Event ID 5137 is a common security errors in Windows Security event logs. This error is usually related to a directory service object in Active Directory. Luckily, you can solve this error easily after applying the solutions mentioned in this post from MiniTool Solution.

What Is Event ID 5137?

Event Viewer can provide you with a list of Event IDs that help monitor and track objection creations. Event ID 5137 is a specific event log entry associated with security audit failures in the active directory, specially to a directory service object. Usually, this error might crop up in the following situations:

  • Improper configurations – misconfigurations or errors in Active Directory settings like issues with synchronization or permissions processes.
  • Unauthorized object creation – it indicates a sign of a malicious activity or security breach.
  • Legitimate object creation – this error appears due to some daily administrative operations including creating a user account, group, organizational unites, and so on.

Suggestions: Back up Your Data Before Proceeding

As mentioned above, if Event ID 5137 occurs due to an unauthorized object creation, it might be a sign of malicious activities or security breaches. To safeguard your data, it is essential to create a backup of your important files with a professional Windows backup software – MiniTool ShadowMaker.

This powerful tool is designed to back up files, folders, partitions, systems, and even the whole disk. Moreover, it also enables you to move OS to another drive with ease. Now, let’s see how to create a file backup with it:

Step 1. Launch MiniTool ShadowMaker Trial Edition.

MiniTool ShadowMaker TrialClick to Download100%Clean & Safe

Step 2. In the Backup page, you can select what to backup and where to save the backup image.

  • Backup source – select SOURCE > Folders and Files, and then you can check the files you want to back up.
  • Backup destination – select an external hard drive or USB flash drive as the storage path in DESTINATION.

Step 3. Click on Back Up Now to start the process at once.

hit Back Up Now

How to Fix Event ID 5137 on Windows 10/11?

Fix 1: Verify the Legitimacy

Event Viewer allows you to identify the subjected directory service object by listing all the information related to the error. Here’s how to review the event details with it:

Step 1. Press Win + S to evoke the search bar.

Step 2. Type event viewer and hit Enter.

Step 3. In the left pane, expand Windows Logs > Security.

the event logs

Step 4. Then, you can see a list of event logs. Locate Event ID 5137 and double-click on it to see all the error details in General. If you find anything suspicious, please move to the following solution.

Fix 2: Check Object Permissions

To fix event ID 5137, make sure all the object’s permissions are configured properly. Here’s how to do it in Local Group Policy Editor:

Tips:
Local Group Policy Editor is only available in Windows 10 Pro and Enterprise. If you are using Windows 10 Home edition, you need to upgrade your Windows edition. Or else, you might get the Windows cannot find gpedit.msc error.

Step 1. Right-click on the Start menu and select Run.

Step 2. Type gpedit.msc and hit Enter to launch Local Group Policy Editor.

Step 3. Navigate to the following path:

Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy

Step 4. Double-click on Audit Policy and then check if all the policies are appropriate.

Audit Policy

Final Words

That’s all you can do when running into Event ID 5137 a directory service object was created on your computer. Also, don’t forget to back up your crucial files with MiniTool ShadowMaker to add an extra protection layer of your data. Have a nice day!

  • linkedin
  • reddit