Event ID - 4907

Event Id4907
SourceMicrosoft-Windows-Security-Auditing
DescriptionAuditing settings on object were changed.

Subject:
      Security ID:<Security ID>
      Account Name: <Account Name>
      Account Domain:<Domain Name>
      Logon ID:<Logon ID>     

Object:
      Object Server: <Object Server>
      Object Type: <Object Type>
      Object Name: <Object Name>
      Handle ID: <Handle ID>     

Process Information:
      Process ID: <Process ID>
      Process Name: <Process Name>     

Auditing Settings:
      Original Security Descriptor:
New Security Descriptor: S:ARAI(AU;OIIOSAFA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)

Event InformationCause :
When user change the audit SACL of an object, such as a file or folder, Windows logs this event.
Reference Links

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.