Log Rule Type: WindowsEvent Log Type: SecurityEvent Severity: InformationEvent ID: 4720Source: Microsoft-Windows-Security-Auditing