mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-14 14:27:22 +00:00
meta security 6
This commit is contained in:
parent
0314e27692
commit
4db3713dbb
@ -6,13 +6,13 @@ ms.reviewer:
|
|||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
author: vinaypamnani-msft
|
author: vinaypamnani-msft
|
||||||
ms.date: 09/06/2021
|
ms.date: 09/06/2021
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# Audit Removable Storage
|
# Audit Removable Storage
|
||||||
|
@ -6,13 +6,13 @@ ms.reviewer:
|
|||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
author: vinaypamnani-msft
|
author: vinaypamnani-msft
|
||||||
ms.date: 09/06/2021
|
ms.date: 09/06/2021
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# Audit RPC Events
|
# Audit RPC Events
|
||||||
|
@ -6,13 +6,13 @@ ms.reviewer:
|
|||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
author: vinaypamnani-msft
|
author: vinaypamnani-msft
|
||||||
ms.date: 09/06/2021
|
ms.date: 09/06/2021
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# Audit SAM
|
# Audit SAM
|
||||||
|
@ -6,13 +6,13 @@ ms.reviewer:
|
|||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
author: vinaypamnani-msft
|
author: vinaypamnani-msft
|
||||||
ms.date: 09/06/2021
|
ms.date: 09/06/2021
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# Audit Security Group Management
|
# Audit Security Group Management
|
||||||
|
@ -6,13 +6,13 @@ ms.reviewer:
|
|||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
author: vinaypamnani-msft
|
author: vinaypamnani-msft
|
||||||
ms.date: 09/06/2021
|
ms.date: 09/06/2021
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# Audit Security State Change
|
# Audit Security State Change
|
||||||
|
@ -6,13 +6,13 @@ ms.reviewer:
|
|||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
author: vinaypamnani-msft
|
author: vinaypamnani-msft
|
||||||
ms.date: 09/06/2021
|
ms.date: 09/06/2021
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# Audit Security System Extension
|
# Audit Security System Extension
|
||||||
|
@ -6,13 +6,13 @@ ms.reviewer:
|
|||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
author: vinaypamnani-msft
|
author: vinaypamnani-msft
|
||||||
ms.date: 09/06/2021
|
ms.date: 09/06/2021
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# Audit Sensitive Privilege Use
|
# Audit Sensitive Privilege Use
|
||||||
|
@ -6,13 +6,13 @@ ms.reviewer:
|
|||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
author: vinaypamnani-msft
|
author: vinaypamnani-msft
|
||||||
ms.date: 09/06/2021
|
ms.date: 09/06/2021
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# Audit Special Logon
|
# Audit Special Logon
|
||||||
|
@ -6,13 +6,13 @@ ms.reviewer:
|
|||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
author: vinaypamnani-msft
|
author: vinaypamnani-msft
|
||||||
ms.date: 09/06/2021
|
ms.date: 09/06/2021
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# Audit System Integrity
|
# Audit System Integrity
|
||||||
|
@ -5,8 +5,8 @@ manager: aaroncz
|
|||||||
author: vinaypamnani-msft
|
author: vinaypamnani-msft
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# Audit Token Right Adjusted
|
# Audit Token Right Adjusted
|
||||||
|
@ -6,13 +6,13 @@ ms.reviewer:
|
|||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
author: vinaypamnani-msft
|
author: vinaypamnani-msft
|
||||||
ms.date: 09/06/2021
|
ms.date: 09/06/2021
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# Audit User Account Management
|
# Audit User Account Management
|
||||||
|
@ -6,13 +6,13 @@ ms.reviewer:
|
|||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
author: vinaypamnani-msft
|
author: vinaypamnani-msft
|
||||||
ms.date: 09/06/2021
|
ms.date: 09/06/2021
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# Audit User/Device Claims
|
# Audit User/Device Claims
|
||||||
|
@ -4,7 +4,7 @@ description: Determines whether to audit each instance of a user logging on to o
|
|||||||
ms.assetid: 84B44181-E325-49A1-8398-AECC3CE0A516
|
ms.assetid: 84B44181-E325-49A1-8398-AECC3CE0A516
|
||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
@ -15,7 +15,7 @@ audience: ITPro
|
|||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: conceptual
|
ms.topic: conceptual
|
||||||
ms.date: 09/06/2021
|
ms.date: 09/06/2021
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# Audit account logon events
|
# Audit account logon events
|
||||||
|
@ -4,7 +4,7 @@ description: Determines whether to audit each event of account management on a d
|
|||||||
ms.assetid: 369197E1-7E0E-45A4-89EA-16D91EF01689
|
ms.assetid: 369197E1-7E0E-45A4-89EA-16D91EF01689
|
||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
@ -15,7 +15,7 @@ audience: ITPro
|
|||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: conceptual
|
ms.topic: conceptual
|
||||||
ms.date: 09/06/2021
|
ms.date: 09/06/2021
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# Audit account management
|
# Audit account management
|
||||||
|
@ -4,7 +4,7 @@ description: Determines whether to audit the event of a user accessing an Active
|
|||||||
ms.assetid: 52F02EED-3CFE-4307-8D06-CF1E27693D09
|
ms.assetid: 52F02EED-3CFE-4307-8D06-CF1E27693D09
|
||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
@ -15,7 +15,7 @@ audience: ITPro
|
|||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: conceptual
|
ms.topic: conceptual
|
||||||
ms.date: 09/06/2021
|
ms.date: 09/06/2021
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# Audit directory service access
|
# Audit directory service access
|
||||||
|
@ -4,7 +4,7 @@ description: Determines whether to audit each instance of a user logging on to o
|
|||||||
ms.assetid: 78B5AFCB-0BBD-4C38-9FE9-6B4571B94A35
|
ms.assetid: 78B5AFCB-0BBD-4C38-9FE9-6B4571B94A35
|
||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
@ -15,7 +15,7 @@ audience: ITPro
|
|||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: conceptual
|
ms.topic: conceptual
|
||||||
ms.date: 09/06/2021
|
ms.date: 09/06/2021
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# Audit logon events
|
# Audit logon events
|
||||||
|
@ -4,7 +4,7 @@ description: The policy setting, Audit object access, determines whether to audi
|
|||||||
ms.assetid: D15B6D67-7886-44C2-9972-3F192D5407EA
|
ms.assetid: D15B6D67-7886-44C2-9972-3F192D5407EA
|
||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
@ -15,7 +15,7 @@ audience: ITPro
|
|||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: conceptual
|
ms.topic: conceptual
|
||||||
ms.date: 09/06/2021
|
ms.date: 09/06/2021
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# Audit object access
|
# Audit object access
|
||||||
|
@ -4,7 +4,7 @@ description: Determines whether to audit every incident of a change to user righ
|
|||||||
ms.assetid: 1025A648-6B22-4C85-9F47-FE0897F1FA31
|
ms.assetid: 1025A648-6B22-4C85-9F47-FE0897F1FA31
|
||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
@ -15,7 +15,7 @@ audience: ITPro
|
|||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: conceptual
|
ms.topic: conceptual
|
||||||
ms.date: 09/06/2021
|
ms.date: 09/06/2021
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# Audit policy change
|
# Audit policy change
|
||||||
|
@ -4,7 +4,7 @@ description: Determines whether to audit each instance of a user exercising a us
|
|||||||
ms.assetid: C5C6DAAF-8B58-4DFB-B1CE-F0675AE0E9F8
|
ms.assetid: C5C6DAAF-8B58-4DFB-B1CE-F0675AE0E9F8
|
||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
@ -15,7 +15,7 @@ audience: ITPro
|
|||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: conceptual
|
ms.topic: conceptual
|
||||||
ms.date: 09/06/2021
|
ms.date: 09/06/2021
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# Audit privilege use
|
# Audit privilege use
|
||||||
|
@ -4,7 +4,7 @@ description: Determines whether to audit detailed tracking information for event
|
|||||||
ms.assetid: 91AC5C1E-F4DA-4B16-BEE2-C92D66E4CEEA
|
ms.assetid: 91AC5C1E-F4DA-4B16-BEE2-C92D66E4CEEA
|
||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
@ -15,7 +15,7 @@ audience: ITPro
|
|||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: conceptual
|
ms.topic: conceptual
|
||||||
ms.date: 09/06/2021
|
ms.date: 09/06/2021
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# Audit process tracking
|
# Audit process tracking
|
||||||
|
@ -4,7 +4,7 @@ description: Determines whether to audit when a user restarts or shuts down the
|
|||||||
ms.assetid: BF27588C-2AA7-4365-A4BF-3BB377916447
|
ms.assetid: BF27588C-2AA7-4365-A4BF-3BB377916447
|
||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
@ -15,7 +15,7 @@ audience: ITPro
|
|||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: conceptual
|
ms.topic: conceptual
|
||||||
ms.date: 09/06/2021
|
ms.date: 09/06/2021
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# Audit system events
|
# Audit system events
|
||||||
|
@ -4,7 +4,7 @@ description: Learn about basic security audit policies that specify the categori
|
|||||||
ms.assetid: 3B678568-7AD7-4734-9BB4-53CF5E04E1D3
|
ms.assetid: 3B678568-7AD7-4734-9BB4-53CF5E04E1D3
|
||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
@ -15,7 +15,7 @@ audience: ITPro
|
|||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: conceptual
|
ms.topic: conceptual
|
||||||
ms.date: 09/06/2021
|
ms.date: 09/06/2021
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# Basic security audit policies
|
# Basic security audit policies
|
||||||
|
@ -4,7 +4,7 @@ description: Basic security audit policy settings are found under Computer Confi
|
|||||||
ms.assetid: 31C2C453-2CFC-4D9E-BC88-8CE1C1A8F900
|
ms.assetid: 31C2C453-2CFC-4D9E-BC88-8CE1C1A8F900
|
||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
@ -15,7 +15,7 @@ audience: ITPro
|
|||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: conceptual
|
ms.topic: conceptual
|
||||||
ms.date: 09/06/2021
|
ms.date: 09/06/2021
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# Basic security audit policy settings
|
# Basic security audit policy settings
|
||||||
|
@ -4,7 +4,7 @@ description: By defining auditing settings for specific event categories, you ca
|
|||||||
ms.assetid: C9F52751-B40D-482E-BE9D-2C61098249D3
|
ms.assetid: C9F52751-B40D-482E-BE9D-2C61098249D3
|
||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
@ -15,7 +15,7 @@ audience: ITPro
|
|||||||
ms.collection: M365-security-compliance
|
ms.collection: M365-security-compliance
|
||||||
ms.topic: conceptual
|
ms.topic: conceptual
|
||||||
ms.date: 09/07/2021
|
ms.date: 09/07/2021
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# Create a basic audit policy for an event category
|
# Create a basic audit policy for an event category
|
||||||
|
@ -2,7 +2,7 @@
|
|||||||
title: 1100(S) The event logging service has shut down. (Windows 10)
|
title: 1100(S) The event logging service has shut down. (Windows 10)
|
||||||
description: Describes security event 1100(S) The event logging service has shut down.
|
description: Describes security event 1100(S) The event logging service has shut down.
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
|||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# 1100(S): The event logging service has shut down.
|
# 1100(S): The event logging service has shut down.
|
||||||
|
@ -2,7 +2,7 @@
|
|||||||
title: 1102(S) The audit log was cleared. (Windows 10)
|
title: 1102(S) The audit log was cleared. (Windows 10)
|
||||||
description: Though you shouldn't normally see it, this event generates every time Windows Security audit log is cleared. This is for event 1102(S).
|
description: Though you shouldn't normally see it, this event generates every time Windows Security audit log is cleared. This is for event 1102(S).
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
|||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# 1102(S): The audit log was cleared.
|
# 1102(S): The audit log was cleared.
|
||||||
|
@ -2,7 +2,7 @@
|
|||||||
title: 1104(S) The security log is now full. (Windows 10)
|
title: 1104(S) The security log is now full. (Windows 10)
|
||||||
description: This event generates every time Windows security log becomes full and the event log retention method is set to Do not overwrite events.
|
description: This event generates every time Windows security log becomes full and the event log retention method is set to Do not overwrite events.
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
|||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# 1104(S): The security log is now full.
|
# 1104(S): The security log is now full.
|
||||||
|
@ -2,7 +2,7 @@
|
|||||||
title: 1105(S) Event log automatic backup. (Windows 10)
|
title: 1105(S) Event log automatic backup. (Windows 10)
|
||||||
description: This event generates every time Windows security log becomes full and new event log file was created.
|
description: This event generates every time Windows security log becomes full and new event log file was created.
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
|||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# 1105(S): Event log automatic backup
|
# 1105(S): Event log automatic backup
|
||||||
|
@ -2,7 +2,7 @@
|
|||||||
title: The event logging service encountered an error (Windows 10)
|
title: The event logging service encountered an error (Windows 10)
|
||||||
description: Describes security event 1108(S) The event logging service encountered an error while processing an incoming event published from %1.
|
description: Describes security event 1108(S) The event logging service encountered an error while processing an incoming event published from %1.
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
|||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# 1108(S): The event logging service encountered an error while processing an incoming event published from %1.
|
# 1108(S): The event logging service encountered an error while processing an incoming event published from %1.
|
||||||
|
@ -2,7 +2,7 @@
|
|||||||
title: 4608(S) Windows is starting up. (Windows 10)
|
title: 4608(S) Windows is starting up. (Windows 10)
|
||||||
description: Describes security event 4608(S) Windows is starting up. This event is logged when the LSASS.EXE process starts and the auditing subsystem is initialized.
|
description: Describes security event 4608(S) Windows is starting up. This event is logged when the LSASS.EXE process starts and the auditing subsystem is initialized.
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
|||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# 4608(S): Windows is starting up.
|
# 4608(S): Windows is starting up.
|
||||||
|
@ -2,7 +2,7 @@
|
|||||||
title: 4610(S) An authentication package has been loaded by the Local Security Authority. (Windows 10)
|
title: 4610(S) An authentication package has been loaded by the Local Security Authority. (Windows 10)
|
||||||
description: Describes security event 4610(S) An authentication package has been loaded by the Local Security Authority.
|
description: Describes security event 4610(S) An authentication package has been loaded by the Local Security Authority.
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
|||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# 4610(S): An authentication package has been loaded by the Local Security Authority.
|
# 4610(S): An authentication package has been loaded by the Local Security Authority.
|
||||||
|
@ -2,7 +2,7 @@
|
|||||||
title: 4611(S) A trusted logon process has been registered with the Local Security Authority. (Windows 10)
|
title: 4611(S) A trusted logon process has been registered with the Local Security Authority. (Windows 10)
|
||||||
description: Describes security event 4611(S) A trusted logon process has been registered with the Local Security Authority.
|
description: Describes security event 4611(S) A trusted logon process has been registered with the Local Security Authority.
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
|||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# 4611(S): A trusted logon process has been registered with the Local Security Authority.
|
# 4611(S): A trusted logon process has been registered with the Local Security Authority.
|
||||||
|
@ -2,7 +2,7 @@
|
|||||||
title: 4612(S) Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits. (Windows 10)
|
title: 4612(S) Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits. (Windows 10)
|
||||||
description: Describes security event 4612(S) Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits.
|
description: Describes security event 4612(S) Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits.
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
|||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# 4612(S): Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits.
|
# 4612(S): Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits.
|
||||||
|
@ -2,7 +2,7 @@
|
|||||||
title: 4614(S) A notification package has been loaded by the Security Account Manager. (Windows 10)
|
title: 4614(S) A notification package has been loaded by the Security Account Manager. (Windows 10)
|
||||||
description: Describes security event 4614(S) A notification package has been loaded by the Security Account Manager.
|
description: Describes security event 4614(S) A notification package has been loaded by the Security Account Manager.
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
|||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# 4614(S): A notification package has been loaded by the Security Account Manager.
|
# 4614(S): A notification package has been loaded by the Security Account Manager.
|
||||||
|
@ -2,7 +2,7 @@
|
|||||||
title: 4615(S) Invalid use of LPC port. (Windows 10)
|
title: 4615(S) Invalid use of LPC port. (Windows 10)
|
||||||
description: Describes security event 4615(S) Invalid use of LPC port. It appears that the Invalid use of LPC port event never occurs.
|
description: Describes security event 4615(S) Invalid use of LPC port. It appears that the Invalid use of LPC port event never occurs.
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
|||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# 4615(S): Invalid use of LPC port.
|
# 4615(S): Invalid use of LPC port.
|
||||||
|
@ -2,7 +2,7 @@
|
|||||||
title: 4616(S) The system time was changed. (Windows 10)
|
title: 4616(S) The system time was changed. (Windows 10)
|
||||||
description: Describes security event 4616(S) The system time was changed. This event is generated every time system time is changed.
|
description: Describes security event 4616(S) The system time was changed. This event is generated every time system time is changed.
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
|||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# 4616(S): The system time was changed.
|
# 4616(S): The system time was changed.
|
||||||
|
@ -2,7 +2,7 @@
|
|||||||
title: 4618(S) A monitored security event pattern has occurred. (Windows 10)
|
title: 4618(S) A monitored security event pattern has occurred. (Windows 10)
|
||||||
description: Describes security event 4618(S) A monitored security event pattern has occurred.
|
description: Describes security event 4618(S) A monitored security event pattern has occurred.
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
|||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# 4618(S): A monitored security event pattern has occurred.
|
# 4618(S): A monitored security event pattern has occurred.
|
||||||
|
@ -2,7 +2,7 @@
|
|||||||
title: 4621(S) Administrator recovered system from CrashOnAuditFail. (Windows 10)
|
title: 4621(S) Administrator recovered system from CrashOnAuditFail. (Windows 10)
|
||||||
description: Describes security event 4621(S) Administrator recovered system from CrashOnAuditFail.
|
description: Describes security event 4621(S) Administrator recovered system from CrashOnAuditFail.
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
|||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# 4621(S): Administrator recovered system from CrashOnAuditFail.
|
# 4621(S): Administrator recovered system from CrashOnAuditFail.
|
||||||
|
@ -2,7 +2,7 @@
|
|||||||
title: 4622(S) A security package has been loaded by the Local Security Authority. (Windows 10)
|
title: 4622(S) A security package has been loaded by the Local Security Authority. (Windows 10)
|
||||||
description: Describes security event 4622(S) A security package has been loaded by the Local Security Authority.
|
description: Describes security event 4622(S) A security package has been loaded by the Local Security Authority.
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
|||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# 4622(S): A security package has been loaded by the Local Security Authority.
|
# 4622(S): A security package has been loaded by the Local Security Authority.
|
||||||
|
@ -2,7 +2,7 @@
|
|||||||
title: 4624(S) An account was successfully logged on. (Windows 10)
|
title: 4624(S) An account was successfully logged on. (Windows 10)
|
||||||
description: Describes security event 4624(S) An account was successfully logged on.
|
description: Describes security event 4624(S) An account was successfully logged on.
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
|||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# 4624(S): An account was successfully logged on.
|
# 4624(S): An account was successfully logged on.
|
||||||
|
@ -2,7 +2,7 @@
|
|||||||
title: 4625(F) An account failed to log on. (Windows 10)
|
title: 4625(F) An account failed to log on. (Windows 10)
|
||||||
description: Describes security event 4625(F) An account failed to log on. This event is generated if an account logon attempt failed for a locked out account.
|
description: Describes security event 4625(F) An account failed to log on. This event is generated if an account logon attempt failed for a locked out account.
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
@ -11,7 +11,7 @@ ms.date: 01/03/2022
|
|||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# 4625(F): An account failed to log on.
|
# 4625(F): An account failed to log on.
|
||||||
|
@ -2,7 +2,7 @@
|
|||||||
title: 4626(S) User/Device claims information. (Windows 10)
|
title: 4626(S) User/Device claims information. (Windows 10)
|
||||||
description: Describes security event 4626(S) User/Device claims information. This event is generated for new account logons.
|
description: Describes security event 4626(S) User/Device claims information. This event is generated for new account logons.
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
|||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# 4626(S): User/Device claims information.
|
# 4626(S): User/Device claims information.
|
||||||
|
@ -2,7 +2,7 @@
|
|||||||
title: 4627(S) Group membership information. (Windows 10)
|
title: 4627(S) Group membership information. (Windows 10)
|
||||||
description: Describes security event 4627(S) Group membership information. This event is generated with event 4624(S) An account was successfully logged on.
|
description: Describes security event 4627(S) Group membership information. This event is generated with event 4624(S) An account was successfully logged on.
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
|||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# 4627(S): Group membership information.
|
# 4627(S): Group membership information.
|
||||||
|
@ -2,7 +2,7 @@
|
|||||||
title: 4634(S) An account was logged off. (Windows 10)
|
title: 4634(S) An account was logged off. (Windows 10)
|
||||||
description: Describes security event 4634(S) An account was logged off. This event is generated when a logon session is terminated and no longer exists.
|
description: Describes security event 4634(S) An account was logged off. This event is generated when a logon session is terminated and no longer exists.
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
|||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# 4634(S): An account was logged off.
|
# 4634(S): An account was logged off.
|
||||||
|
@ -2,7 +2,7 @@
|
|||||||
title: 4647(S) User initiated logoff. (Windows 10)
|
title: 4647(S) User initiated logoff. (Windows 10)
|
||||||
description: Describes security event 4647(S) User initiated logoff. This event is generated when a logoff is initiated. No further user-initiated activity can occur.
|
description: Describes security event 4647(S) User initiated logoff. This event is generated when a logoff is initiated. No further user-initiated activity can occur.
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
|||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# 4647(S): User initiated logoff.
|
# 4647(S): User initiated logoff.
|
||||||
|
@ -2,7 +2,7 @@
|
|||||||
title: 4648(S) A logon was attempted using explicit credentials. (Windows 10)
|
title: 4648(S) A logon was attempted using explicit credentials. (Windows 10)
|
||||||
description: Describes security event 4648(S) A logon was attempted using explicit credentials.
|
description: Describes security event 4648(S) A logon was attempted using explicit credentials.
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
|||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# 4648(S): A logon was attempted using explicit credentials.
|
# 4648(S): A logon was attempted using explicit credentials.
|
||||||
|
@ -2,7 +2,7 @@
|
|||||||
title: 4649(S) A replay attack was detected. (Windows 10)
|
title: 4649(S) A replay attack was detected. (Windows 10)
|
||||||
description: Describes security event 4649(S) A replay attack was detected. This event is generated when a KRB_AP_ERR_REPEAT Kerberos response is sent to the client.
|
description: Describes security event 4649(S) A replay attack was detected. This event is generated when a KRB_AP_ERR_REPEAT Kerberos response is sent to the client.
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
|||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# 4649(S): A replay attack was detected.
|
# 4649(S): A replay attack was detected.
|
||||||
|
@ -2,7 +2,7 @@
|
|||||||
title: 4656(S, F) A handle to an object was requested. (Windows 10)
|
title: 4656(S, F) A handle to an object was requested. (Windows 10)
|
||||||
description: Describes security event 4656(S, F) A handle to an object was requested.
|
description: Describes security event 4656(S, F) A handle to an object was requested.
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
|||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# 4656(S, F): A handle to an object was requested.
|
# 4656(S, F): A handle to an object was requested.
|
||||||
|
@ -2,7 +2,7 @@
|
|||||||
title: 4657(S) A registry value was modified. (Windows 10)
|
title: 4657(S) A registry value was modified. (Windows 10)
|
||||||
description: Describes security event 4657(S) A registry value was modified. This event is generated when a registry key value is modified.
|
description: Describes security event 4657(S) A registry value was modified. This event is generated when a registry key value is modified.
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
|||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# 4657(S): A registry value was modified.
|
# 4657(S): A registry value was modified.
|
||||||
|
@ -2,7 +2,7 @@
|
|||||||
title: 4658(S) The handle to an object was closed. (Windows 10)
|
title: 4658(S) The handle to an object was closed. (Windows 10)
|
||||||
description: Describes security event 4658(S) The handle to an object was closed. This event is generated when the handle to an object is closed.
|
description: Describes security event 4658(S) The handle to an object was closed. This event is generated when the handle to an object is closed.
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
|||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# 4658(S): The handle to an object was closed.
|
# 4658(S): The handle to an object was closed.
|
||||||
|
@ -2,7 +2,7 @@
|
|||||||
title: 4660(S) An object was deleted. (Windows 10)
|
title: 4660(S) An object was deleted. (Windows 10)
|
||||||
description: Describes security event 4660(S) An object was deleted. This event is generated when an object is deleted.
|
description: Describes security event 4660(S) An object was deleted. This event is generated when an object is deleted.
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
|||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# 4660(S): An object was deleted.
|
# 4660(S): An object was deleted.
|
||||||
|
@ -2,7 +2,7 @@
|
|||||||
title: 4661(S, F) A handle to an object was requested. (Windows 10)
|
title: 4661(S, F) A handle to an object was requested. (Windows 10)
|
||||||
description: Describes security event 4661(S, F) A handle to an object was requested.
|
description: Describes security event 4661(S, F) A handle to an object was requested.
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
|||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# 4661(S, F): A handle to an object was requested.
|
# 4661(S, F): A handle to an object was requested.
|
||||||
|
@ -2,7 +2,7 @@
|
|||||||
title: 4662(S, F) An operation was performed on an object. (Windows 10)
|
title: 4662(S, F) An operation was performed on an object. (Windows 10)
|
||||||
description: Describes security event 4662(S, F) An operation was performed on an object.
|
description: Describes security event 4662(S, F) An operation was performed on an object.
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
|||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# 4662(S, F): An operation was performed on an object.
|
# 4662(S, F): An operation was performed on an object.
|
||||||
|
@ -2,7 +2,7 @@
|
|||||||
title: 4663(S) An attempt was made to access an object. (Windows 10)
|
title: 4663(S) An attempt was made to access an object. (Windows 10)
|
||||||
description: Describes security event 4663(S) An attempt was made to access an object.
|
description: Describes security event 4663(S) An attempt was made to access an object.
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
|||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# 4663(S): An attempt was made to access an object.
|
# 4663(S): An attempt was made to access an object.
|
||||||
|
@ -2,7 +2,7 @@
|
|||||||
title: 4664(S) An attempt was made to create a hard link. (Windows 10)
|
title: 4664(S) An attempt was made to create a hard link. (Windows 10)
|
||||||
description: Describes security event 4664(S) An attempt was made to create a hard link.
|
description: Describes security event 4664(S) An attempt was made to create a hard link.
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
|||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# 4664(S): An attempt was made to create a hard link.
|
# 4664(S): An attempt was made to create a hard link.
|
||||||
|
@ -2,7 +2,7 @@
|
|||||||
title: 4670(S) Permissions on an object were changed. (Windows 10)
|
title: 4670(S) Permissions on an object were changed. (Windows 10)
|
||||||
description: Describes security event 4670(S) Permissions on an object were changed.
|
description: Describes security event 4670(S) Permissions on an object were changed.
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.prod: m365-security
|
ms.prod: windows-client
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.localizationpriority: none
|
ms.localizationpriority: none
|
||||||
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
|||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
ms.author: vinpa
|
ms.author: vinpa
|
||||||
ms.technology: windows-sec
|
ms.technology: itpro-security
|
||||||
---
|
---
|
||||||
|
|
||||||
# 4670(S): Permissions on an object were changed.
|
# 4670(S): Permissions on an object were changed.
|
||||||
|
Loading…
x
Reference in New Issue
Block a user