Multi-Factor Authentication for User Enabled
Sent when a user enables multi-factor authentication for a specific user if it is not used as a service account anymore. For more information, see DIsabling MFA for Service Accounts.
General Information
Event ID: 40203
Event message details: Multi-factor authentication has been enabled for <UserName> by <UserName>
Severity: Info
Parameters
|
Parameter Name |
Description |
Example |
|---|---|---|
|
UserFullInfo |
Detailed information about the user who performed an operation. Includes the following data:
|
UserFullInfo="<ModifiedUserInfo fullName="TECH\user1" loginType="0" />" |
|
VbrHostName |
Backup server name. Can be a DNS name, an FQDN or an IP address. |
VbrHostName="vbrsrv01.tech.local" |
|
VbrVersion |
Veeam Backup & Replication version. |
VbrVersion="13.0.1.180" |
|
Version |
Event version (service parameter). |
Version="1" |
|
Description |
Event message details. |
Description="Multi-factor authentication has been enabled for TECH\user2 by TECH\user1." |
Syslog Message Example
|
1 2025-11-19T06:06:51.123756-07:00 VBRSRV01 Veeam_MP - - [origin enterpriseId="31023"] [categoryId=0 instanceId=40203 UserFullInfo="<ModifiedUserInfo fullName="TECH\user1" loginType="0" />" VbrHostName="vbrsrv01.tech.local" VbrVersion="13.0.1.180" Version="1" Description="Multi-factor authentication has been enabled for TECH\user2 by TECH\user1."] |