Skip to content
Task Scheduler

Task Scheduler Event ID 142: Task disabled

Task disabledTask Scheduler event 142 records that a user disabled a scheduled task — relevant when security, update or backup tasks are switched off.
142
Event ID
142
Channel
Microsoft-Windows-TaskScheduler/Operational
Provider
Microsoft-Windows-TaskScheduler
Log file
Microsoft-Windows-TaskScheduler%4Operational.evtx
Category
Scheduled tasks
Default logging
Needs configuration

What event 142 means

Event 142 is written when a registered task is disabled, for example with schtasks /change /disable, Disable-ScheduledTask or the console. The task stays in the library but will no longer run on its triggers. The record holds the task path (TaskName) and the account that disabled it (UserName).

Most disables are routine administration. What matters is which task: tasks that run antivirus scans or signature updates, Windows Update, backups or log collection are the ones an attacker wants silenced, and a disable is quieter than a deletion.

If object access auditing is enabled, Security event 4701 records the same action with the task XML, which helps confirm what the disabled task used to do.

When it is logged

Audit policy / configuration

The Microsoft-Windows-TaskScheduler/Operational channel must be enabled — "Enable All Tasks History" in the Task Scheduler console, or wevtutil sl Microsoft-Windows-TaskScheduler/Operational /e:true.

The default state of this channel is not consistent across Windows versions, editions and builds: on some installs it is already recording, on others task history is off and the log stays empty until someone enables it. Check whether the log holds any records before treating a missing event as evidence. On busy hosts the log rolls over quickly.

Key fields

FieldWhat it tells you
TaskNameFull path of the disabled task in the task library.
UserNameAccount that disabled the task (DOMAIN\user or NT AUTHORITY\SYSTEM).

Common benign sources

  • Administrators or optimization scripts disabling telemetry, consumer or vendor tasks.
  • Software disabling its own updater task when a setting is changed.

What attackers do that produces it

  • Disabling security product, Windows Update or backup tasks before deploying ransomware or other payloads.
  • Disabling a legitimate task so a look-alike malicious task can take its place.

Investigation tips

  • Review TaskName against a list of tasks that must stay enabled (AV, update, backup, monitoring agents).
  • Check whether UserName is an expected admin account and whether the change came during a known maintenance window.
  • Look for other defense tampering around the same time (service stops, Defender configuration changes).

MITRE ATT&CK techniques

TechniqueTactics
T1685 Disable or Modify ToolsDefense Impairment

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading