In this scenario, the following event message is logged in the Security log:
Event Type: Success Audit
Event Source: Security
Event Category: Account Management
Event ID: 684
Date: 28.04.2006
Time: 05:16:33
User: NT AUTHORITY\ANONYMOUS LOGON
Computer: ComputerName
Description:
Set ACLs of members in administrators groups:
Target Account Name: NewlyCreatedUser
Target Domain: DC=DomainName,DC=com
Target Account ID: DomainName\ NewlyCreatedUser
Caller User Name: ComputerName$
Caller Domain: DomainName
Caller Logon ID: (0x0,0x3E7)
Privileges: -
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Event ID 684 is logged every 60 minutes on the primary domain controller (PDC) emulator.