Event Id | 4912 |
Source | Microsoft-Windows-Security-Auditing |
Description | Per User Audit Policy was changed. Subject: Security ID: <Security ID> Account Name: <Account Name> Account Domain: <Domain Name> Logon ID: <Logon ID> Policy For Account: Security ID:<Security ID> Policy Change Details: Category: <Category> Subcategory: <Subcategory> Subcategory GUID: <Subcategory GUID> Changes: <Changes> |
Event Information | Cause : This event is logged when the user set audit policy as well as the category, subcategory and the nature of the change in terms of success/failure and include/exclude. |
Reference Links |
Catch threats immediately
We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.