﻿<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>WinSecWiki » Windows Security Settings » Local Policies » Audit Policy » Audit policy change</title><generator>InstantKB.NET 2.0.3</generator><description>WinSecWiki</description><link>http://www.ultimatewindowssecurity.com/wiki/</link><webMaster>noreply@ultimatewindowssecurity.com</webMaster><lastBuildDate>Tue, 21 May 2013 02:04:16 GMT</lastBuildDate><ttl>20</ttl><item><title>Other Policy Change Events</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50606.aspx</link><description>&lt;font color="#000000" size="1"&gt;So far I've only found one event in this category and it should clearly be in the &lt;/font&gt;&lt;a title="Audit Category: Filtering Platform Policy Change (Vista and Windows Server 2008)" class="pagelink" href="/wiki/WindowsSecuritySettings/Filtering-Platform-Policy-Change"&gt;&lt;font color="#000000" size="1"&gt;Filtering Platform Policy Change&lt;/font&gt;&lt;/a&gt;&lt;font color="#000000" size="1"&gt; subcategory instead. As with all subcategories you must use auditpol to enable to disable these events.&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=5&amp;amp;subcatid=40"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;/span&gt;&lt;br /&gt;&lt;/font&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5447" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5447"&gt;5447&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5447" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5447"&gt;A Windows Filtering Platform filter has been changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 17:25:52 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Filtering Platform Policy Change</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50605.aspx</link><description>&lt;font color="#000000"&gt;&lt;font size="1"&gt;This chatty category documents the current configuration of the Windows Filtering Platform (related for lower level than the Windows Firewall) whenever it starts as well as any changes to it's configuration. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=5&amp;amp;subcatid=39"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5440" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5440"&gt;5440&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5440" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5440"&gt;The following callout was present when the Windows Filtering Platform Base Filtering Engine started&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5441" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5441"&gt;5441&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5441" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5441"&gt;The following filter was present when the Windows Filtering Platform Base Filtering Engine started.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5442" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5442"&gt;5442&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5442" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5442"&gt;The following provider was present when the Windows Filtering Platform Base Filtering Engine started.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5443" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5443"&gt;5443&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5443" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5443"&gt;The following provider context was present when the Windows Filtering Platform Base Filtering Engine started.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5444" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5444"&gt;5444&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5444" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5444"&gt;The following sub-layer was present when the Windows Filtering Platform Base Filtering Engine started.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5446" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5446"&gt;5446&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5446" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5446"&gt;A Windows Filtering Platform callout has been changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5448" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5448"&gt;5448&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5448" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5448"&gt;A Windows Filtering Platform provider has been changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5449" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5449"&gt;5449&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5449" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5449"&gt;A Windows Filtering Platform provider context has been changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5450" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5450"&gt;5450&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 5450" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=5450"&gt;A Windows Filtering Platform sub-layer has been changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 17:24:23 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>MPSSVC Rule-Level Policy Change</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50604.aspx</link><description>&lt;font color="#000000"&gt;&lt;font size="1"&gt;This chatty category documents the current configuration of the Windows Firewall (aka MPSSVC) whenever it starts as well as any changes to it's configuration. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=5&amp;amp;subcatid=38"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4944" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4944"&gt;4944&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4944" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4944"&gt;The following policy was active when the Windows Firewall started.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4945" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4945"&gt;4945&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4945" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4945"&gt;A rule was listed when the Windows Firewall started.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4946" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4946"&gt;4946&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4946" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4946"&gt;A change has been made to Windows Firewall exception list. A rule was added.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4947" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4947"&gt;4947&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4947" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4947"&gt;A change has been made to Windows Firewall exception list. A rule was modified.