From ff98d60cedfedff9dd4bf22686fc348ca9eb120e Mon Sep 17 00:00:00 2001
From: Paolo Matarazzo <74918781+paolomatarazzo@users.noreply.github.com>
Date: Fri, 16 Dec 2022 11:11:00 -0500
Subject: [PATCH] bulk metadata updates
---
...nfigure-diffie-hellman-protocol-over-ikev2-vpn-connections.md | 1 +
...w-to-use-single-sign-on-sso-over-vpn-and-wi-fi-connections.md | 1 +
windows/security/identity-protection/vpn/vpn-authentication.md | 1 +
.../security/identity-protection/vpn/vpn-auto-trigger-profile.md | 1 +
.../security/identity-protection/vpn/vpn-conditional-access.md | 1 +
windows/security/identity-protection/vpn/vpn-connection-type.md | 1 +
windows/security/identity-protection/vpn/vpn-guide.md | 1 +
windows/security/identity-protection/vpn/vpn-name-resolution.md | 1 +
windows/security/identity-protection/vpn/vpn-profile-options.md | 1 +
windows/security/identity-protection/vpn/vpn-routing.md | 1 +
.../security/identity-protection/vpn/vpn-security-features.md | 1 +
windows/security/information-protection/encrypted-hard-drive.md | 1 +
...-security-monitoring-recommendations-for-many-audit-events.md | 1 +
.../security/threat-protection/auditing/audit-account-lockout.md | 1 +
.../threat-protection/auditing/audit-application-generated.md | 1 +
.../auditing/audit-application-group-management.md | 1 +
.../threat-protection/auditing/audit-audit-policy-change.md | 1 +
.../auditing/audit-authentication-policy-change.md | 1 +
.../auditing/audit-authorization-policy-change.md | 1 +
.../auditing/audit-central-access-policy-staging.md | 1 +
.../threat-protection/auditing/audit-certification-services.md | 1 +
.../auditing/audit-computer-account-management.md | 1 +
.../threat-protection/auditing/audit-credential-validation.md | 1 +
.../auditing/audit-detailed-directory-service-replication.md | 1 +
.../threat-protection/auditing/audit-detailed-file-share.md | 1 +
.../threat-protection/auditing/audit-directory-service-access.md | 1 +
.../auditing/audit-directory-service-changes.md | 1 +
.../auditing/audit-directory-service-replication.md | 1 +
.../auditing/audit-distribution-group-management.md | 1 +
.../security/threat-protection/auditing/audit-dpapi-activity.md | 1 +
windows/security/threat-protection/auditing/audit-file-share.md | 1 +
windows/security/threat-protection/auditing/audit-file-system.md | 1 +
.../auditing/audit-filtering-platform-connection.md | 1 +
.../auditing/audit-filtering-platform-packet-drop.md | 1 +
.../auditing/audit-filtering-platform-policy-change.md | 1 +
.../threat-protection/auditing/audit-group-membership.md | 1 +
.../threat-protection/auditing/audit-handle-manipulation.md | 1 +
.../security/threat-protection/auditing/audit-ipsec-driver.md | 1 +
.../threat-protection/auditing/audit-ipsec-extended-mode.md | 1 +
.../security/threat-protection/auditing/audit-ipsec-main-mode.md | 1 +
.../threat-protection/auditing/audit-ipsec-quick-mode.md | 1 +
.../auditing/audit-kerberos-authentication-service.md | 1 +
.../auditing/audit-kerberos-service-ticket-operations.md | 1 +
.../security/threat-protection/auditing/audit-kernel-object.md | 1 +
windows/security/threat-protection/auditing/audit-logoff.md | 1 +
windows/security/threat-protection/auditing/audit-logon.md | 1 +
.../auditing/audit-mpssvc-rule-level-policy-change.md | 1 +
.../threat-protection/auditing/audit-network-policy-server.md | 1 +
.../auditing/audit-non-sensitive-privilege-use.md | 1 +
.../auditing/audit-other-account-logon-events.md | 1 +
.../auditing/audit-other-account-management-events.md | 1 +
.../threat-protection/auditing/audit-other-logonlogoff-events.md | 1 +
.../auditing/audit-other-object-access-events.md | 1 +
.../auditing/audit-other-policy-change-events.md | 1 +
