Windows Security Log Event ID 857

Operating Systems Windows 2003 and XP
CategoryPolicy Change
Type Success
Corresponding events
in Windows 2008
and Vista
 

857: The Windows Firewall setting to allow remote administration, allowing port TCP 135 and DCOM/RPC, has changed

On this page

Windows logs this event when an administrator changes the local policy of the Windows Firewall or a group policy refresh results in setting the Windows Firewall setting to allow or disable remote administration.

Free Security Log Resources by Randy

Description Fields in 857

  • Policy origin: Group Policy or Local Policy
  • Profile changed: Standard or Domain

New Settings:

  • Allow remote administration: Enabled or Disabled

Old Settings:

  • Allow remote administration: Enabled or Disabled

 

Supercharger Free Edition


Centrally manage WEC subscriptions.

Free.

 

Examples of 857

The Windows Firewall setting to allow remote administration, allowing port TCP 135 and DCOM/RPC, has changed.
 
Policy origin: Group Policy
Profile changed: Standard
New Setting:
     Allow remote administration: Enabled
Old Setting:
     Allow remote administration: Disabled

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection

 

Additional Resources

    Go To Event ID:

    Security Log
    Quick Reference
    Chart
    Download now!