mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-15 06:47:21 +00:00
Merge branch 'master' into repo_sync_working_branch
This commit is contained in:
commit
7aad93252d
@ -12,7 +12,7 @@ ms.author: greglin
|
|||||||
ms.date: 02/13/2018
|
ms.date: 02/13/2018
|
||||||
manager: dougeby
|
manager: dougeby
|
||||||
ms.audience: itpro
|
ms.audience: itpro
|
||||||
ms.localizationpriority: medium
|
ms.localizationpriority: high
|
||||||
ms.topic: article
|
ms.topic: article
|
||||||
ms.custom: seo-marvel-apr2020
|
ms.custom: seo-marvel-apr2020
|
||||||
ms.collection: highpri
|
ms.collection: highpri
|
||||||
|
@ -3,7 +3,7 @@ title: Windows 10 Pro in S mode
|
|||||||
description: Overview of Windows 10 Pro/Enterprise in S mode. What is S mode for Enterprise customers?
|
description: Overview of Windows 10 Pro/Enterprise in S mode. What is S mode for Enterprise customers?
|
||||||
keywords: Windows 10 S, S mode, Windows S mode, Windows 10 S mode, S-mode, system requirements, Overview, Windows 10 Pro in S mode, Windows 10 Enterprise in S mode, Windows 10 Pro/Enterprise in S mode
|
keywords: Windows 10 S, S mode, Windows S mode, Windows 10 S mode, S-mode, system requirements, Overview, Windows 10 Pro in S mode, Windows 10 Enterprise in S mode, Windows 10 Pro/Enterprise in S mode
|
||||||
ms.mktglfcycl: deploy
|
ms.mktglfcycl: deploy
|
||||||
ms.localizationpriority: medium
|
ms.localizationpriority: high
|
||||||
ms.prod: w10
|
ms.prod: w10
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.pagetype: deploy
|
ms.pagetype: deploy
|
||||||
|
@ -6,7 +6,7 @@ ms.mktglfcycl: manage
|
|||||||
audience: itpro
|
audience: itpro
|
||||||
itproauthor: jaimeo
|
itproauthor: jaimeo
|
||||||
author: jaimeo
|
author: jaimeo
|
||||||
ms.localizationpriority: medium
|
ms.localizationpriority: high
|
||||||
ms.author: jaimeo
|
ms.author: jaimeo
|
||||||
manager: dougeby
|
manager: dougeby
|
||||||
ms.collection:
|
ms.collection:
|
||||||
|
@ -173,7 +173,7 @@ For 4673(S, F): A privileged service was called.
|
|||||||
|
|
||||||
> **Important** For this event, also see [Appendix A: Security monitoring recommendations for many audit events](appendix-a-security-monitoring-recommendations-for-many-audit-events.md).
|
> **Important** For this event, also see [Appendix A: Security monitoring recommendations for many audit events](appendix-a-security-monitoring-recommendations-for-many-audit-events.md).
|
||||||
|
|
||||||
- Monitor for this event where “**Subject\\Security ID**” is *not* one of these well-known security principals: LOCAL SYSTEM, NETWORK SERVICE, LOCAL SERVICE, and where “**Subject\\Security ID**” is not an administrative account that is expected to have the listed **Privileges**. Especially monitor Failure events.
|
- Monitor for this event where “**Subject\\Security ID**” is *not* one of these well-known security principals: LOCAL SYSTEM, NETWORK SERVICE, LOCAL SERVICE, and where “**Subject\\Security ID**” is not an administrative account that is expected to have the listed **Privileges**. See subcategories [Audit Sensitive Privilege Use](/windows/security/threat-protection/auditing/audit-sensitive-privilege-use) and [Audit Non Sensitive Privilege Use](/windows/security/threat-protection/auditing/audit-non-sensitive-privilege-use) for more details.
|
||||||
|
|
||||||
- If you need to monitor events related to specific Windows subsystems (“**Service\\Server**”), for example **NT Local Security Authority / Authentication Service** or **Security Account Manager**, monitor this event for the corresponding “**Service\\Server**.”
|
- If you need to monitor events related to specific Windows subsystems (“**Service\\Server**”), for example **NT Local Security Authority / Authentication Service** or **Security Account Manager**, monitor this event for the corresponding “**Service\\Server**.”
|
||||||
|
|
||||||
|
Loading…
x
Reference in New Issue
Block a user