.../auditing/audit-other-privilege-use-events.md | 1 +
.../threat-protection/auditing/audit-other-system-events.md | 1 +
.../security/threat-protection/auditing/audit-pnp-activity.md | 1 +
.../threat-protection/auditing/audit-process-creation.md | 1 +
.../threat-protection/auditing/audit-process-termination.md | 1 +
windows/security/threat-protection/auditing/audit-registry.md | 1 +
.../threat-protection/auditing/audit-removable-storage.md | 1 +
windows/security/threat-protection/auditing/audit-rpc-events.md | 1 +
windows/security/threat-protection/auditing/audit-sam.md | 1 +
.../auditing/audit-security-group-management.md | 1 +
.../threat-protection/auditing/audit-security-state-change.md | 1 +
.../auditing/audit-security-system-extension.md | 1 +
.../threat-protection/auditing/audit-sensitive-privilege-use.md | 1 +
.../security/threat-protection/auditing/audit-special-logon.md | 1 +
.../threat-protection/auditing/audit-system-integrity.md | 1 +
.../threat-protection/auditing/audit-user-account-management.md | 1 +
.../threat-protection/auditing/audit-user-device-claims.md | 1 +
windows/security/threat-protection/auditing/event-1100.md | 1 +
windows/security/threat-protection/auditing/event-1102.md | 1 +
windows/security/threat-protection/auditing/event-1104.md | 1 +
windows/security/threat-protection/auditing/event-1105.md | 1 +
windows/security/threat-protection/auditing/event-1108.md | 1 +
windows/security/threat-protection/auditing/event-4608.md | 1 +
windows/security/threat-protection/auditing/event-4610.md | 1 +
windows/security/threat-protection/auditing/event-4611.md | 1 +
windows/security/threat-protection/auditing/event-4612.md | 1 +
windows/security/threat-protection/auditing/event-4614.md | 1 +
windows/security/threat-protection/auditing/event-4615.md | 1 +
windows/security/threat-protection/auditing/event-4616.md | 1 +
windows/security/threat-protection/auditing/event-4618.md | 1 +
windows/security/threat-protection/auditing/event-4621.md | 1 +
windows/security/threat-protection/auditing/event-4622.md | 1 +
windows/security/threat-protection/auditing/event-4624.md | 1 +
windows/security/threat-protection/auditing/event-4625.md | 1 +
windows/security/threat-protection/auditing/event-4626.md | 1 +
windows/security/threat-protection/auditing/event-4627.md | 1 +
windows/security/threat-protection/auditing/event-4634.md | 1 +
windows/security/threat-protection/auditing/event-4647.md | 1 +
windows/security/threat-protection/auditing/event-4648.md | 1 +
windows/security/threat-protection/auditing/event-4649.md | 1 +
windows/security/threat-protection/auditing/event-4656.md | 1 +
windows/security/threat-protection/auditing/event-4657.md | 1 +
windows/security/threat-protection/auditing/event-4658.md | 1 +
windows/security/threat-protection/auditing/event-4660.md | 1 +
windows/security/threat-protection/auditing/event-4661.md | 1 +
windows/security/threat-protection/auditing/event-4662.md | 1 +
windows/security/threat-protection/auditing/event-4663.md | 1 +
windows/security/threat-protection/auditing/event-4664.md | 1 +
windows/security/threat-protection/auditing/event-4670.md | 1 +
windows/security/threat-protection/auditing/event-4671.md | 1 +
windows/security/threat-protection/auditing/event-4672.md | 1 +
windows/security/threat-protection/auditing/event-4673.md | 1 +
windows/security/threat-protection/auditing/event-4674.md | 1 +
windows/security/threat-protection/auditing/event-4675.md | 1 +
windows/security/threat-protection/auditing/event-4688.md | 1 +
windows/security/threat-protection/auditing/event-4689.md | 1 +
windows/security/threat-protection/auditing/event-4690.md | 1 +
windows/security/threat-protection/auditing/event-4691.md | 1 +
windows/security/threat-protection/auditing/event-4692.md | 1 +
windows/security/threat-protection/auditing/event-4693.md | 1 +
windows/security/threat-protection/auditing/event-4694.md | 1 +
windows/security/threat-protection/auditing/event-4695.md | 1 +
windows/security/threat-protection/auditing/event-4696.md | 1 +
windows/security/threat-protection/auditing/event-4697.md | 1 +
windows/security/threat-protection/auditing/event-4698.md | 1 +
windows/security/threat-protection/auditing/event-4699.md | 1 +
windows/security/threat-protection/auditing/event-4700.md | 1 +
windows/security/threat-protection/auditing/event-4701.md | 1 +
windows/security/threat-protection/auditing/event-4702.md | 1 +
windows/security/threat-protection/auditing/event-4703.md | 1 +
windows/security/threat-protection/auditing/event-4704.md | 1 +
windows/security/threat-protection/auditing/event-4705.md | 1 +
windows/security/threat-protection/auditing/event-4706.md | 1 +
windows/security/threat-protection/auditing/event-4707.md | 1 +
windows/security/threat-protection/auditing/event-4713.md | 1 +
windows/security/threat-protection/auditing/event-4714.md | 1 +
windows/security/threat-protection/auditing/event-4715.md | 1 +
windows/security/threat-protection/auditing/event-4716.md | 1 +
windows/security/threat-protection/auditing/event-4717.md | 1 +
windows/security/threat-protection/auditing/event-4718.md | 1 +
windows/security/threat-protection/auditing/event-4719.md | 1 +
windows/security/threat-protection/auditing/event-4720.md | 1 +
windows/security/threat-protection/auditing/event-4722.md | 1 +
windows/security/threat-protection/auditing/event-4723.md | 1 +
windows/security/threat-protection/auditing/event-4724.md | 1 +
windows/security/threat-protection/auditing/event-4725.md | 1 +
windows/security/threat-protection/auditing/event-4726.md | 1 +
windows/security/threat-protection/auditing/event-4731.md | 1 +
windows/security/threat-protection/auditing/event-4732.md | 1 +
windows/security/threat-protection/auditing/event-4733.md | 1 +
windows/security/threat-protection/auditing/event-4734.md | 1 +
windows/security/threat-protection/auditing/event-4735.md | 1 +
windows/security/threat-protection/auditing/event-4738.md | 1 +
windows/security/threat-protection/auditing/event-4739.md | 1 +
windows/security/threat-protection/auditing/event-4740.md | 1 +
windows/security/threat-protection/auditing/event-4741.md | 1 +
windows/security/threat-protection/auditing/event-4742.md | 1 +
windows/security/threat-protection/auditing/event-4743.md | 1 +
windows/security/threat-protection/auditing/event-4749.md | 1 +
windows/security/threat-protection/auditing/event-4750.md | 1 +
windows/security/threat-protection/auditing/event-4751.md | 1 +
windows/security/threat-protection/auditing/event-4752.md | 1 +
windows/security/threat-protection/auditing/event-4753.md | 1 +
windows/security/threat-protection/auditing/event-4764.md | 1 +
windows/security/threat-protection/auditing/event-4765.md | 1 +
windows/security/threat-protection/auditing/event-4766.md | 1 +
windows/security/threat-protection/auditing/event-4767.md | 1 +
windows/security/threat-protection/auditing/event-4768.md | 1 +
windows/security/threat-protection/auditing/event-4769.md | 1 +
windows/security/threat-protection/auditing/event-4770.md | 1 +
windows/security/threat-protection/auditing/event-4771.md | 1 +
windows/security/threat-protection/auditing/event-4772.md | 1 +
windows/security/threat-protection/auditing/event-4773.md | 1 +
windows/security/threat-protection/auditing/event-4774.md | 1 +
windows/security/threat-protection/auditing/event-4775.md | 1 +
