ANAVEM
Languagefr

#audit-policy

5 articles

Windows Events5

Windows security monitoring dashboard displaying audit policy events and security logs
Event 4714
Microsoft-Windows-Security-Auditing
Windows EventInformation

Windows Event ID 4714 – Microsoft-Windows-Security-Auditing: System Security Access Control List Was Changed

Event ID 4714 fires when the System Access Control List (SACL) is modified on a Windows system, indicating changes to audit policies or security monitoring configurations.

March 1812 min
Windows security monitoring dashboard showing Event Viewer Security logs and audit policy management interface
Event 4692
Microsoft-Windows-Security-Auditing
Windows EventInformation

Windows Event ID 4692 – Microsoft-Windows-Security-Auditing: An attempt was made to backup the security audit policy

Event ID 4692 fires when Windows attempts to backup the security audit policy configuration. This security audit event tracks policy backup operations for compliance and forensic purposes.

March 1812 min
Windows Security Event Viewer displaying audit policy events on a professional monitoring dashboard
Event 4964
Microsoft-Windows-Security-Auditing
Windows EventInformation

Windows Event ID 4964 – Microsoft-Windows-Security-Auditing: Object Access Audit Policy Changed

Event ID 4964 logs when object access audit policy settings are modified on Windows systems, indicating changes to file, folder, or registry auditing configuration.

March 189 min
Windows Security Event Viewer displaying audit policy change events on a cybersecurity monitoring dashboard
Event 4719
Microsoft-Windows-Security-Auditing
Windows EventInformation

Windows Event ID 4719 – Microsoft-Windows-Security-Auditing: System Audit Policy Changed

Event ID 4719 fires when Windows audit policy settings are modified, indicating changes to security auditing configuration that affect what events get logged.

March 189 min
Windows security monitoring dashboard showing Event Viewer with audit policy configuration logs
Event 4612
Microsoft-Windows-Security-Auditing
Windows EventInformation

Windows Event ID 4612 – LSA: Security Audit Policy Changes

Event ID 4612 fires when Local Security Authority (LSA) audit policy settings are modified, indicating changes to Windows security auditing configuration that affect what events get logged.

March 189 min