Windows Security Log Event ID 618
Operating Systems |
Windows Server 2000
Windows 2003 and XP
|
Category | Policy Change |
Type
|
Success
|
Corresponding events
in Windows
2008 and Vista |
4714
|
618: Encrypted Data Recovery Policy Changed
On this page
This event gets logged when EFS data recovery agent information is changed. User name will usually correspond to the local computer's name because EFS is controlled through group policy. To find out who changed EFS policy you must determine who changed the relevant group policy object.
The encrypted data recovery agent policy is defined in group policy objects under Computer Configuratoin\Windows Settings\Securirty Settings\Public Key Policies\Encrypted File System.
Free Security Log Resources by Randy
- Encrypted Data Recovery Policy Changed:
- Changed By:
- User Name: %1
- Domain Name: %2
- Logon ID: %3
- Changes made:('--' means no changes, otherwise each change is shown as: <ParameterName>: <new value> (<old value>)) %4
Setup PowerShell Audit Log Forwarding in 4 Minutes