Skip to content

Object-Access

4656 A handle to an object was requested

4657 A registry value was modified

4658 The handle to an object was closed

4660 An object was deleted

4661 A handle to an AD/SAM object was requested

4662 An operation was performed on an object

4663 An attempt was made to access an object

4664 An attempt was made to create a hard link

4670 Permissions on an object were changed

4671 An application attempted to access a blocked ordinal through the TBS

4690 An attempt was made to duplicate a handle to an object

4691 Indirect access to an object was requested

4818 Proposed Central Access Policy does not grant the same access as the current one

4985 The state of a transaction has changed

5039 A registry key was virtualized

5051 A file was virtualized

5140 A network share object was accessed

5142 A network share object was added

5143 A network share object was modified

5144 A network share object was deleted

5145 A network share object was checked for desired access (detailed file share)

5148 WFP detected a DoS attack and entered a defensive mode

5149 The DoS attack has subsided and normal processing is being resumed

5168 SPN check for SMB/SMB2 failed

5712 A Remote Procedure Call (RPC) was attempted

5888 An object in the COM+ Catalog was modified

5889 An object was deleted from the COM+ Catalog

5890 An object was added to the COM+ Catalog

6416 A new external device was recognized by the System

6419 A request was made to disable a device

6420 A device was disabled

6421 A request was made to enable a device

6422 A device was enabled

6423 The installation of this device is forbidden by system policy

6424 The installation of this device was allowed, after previously being forbidden by policy