I am using a tool called SumoLogic to analyze the windows syslogs. i am looking for the i someone change there account to have there password never expire. i can find and event id closest i have been able to find is account been changed?
Active DirectoryWindows Server 2008SecurityOS Security