Event ID - 4912

Event Id4912
SourceMicrosoft-Windows-Security-Auditing
DescriptionPer User Audit Policy was changed.

Subject:
      Security ID: <Security ID>
      Account Name: <Account Name>
      Account Domain: <Domain Name>
      Logon ID: <Logon ID>     

Policy For Account:
      Security ID:<Security ID>     

Policy Change Details:
      Category: <Category>
      Subcategory: <Subcategory>
      Subcategory GUID: <Subcategory GUID>
      Changes: <Changes>     

Event InformationCause :
This event is logged when the user set audit policy as well as the category, subcategory and the nature of the change in terms of success/failure and include/exclude.
Reference Links

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.