We are starting to roll out Group Managed Service Accounts for things like services and scheduled tasks in my organization, part of that process when creating scheduled tasks that use the account is to create the scheduled task using powershell. I have no problem with a scheduled task whose trigger is a time of day as the New-ScheduledTaskTrigger cmdlet for that is very straightforward. My problem is we have several scheduled tasks that run when certain events ids occur in the event logs and I cannot seem to find any documentation on how to create a scheduled task in powershell based on those criteria. For example: Event ID 4740 Log: Security Source: Microsoft-Windows-Security-Auditing when an account gets locked out. Has anyone been able to successfully create scheduled tasks in powershell with these kind of triggers? If so your help is greatly appreciated.