#pki-security
10 articles
Windows Events10
Windows Event ID 4897 – Microsoft-Windows-Security-Auditing: Certificate Services Template Security Descriptor Changed
Event ID 4897 fires when security permissions on a Certificate Authority template are modified, indicating changes to who can request, manage, or enroll certificates from that template.
Windows Event ID 4881 – Security: Certificate Services Template Security Permissions Changed
Event ID 4881 logs when security permissions on a Certificate Authority template are modified, indicating changes to who can request or manage specific certificate types in your PKI infrastructure.
Windows Event ID 4880 – Security: Certificate Services Template Security Permissions Changed
Event ID 4880 logs when security permissions on a Certificate Authority template are modified, indicating changes to who can request or manage specific certificate types in your PKI infrastructure.
Windows Event ID 4877 – Security-Auditing: Certificate Services Template Security Permissions Changed
Event ID 4877 fires when security permissions on a Certificate Authority template are modified. Critical for PKI security monitoring and compliance auditing in enterprise environments.
Windows Event ID 4872 – Microsoft-Windows-Security-Auditing: Certificate Services Template Security Permissions Changed
Event ID 4872 fires when security permissions on a Certificate Authority template are modified. This audit event tracks changes to certificate template access control lists and helps monitor PKI security modifications.
Windows Event ID 4868 – Security: Certificate Services Denied Request
Event ID 4868 fires when Active Directory Certificate Services denies a certificate request due to policy violations, insufficient permissions, or template restrictions.
Windows Event ID 4867 – Security-Auditing: Certificate Services Template Security Descriptor Modified
Event ID 4867 fires when security permissions on a certificate template are modified in Active Directory Certificate Services, indicating changes to who can request or manage certificates.
Windows Event ID 4886 – Microsoft-Windows-Security-Auditing: Certificate Services Template Security Descriptor Modified
Event ID 4886 fires when security permissions on a Certificate Authority template are modified. Critical for PKI security monitoring and compliance auditing in Active Directory environments.
Windows Event ID 4885 – Security: Certificate Services Template Security Permissions Changed
Event ID 4885 fires when security permissions on a Certificate Authority template are modified, indicating changes to who can request or manage specific certificate types.
Windows Event ID 4882 – Security: Certificate Services Received a Certificate Request
Event ID 4882 logs when Active Directory Certificate Services receives a certificate request. This security audit event tracks certificate enrollment activity and helps monitor PKI operations in Windows environments.