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4948" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4948"&gt;4948&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4948" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4948"&gt;A change has been made to Windows Firewall exception list. A rule was deleted.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4949" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4949"&gt;4949&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4949" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4949"&gt;Windows Firewall settings were restored to the default values.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4950" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4950"&gt;4950&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4950" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4950"&gt;A Windows Firewall setting has changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4951" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4951"&gt;4951&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4951" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4951"&gt;A rule has been ignored because its major version number was not recognized by Windows Firewall.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4952" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4952"&gt;4952&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4952" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4952"&gt;Parts of a rule have been ignored because its minor version number was not recognized by Windows Firewall.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4954" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4954"&gt;4954&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4954" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4954"&gt;Windows Firewall Group Policy settings has changed. The new settings have been applied.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4956" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4956"&gt;4956&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4956" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4956"&gt;Windows Firewall has changed the active profile.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4957" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4957"&gt;4957&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4957" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4957"&gt;Windows Firewall did not apply the following rule:&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4958" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4958"&gt;4958&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4958" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4958"&gt;Windows Firewall did not apply the following rule because the rule referred to items not configured on this computer:&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;div id="MainFooterDiv"&gt;&lt;!-- Used for layout purposes only --&gt;&lt;/div&gt;</description><pubDate>Tue, 28 Aug 2012 17:22:38 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Authorization Policy Change</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50603.aspx</link><description>&lt;font color="#000000" size="1"&gt;I've only isolated a few events logged by this category. Let me know via a discussion post on this event if you know of more. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.&lt;br /&gt;&lt;br /&gt;&lt;/font&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;&lt;font color="#000000" size="2"&gt;&lt;font size="1"&gt;Coverage on events generated by this category are currently in the &lt;/font&gt;&lt;a href="/securitylog/encyclopedia/Default.aspx?catid=5&amp;amp;subcatid=37"&gt;&lt;font size="1"&gt;Security Log Encyclopedia&lt;/font&gt;&lt;/a&gt;&lt;font size="1"&gt;:&lt;/font&gt;&lt;br /&gt;&lt;/font&gt;&lt;span&gt;&lt;font color="#000000" size="2"&gt;&lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4704" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4704"&gt;4704&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4704" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4704"&gt;A user right was assigned.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4705" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4705"&gt;4705&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4705" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4705"&gt;A user right was removed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4714" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4714"&gt;4714&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4714" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4714"&gt;Encrypted data recovery policy was changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 17:21:14 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Authentication Policy Change</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50602.aspx</link><description>&lt;font color="#000000"&gt;&lt;font size="1"&gt;This category tracks any configuration changes that would impact how user accounts are authenticated although password and lockout policies are conspicuously missing. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.&lt;br /&gt;&lt;br /&gt;&lt;/font&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;&lt;font size="2"&gt;&lt;font size="1"&gt;Coverage on events generated by this category are currently in the &lt;/font&gt;&lt;a href="/securitylog/encyclopedia/Default.aspx?catid=5&amp;amp;subcatid=36"&gt;&lt;font size="1"&gt;Security Log Encyclopedia&lt;/font&gt;&lt;/a&gt;&lt;font size="1"&gt;:&lt;/font&gt;&lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4706" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4706"&gt;4706&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4706" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4706"&gt;A new trust was created to a domain.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4707" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4707"&gt;4707&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4707" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4707"&gt;A trust to a domain was removed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4713" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4713"&gt;4713&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4713" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4713"&gt;Kerberos policy was changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4716" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4716"&gt;4716&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4716" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4716"&gt;Trusted domain information was modified.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4717" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4717"&gt;4717&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4717" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4717"&gt;System security access was granted to an account.