Active Directory Event ID
http://social.technet.microsoft.com/wiki/contents/articles/15232.adds-audit.aspx
Event ID Description
4741 – A computer account was created.
4742 – A computer account was changed.
4743 – A computer account was deleted.
4739 – Domain Policy was changed.
4782 – The password hash an account was accessed.
4727 – A security-enabled global group was created.
4728 – A member was added to a security-enabled global group.
4729 – A member was removed from a security-enabled global group.
4730 – A security-enabled global group was deleted.
4731 – A security-enabled local group was created.
4732 – A member was added to a security-enabled local group.
4733 – A member was removed from a security-enabled local group.
4734 – A security-enabled local group was deleted.
4735 – A security-enabled local group was changed.
4737 – A security-enabled global group was changed.
4754 – A security-enabled universal group was created.
4755 – A security-enabled universal group was changed.
4756 – A member was added to a security-enabled universal group.
4757 – A member was removed from a security-enabled universal group.
4758 – A security-enabled universal group was deleted.
4720 – A user account was created.
4722 – A user account was enabled.
4723 – An attempt was made to change an account’s password.
4724 – An attempt was made to reset an account’s password.
4725 – A user account was disabled.
4726 – A user account was deleted.
4738 – A user account was changed.
4740 – A user account was locked out.
4765 – SID History was added to an account.
4766 – An attempt to add SID History to an account failed.
4767 – A user account was unlocked.
4780 – The ACL was set on accounts which are members of administrators groups.
4781 – The name of an account was changed: