Windows Event ID 4881 is generated by the Microsoft-Windows-Security-Auditing provider when security permissions on Certificate Authority certificate templates are modified. This event occurs exclusively on servers running Active Directory Certificate Services (AD CS) and provides comprehensive auditing of certificate template access control changes.
The event captures critical PKI security information including the certificate template name, the security principal (user, group, or computer) whose permissions were modified, the specific access rights that changed, and whether permissions were added, removed, or modified. This granular detail enables administrators to track exactly who can request certificates from each template and identify unauthorized permission changes.
Certificate templates define the properties and permissions for certificate enrollment, making their security settings crucial for PKI integrity. Event 4881 helps maintain the principle of least privilege by providing visibility into template permission modifications. The event includes both the previous and new access control entries, allowing administrators to understand the full scope of changes made to template security.
This event is particularly valuable for compliance auditing, security incident response, and maintaining proper segregation of duties within certificate management operations. Organizations with strict PKI governance requirements rely on Event 4881 to ensure certificate template permissions align with security policies and detect potential insider threats or compromised administrative accounts.