Event ID: 4608

Windows is starting up

Windows is starting up.

This event is logged when LSASS.EXE starts and the auditing subsystem is initialized.


This event is logged when LSASS.EXE process starts and the auditing subsystem is initialized.

It typically generates during operating system startup process.

PCI 3.2.1: 10.2.6


Microsoft Documentation

Event ID - 4608



Lookup Audit Policy Configuration Settings

C:\> AuditPol.exe /get /subcategory:"Security State Change"



LEFT/RIGHT arrow keys for navigation

Back to List