Event ID 4944

The following policy was active when the Windows Firewall started

The following policy was active when the Windows Firewall started.

Group Policy Applied:                                   %1
Profile Used:                                           %2
Operational mode:                                       %3
Allow Remote Administration:                            %4
Allow Unicast Responses to Multicast/Broadcast Traffic: %5
Security Logging:
    Log Dropped Packets:        %6
    Log Successful Connections: %7


This event generates every time Windows Firewall service starts.

This event shows Windows Firewall settings that were in effect when the Windows Firewall service started.

Auditing:     Always


Volume:     Low


Microsoft Documentation

Event ID - 4944



NameFieldInsertion StringOSExample
Group Policy AppliedGroupPolicyApplied%1Any No
Profile UsedProfile%2Any Public
Operational modeOperationMode%3Any Off
Allow Remote AdministrationRemoteAdminEnabled%4Any Disabled
Allow Unicast Responses to Multicast/Broadcast TrafficMulticastFlowsEnabled%5Any Enabled
Log Dropped PacketsLogDroppedPacketsEnabled%6Any Disabled
Log Successful ConnectionsLogSuccessfulConnectionsEnabled%7Any Disabled


Lookup Audit Policy Configuration Settings

C:\> AuditPol.exe /get /subcategory:"MPSSVC Rule-Level Policy Change"



LEFT/RIGHT arrow keys for navigation

Back to List