I was pinged today by a coworker who was trying to track down password change audit entries that looked something like: Event Type: Success Audit Event Source: Security Event Category: Account Management Event ID: 628 Date: 1/14/2013 Time: 2:52:32 PM User: NT AUTHORITY\SYSTEM Computer: DCNAME Description: User Account password set: Target Account Name: USERID […]