WinSecWiki > Security Settings > Local Policies > Audit Policy > Policy Change > Authorization

Authorization Policy Change

I've only isolated a few events logged by this category. Let me know via a discussion post on this event if you know of more. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.

Coverage on events generated by this category are currently in the Security Log Encyclopedia:

Event IDTitle
4704 A user right was assigned.
4705 A user right was removed.
4714 Encrypted data recovery policy was changed.

Back to top

 

Additional Resources