Windows Security Log Event ID 4817

Operating Systems Windows 2008 R2 and 7
Windows 2012 R2 and 8.1
Windows 2016 and 10
Windows Server 2019 and 2022
Category
 • Subcategory
Policy Change
 • Audit Policy Change
Type Success
Corresponding events
in Windows 2003
and before
 

4817: Auditing settings on object were changed.

On this page

Auditing settings on object were changed.

This event is new to Windows 2008 Release 2 and Windows 7. It does not appear in earlier versions of Windows.

We have not been able to produce this event.

This event has the same title as Event 4907 although the fields are somewhat different.

Free Security Log Resources by Randy

Description Fields in 4817

Subject:
 Security ID:  %1
 Account Name:  %2
 Account Domain:  %3
 Logon ID:  %4

Object:
 Object Server: %5
 Object Type: %6
 Object Name: %7

Auditing Settings:
 Original Security Descriptor: %8
 New Security Descriptor:  %9

Setup PowerShell Audit Log Forwarding in 4 Minutes

 

 

Upcoming Webinars
    Additional Resources