Windows Security Log Event ID 807

Operating Systems Windows 2003 and XP
CategoryPolicy Change
Type Success
Corresponding events
in Windows 2008
and Vista

807: Per user auditing policy set for user

On this page

Not confirmed. See event 806 for more information on per user selective auditing.

See Roger Grimes article at for an excellent introduction to per user selective auditing

Free Security Log Resources by Randy

Description Fields in 807

  • Target user: %1
  • Policy ID: %2
  • Category Settings:
  • System: %3
  • Logon: %4
  • Object Access %5
  • Privilege Use: %6
  • Detailed Tracking: %7
  • Policy Change: %8
  • Account Management: %9
  • DS Access: %10
  • Account Logon: %11

Setup PowerShell Audit Log Forwarding in 4 Minutes


Examples of 807

Per user auditing policy set for user:
Target user:%1
Policy ID:%2
Category Settings:
Object Access%5
Privilege Use:%6
Detailed Tracking:%7
Policy Change:%8
Account Management:%9
DS Access:%10
Account Logon:%11

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection


Additional Resources