windows/security/threat-protection/auditing/event-4776.md | 1 +
windows/security/threat-protection/auditing/event-4777.md | 1 +
windows/security/threat-protection/auditing/event-4778.md | 1 +
windows/security/threat-protection/auditing/event-4779.md | 1 +
windows/security/threat-protection/auditing/event-4780.md | 1 +
windows/security/threat-protection/auditing/event-4781.md | 1 +
windows/security/threat-protection/auditing/event-4782.md | 1 +
windows/security/threat-protection/auditing/event-4793.md | 1 +
windows/security/threat-protection/auditing/event-4794.md | 1 +
windows/security/threat-protection/auditing/event-4798.md | 1 +
windows/security/threat-protection/auditing/event-4799.md | 1 +
windows/security/threat-protection/auditing/event-4800.md | 1 +
windows/security/threat-protection/auditing/event-4801.md | 1 +
windows/security/threat-protection/auditing/event-4802.md | 1 +
windows/security/threat-protection/auditing/event-4803.md | 1 +
windows/security/threat-protection/auditing/event-4816.md | 1 +
windows/security/threat-protection/auditing/event-4817.md | 1 +
windows/security/threat-protection/auditing/event-4818.md | 1 +
windows/security/threat-protection/auditing/event-4819.md | 1 +
windows/security/threat-protection/auditing/event-4826.md | 1 +
windows/security/threat-protection/auditing/event-4864.md | 1 +
windows/security/threat-protection/auditing/event-4865.md | 1 +
windows/security/threat-protection/auditing/event-4866.md | 1 +
windows/security/threat-protection/auditing/event-4867.md | 1 +
windows/security/threat-protection/auditing/event-4902.md | 1 +
windows/security/threat-protection/auditing/event-4904.md | 1 +
windows/security/threat-protection/auditing/event-4905.md | 1 +
windows/security/threat-protection/auditing/event-4906.md | 1 +
windows/security/threat-protection/auditing/event-4907.md | 1 +
windows/security/threat-protection/auditing/event-4908.md | 1 +
windows/security/threat-protection/auditing/event-4909.md | 1 +
windows/security/threat-protection/auditing/event-4910.md | 1 +
windows/security/threat-protection/auditing/event-4911.md | 1 +
windows/security/threat-protection/auditing/event-4912.md | 1 +
windows/security/threat-protection/auditing/event-4913.md | 1 +
windows/security/threat-protection/auditing/event-4928.md | 1 +
windows/security/threat-protection/auditing/event-4929.md | 1 +
windows/security/threat-protection/auditing/event-4930.md | 1 +
windows/security/threat-protection/auditing/event-4931.md | 1 +
windows/security/threat-protection/auditing/event-4932.md | 1 +
windows/security/threat-protection/auditing/event-4933.md | 1 +
windows/security/threat-protection/auditing/event-4934.md | 1 +
windows/security/threat-protection/auditing/event-4935.md | 1 +
windows/security/threat-protection/auditing/event-4936.md | 1 +
windows/security/threat-protection/auditing/event-4937.md | 1 +
windows/security/threat-protection/auditing/event-4944.md | 1 +
windows/security/threat-protection/auditing/event-4945.md | 1 +
windows/security/threat-protection/auditing/event-4946.md | 1 +
windows/security/threat-protection/auditing/event-4947.md | 1 +
windows/security/threat-protection/auditing/event-4948.md | 1 +
windows/security/threat-protection/auditing/event-4949.md | 1 +
windows/security/threat-protection/auditing/event-4950.md | 1 +
windows/security/threat-protection/auditing/event-4951.md | 1 +
windows/security/threat-protection/auditing/event-4952.md | 1 +
windows/security/threat-protection/auditing/event-4953.md | 1 +
windows/security/threat-protection/auditing/event-4954.md | 1 +
windows/security/threat-protection/auditing/event-4956.md | 1 +
windows/security/threat-protection/auditing/event-4957.md | 1 +