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4718" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4718"&gt;4718&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4718" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4718"&gt;System security access was removed from an account.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4865" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4865"&gt;4865&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4865" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4865"&gt;A trusted forest information entry was added.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4866" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4866"&gt;4866&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4866" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4866"&gt;A trusted forest information entry was removed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4867" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4867"&gt;4867&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4867" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4867"&gt;A trusted forest information entry was modified.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 17:16:14 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>Audit Policy Change</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50601.aspx</link><description>&lt;font size="1"&gt;&lt;font color="#000000"&gt;This category tracks any policy changes that would affect what gets reported to the security log. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy&lt;/font&gt;&lt;/font&gt;&lt;font size="1"&gt;&lt;font color="#000000"&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-FAMILY: Verdana; COLOR: rgb(51,51,51); FONT-SIZE: 11px"&gt;Coverage on events generated by this category are currently in the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=5&amp;amp;subcatid=35"&gt;Security Log Encyclopedia&lt;/a&gt;:&lt;/span&gt;&lt;/font&gt;&lt;br /&gt;&lt;/font&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Event ID&lt;/th&gt;&lt;th&gt;Title&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4715" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4715"&gt;4715&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4715" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4715"&gt;The audit policy (SACL) on an object was changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4719" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4719"&gt;4719&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4719" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4719"&gt;System audit policy was changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4902" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4902"&gt;4902&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4902" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4902"&gt;The Per-user audit policy table was created.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4904" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4904"&gt;4904&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4904" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4904"&gt;An attempt was made to register a security event source.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4905" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4905"&gt;4905&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4905" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4905"&gt;An attempt was made to unregister a security event source.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4906" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4906"&gt;4906&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4906" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4906"&gt;The CrashOnAuditFail value has changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4907" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4907"&gt;4907&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4907" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4907"&gt;Auditing settings on object were changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4912" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4912"&gt;4912&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a title="Windows Security Log Event ID 4912" class="pagelink" href="/securitylog/encyclopedia/event.aspx?eventid=4912"&gt;Per User Audit Policy was changed.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description><pubDate>Tue, 28 Aug 2012 17:11:41 GMT</pubDate><dc:creator>whsmith</dc:creator></item><item><title>OVERVIEW: Audit Policy Change</title><link>http://www.ultimatewindowssecurity.com/wiki/Goto50028.aspx</link><description>&lt;span style="COLOR: rgb(0,0,0)"&gt; &lt;font size="1"&gt;The Audit policy change policy provides notification of changes to important security policies on the local system, such as changes to the system’s audit policy or, when the local system is a DC, changes to trust relationships. &lt;br /&gt;&lt;br /&gt;The following is an exerpt from my book, &lt;/font&gt;&lt;a href="/securitylog/resourcekits/Default.aspx"&gt;&lt;font color="#1f5080" size="1"&gt;The Windows Server Security Log Revealed &lt;/font&gt;&lt;/a&gt;&lt;font size="2"&gt;&lt;font size="1"&gt;: &lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;span&gt;&lt;font class="Quote"&gt;The Policy Change category provides notification of changes to important security policies on the local system, such as to the system’s audit policy or, in the case of DCs, to trust relationships. &lt;br /&gt;&lt;/font&gt;&lt;span style="COLOR: rgb(0,0,0)"&gt;&lt;br /&gt;&lt;font size="1"&gt;&lt;br /&gt;For a list of Event IDs generated by this category, see the &lt;a href="/securitylog/encyclopedia/Default.aspx?catid=5"&gt;Security Log Encyclopedia&lt;/a&gt;. &lt;br /&gt;&lt;/font&gt;&lt;br /&gt;&lt;h2&gt;Bottom Line &lt;/h2&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="COLOR: rgb(0,0,0)"&gt;&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="COLOR: rgb(0,0,0)"&gt;&lt;font size="1"&gt;Windows XP, 2000 and 2003: I recommend enabling this policy for success on all computers including workstations. We have not observed any failure events in this category. &lt;/font&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="COLOR: rgb(0,0,0)"&gt;&lt;font size="1"&gt;Windows Server 2008 and Vista: I don't recommend managing audit policy at this level because too much noise is generated. Use subcategories instead. &lt;span&gt;&lt;span&gt;&lt;a href="/wiki/WindowsSecuritySettings/66" target="_blank"&gt;See Audit Category: Policy Change &lt;/a&gt;&lt;/span&gt;&lt;/span&gt;(Windows Server 2008 and Vista). &lt;/font&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;</description><pubDate>Thu, 02 Apr 2009 18:24:59 GMT</pubDate><dc:creator>instantasp@gmail.com</dc:creator></item></channel></rss>