional Information for AD FS Configuration Change

511 - Additional Information for AD FS Configuration Change

4928 - AD Replica Source Naming Context Established

4929 - AD Replica Source Naming Context Removed

4930 - AD Replica Source Naming Context Modified

4931 - AD Replica Destination Naming Context Modified

5136 - Schema or Configuration Attribute Modified

5136 - managedBy Attribute Modified on OU/Group/Computer

4890 - Certificate Revocation Policy Changed

4891 - Certificate Manager Settings Changed

5137 - Contact Object Created

5136 - Contact Attribute Modified

5141 - Contact Object Deleted

5137 - OU Created

5136 - OU Attribute Modified (Description, GPO Links, Managed By)

5139 - OU Moved

5141 - OU Deleted

5137 - Container Object Created

5136 - Container Attribute Modified

5141 - Container Deleted

Next Steps

Did this answer your question?