windows/security/threat-protection/auditing/event-4958.md | 1 +
windows/security/threat-protection/auditing/event-4964.md | 1 +
windows/security/threat-protection/auditing/event-4985.md | 1 +
windows/security/threat-protection/auditing/event-5024.md | 1 +
windows/security/threat-protection/auditing/event-5025.md | 1 +
windows/security/threat-protection/auditing/event-5027.md | 1 +
windows/security/threat-protection/auditing/event-5028.md | 1 +
windows/security/threat-protection/auditing/event-5029.md | 1 +
windows/security/threat-protection/auditing/event-5030.md | 1 +
windows/security/threat-protection/auditing/event-5031.md | 1 +
windows/security/threat-protection/auditing/event-5032.md | 1 +
windows/security/threat-protection/auditing/event-5033.md | 1 +
windows/security/threat-protection/auditing/event-5034.md | 1 +
windows/security/threat-protection/auditing/event-5035.md | 1 +
windows/security/threat-protection/auditing/event-5037.md | 1 +
windows/security/threat-protection/auditing/event-5038.md | 1 +
windows/security/threat-protection/auditing/event-5039.md | 1 +
windows/security/threat-protection/auditing/event-5051.md | 1 +
windows/security/threat-protection/auditing/event-5056.md | 1 +
windows/security/threat-protection/auditing/event-5057.md | 1 +
windows/security/threat-protection/auditing/event-5058.md | 1 +
windows/security/threat-protection/auditing/event-5059.md | 1 +
windows/security/threat-protection/auditing/event-5060.md | 1 +
windows/security/threat-protection/auditing/event-5061.md | 1 +
windows/security/threat-protection/auditing/event-5062.md | 1 +
windows/security/threat-protection/auditing/event-5063.md | 1 +
windows/security/threat-protection/auditing/event-5064.md | 1 +
windows/security/threat-protection/auditing/event-5065.md | 1 +
windows/security/threat-protection/auditing/event-5066.md | 1 +
windows/security/threat-protection/auditing/event-5067.md | 1 +
windows/security/threat-protection/auditing/event-5068.md | 1 +
windows/security/threat-protection/auditing/event-5069.md | 1 +
windows/security/threat-protection/auditing/event-5070.md | 1 +
windows/security/threat-protection/auditing/event-5136.md | 1 +
windows/security/threat-protection/auditing/event-5137.md | 1 +
windows/security/threat-protection/auditing/event-5138.md | 1 +
windows/security/threat-protection/auditing/event-5139.md | 1 +
windows/security/threat-protection/auditing/event-5140.md | 1 +
windows/security/threat-protection/auditing/event-5141.md | 1 +
windows/security/threat-protection/auditing/event-5142.md | 1 +
windows/security/threat-protection/auditing/event-5143.md | 1 +
windows/security/threat-protection/auditing/event-5144.md | 1 +
windows/security/threat-protection/auditing/event-5145.md | 1 +
windows/security/threat-protection/auditing/event-5148.md | 1 +
windows/security/threat-protection/auditing/event-5149.md | 1 +
windows/security/threat-protection/auditing/event-5150.md | 1 +
windows/security/threat-protection/auditing/event-5151.md | 1 +
windows/security/threat-protection/auditing/event-5152.md | 1 +
windows/security/threat-protection/auditing/event-5153.md | 1 +
windows/security/threat-protection/auditing/event-5154.md | 1 +
windows/security/threat-protection/auditing/event-5155.md | 1 +
windows/security/threat-protection/auditing/event-5156.md | 1 +
windows/security/threat-protection/auditing/event-5157.md | 1 +
windows/security/threat-protection/auditing/event-5158.md | 1 +
windows/security/threat-protection/auditing/event-5159.md | 1 +
windows/security/threat-protection/auditing/event-5168.md | 1 +
windows/security/threat-protection/auditing/event-5376.md | 1 +
windows/security/threat-protection/auditing/event-5377.md | 1 +
