Event ID 4671 – An Application Attempted To Access A Blocked Ordinal Through the TBS
Event ID | 4671 |
Category | Object Access: Other Object Access Events |
Type | Success Audit |
When an application tries to access a blocked ordinal through the TBS, event 4671 is logged. TBS is a part of the Trusted Platform Module. Though this event is defined, it is never invoked by the operating system, and thus currently doesn't generate.
This log data provides the following information:
- Security ID
- Account Name
- Account Domain
- Logon ID
- Ordinal
Why does event ID 4671 need to be monitored?
The documentation provided by Microsoft states that this event is never generated by the OS. Thus, the occurrence of this event could indicate a deeper and critical problem which would need further investigation.
Event 4671 applies to the following operating systems:
- Windows 2008 R2 and 7
- Windows 2012 R2 and 8.1
- Windows 2016 and 10
Explore Active Directory auditing and reporting with ADAudit Plus.
- Related Products
- ADManager Plus Active Directory Management & Reporting
- ADAudit Plus Real-time Active Directory Auditing and UBA
- EventLog Analyzer Real-time Log Analysis & Reporting
- ADSelfService Plus Self-Service Password Management
- AD360 Integrated Identity & Access Management
- Log360 (On-Premise | Cloud) Comprehensive SIEM and UEBA
- AD Free Tools Active Directory FREE Tools