Event ID 5466
PAStore Engine polled for changes to the Active Directory IPsec policyPAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory cannot be reached, and will use the cached copy of the Active Directory IPsec policy instead. Any changes made to the Active Directory IPsec policy since the last poll could not be applied.
Event 5466 is logged when the PAStore Engine's scheduled AD poll fails to reach Active Directory and the engine falls back to continuing enforcement using the locally cached copy of the AD IPsec policy.
Like all events in the 5463–5468 polling group, this event carries no insertion strings. The message is fully static.
Enable in environments where AD-assigned IPsec policies are security-critical.
On a well-connected, domain-joined machine in the office this event should be rare — appearing only during transient DC outages or brief network disruptions. On machines that frequently lose AD connectivity (remote workers, laptops, branch offices with unreliable WAN links) this event may appear at every polling interval (every 90–180 minutes) for the duration of the disconnection, which can accumulate to Medium volume during extended outages.
Lookup Audit Policy Configuration Settings
C:\> AuditPol.exe /get /subcategory:"Filtering Platform Policy Change" LEFT/RIGHT arrow keys for navigation
Back to List