Audit Policy Change

Expand / Collapse
 
     

Audit Policy Change


This category tracks any policy changes that would affect what gets reported to the security log. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.

Coverage on events generated by this category are currently in the Security Log Encyclopedia:


Event IDTitle
4715 The audit policy (SACL) on an object was changed.
4719 System audit policy was changed.
4902 The Per-user audit policy table was created.
4904 An attempt was made to register a security event source.
4905 An attempt was made to unregister a security event source.
4906 The CrashOnAuditFail value has changed.
4907 Auditing settings on object were changed.
4912 Per User Audit Policy was changed.

Add Your Comments


Name: *
Email Address:
Web Address:
Verification Code:
*
 

Details
Applies To: Vista, Windows Server 2008, Windows Server 2008 R2, Windows 8, Windows Server 2012
Rated 5 stars based on 1 vote.
Article has been viewed 4,318 times.
Options