Event ID 4912
Per User Audit Policy was changed
Per User Audit Policy was changed.
Subject:
Security ID: %1
Account Name: %2
Account Domain: %3
Logon ID: %4
Policy For Account:
Security ID: %5
Policy Change Details:
Category: %6
Subcategory: %7
Subcategory GUID: %8
Changes: %9
Auditing:
Always
This event is always logged regardless of the "Audit Policy Change" sub-category setting.
Name |
Field |
Insertion String |
OS |
Example |
|
|
Security ID |
SubjectUserSid |
%1 |
Any |
DOMAIN\TheAdmin
|
|
Account Name |
SubjectUserName |
%2 |
Any |
TheAdmin
|
|
Account Domain |
SubjectDomainName |
%3 |
Any |
DOMAIN
|
|
Logon ID |
SubjectLogonId |
%4 |
Any |
0x11ae30
|
|
Security ID |
TargetUserSid |
%5 |
Any |
DOMAIN\SomeUser
|
|
Category |
CategoryId |
%6 |
Any |
Detailed Tracking
|
|
Subcategory |
SubcategoryId |
%7 |
Any |
Audit DPAPI Activity
|
|
Subcategory GUID |
SubcategoryGuid |
%8 |
Any |
{0CCE922D-69AE-11D9-BED3-505054503030}
|
|
Changes |
AuditPolicyChanges |
%9 |
Any |
Success include added
|
The account that made a change to per-user audit policy.
The name of the account that made a change to per-user audit policy.
The account for which the Per User Audit Policy was changed.
The name of auditing category for which the subcategory state was changed.
The name of auditing subcategory that changed state.
The unique GUID of changed subcategory. To see subcategory GUIDs you can use the following command: “auditpol /list /subcategory:* /v”
Changes which were made for the subcategory. Possible values are:
Success include removed
Success include added
Failure include removed
Failure include added
Success exclude removed
Success exclude added
Failure exclude removed
Failure exclude added
Lookup Audit Policy Configuration Settings
C:\> AuditPol.exe /get /subcategory:"Audit Policy Change"
LEFT/RIGHT arrow keys for navigation
Back to List