Event ID - 4715

Event Id4715
SourceMicrosoft-Windows-Security-Auditing
DescriptionThe audit policy (SACL) on an object was changed.

Subject:
      Security ID: <Security ID>
      Account Name: <Account Name>
      Account Domain:<Domain name>
      Logon ID: <Logon ID>     

Audit Policy Change:
      Original Security Descriptor: <Original Security Descriptor>
      New Security Descriptor: <New Security Descriptor>     

Event InformationCause :
This event is logged whenever user set the security descriptor used to delegate access to the audit policy.
Reference Links

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.