Password Edited audit events used to show only
whether
each field had changed — a YES or NO against it. They now record what actually changed.
Previous and new values are captured
for Display Name, Username, Account Type, Computer Name, URL, Notes and Password Access. Previously a change to Password Access recorded only what it had been changed
to
, so there was no way to tell from the audit trail what access had been in force beforehand. The YES/NO indicators remain, with the detail beneath them.
One-time passcode changes are now distinguishable
— the event states whether a passcode was created, changed or deleted, so a second factor being removed from an account is visible in the audit trail rather than looking like any other edit.
Sensitive values are still never recorded.
Password and passcode values are not written to events; for these fields the event says only that a change occurred — the password was changed, the secret key was removed — never the value before or after.
Events identify the type of entry.
Edits to an account linked to a source open with
Password Type: Linked Account
, and entries in Other Passwords with
Password Type: Other Password
, with the Source column showing the account name.
Events recorded before this release keep their original level of detail.