Event Id | 4715 |
Source | Microsoft-Windows-Security-Auditing |
Description | The audit policy (SACL) on an object was changed. Subject: Security ID: <Security ID> Account Name: <Account Name> Account Domain:<Domain name> Logon ID: <Logon ID> Audit Policy Change: Original Security Descriptor: <Original Security Descriptor> New Security Descriptor: <New Security Descriptor> |
Event Information | Cause : This event is logged whenever user set the security descriptor used to delegate access to the audit policy. |
Reference Links |
Catch threats immediately
We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.