windows/security/threat-protection/auditing/event-5378.md | 1 +
windows/security/threat-protection/auditing/event-5447.md | 1 +
windows/security/threat-protection/auditing/event-5632.md | 1 +
windows/security/threat-protection/auditing/event-5633.md | 1 +
windows/security/threat-protection/auditing/event-5712.md | 1 +
windows/security/threat-protection/auditing/event-5888.md | 1 +
windows/security/threat-protection/auditing/event-5889.md | 1 +
windows/security/threat-protection/auditing/event-5890.md | 1 +
windows/security/threat-protection/auditing/event-6144.md | 1 +
windows/security/threat-protection/auditing/event-6145.md | 1 +
windows/security/threat-protection/auditing/event-6281.md | 1 +
windows/security/threat-protection/auditing/event-6400.md | 1 +
windows/security/threat-protection/auditing/event-6401.md | 1 +
windows/security/threat-protection/auditing/event-6402.md | 1 +
windows/security/threat-protection/auditing/event-6403.md | 1 +
windows/security/threat-protection/auditing/event-6404.md | 1 +
windows/security/threat-protection/auditing/event-6405.md | 1 +
windows/security/threat-protection/auditing/event-6406.md | 1 +
windows/security/threat-protection/auditing/event-6407.md | 1 +
windows/security/threat-protection/auditing/event-6408.md | 1 +
windows/security/threat-protection/auditing/event-6409.md | 1 +
windows/security/threat-protection/auditing/event-6410.md | 1 +
windows/security/threat-protection/auditing/event-6416.md | 1 +
windows/security/threat-protection/auditing/event-6419.md | 1 +
windows/security/threat-protection/auditing/event-6420.md | 1 +
windows/security/threat-protection/auditing/event-6421.md | 1 +
windows/security/threat-protection/auditing/event-6422.md | 1 +
windows/security/threat-protection/auditing/event-6423.md | 1 +
windows/security/threat-protection/auditing/event-6424.md | 1 +
.../auditing/how-to-list-xml-elements-in-eventdata.md | 1 +
windows/security/threat-protection/auditing/other-events.md | 1 +
.../threat-protection/block-untrusted-fonts-in-enterprise.md | 1 +
.../configure-md-app-guard.md | 1 +
.../microsoft-defender-application-guard/install-md-app-guard.md | 1 +
.../md-app-guard-browser-extension.md | 1 +
.../md-app-guard-overview.md | 1 +
.../test-scenarios-md-app-guard.md | 1 +
.../microsoft-defender-smartscreen-available-settings.md | 1 +
.../microsoft-defender-smartscreen-set-individual-device.md | 1 +
.../phishing-protection-microsoft-defender-smartscreen.md | 1 +
...sets-by-controlling-the-health-of-windows-10-based-devices.md | 1 +
...rosoft-network-client-digitally-sign-communications-always.md | 1 +
.../security-policy-settings/minimum-password-age.md | 1 +
...k-access-restrict-clients-allowed-to-make-remote-sam-calls.md | 1 +
.../security-policy-settings/security-options.md | 1 +
...-windows-event-forwarding-to-assist-in-intrusion-detection.md | 1 +
.../applocker/working-with-applocker-rules.md | 1 +
.../wdsc-windows-10-in-s-mode.md | 1 +
.../how-hardware-based-root-of-trust-helps-protect-windows.md | 1 +
.../system-guard-secure-launch-and-smm-protection.md | 1 +
...figure-the-workstation-authentication-certificate-template.md | 1 +
336 files changed, 336 insertions(+)
diff --git a/windows/security/identity-protection/vpn/how-to-configure-diffie-hellman-protocol-over-ikev2-vpn-connections.md b/windows/security/identity-protection/vpn/how-to-configure-diffie-hellman-protocol-over-ikev2-vpn-connections.md
index 5ca81d5c91..188fe97442 100644
--- a/windows/security/identity-protection/vpn/how-to-configure-diffie-hellman-protocol-over-ikev2-vpn-connections.md
+++ b/windows/security/identity-protection/vpn/how-to-configure-diffie-hellman-protocol-over-ikev2-vpn-connections.md
@@ -12,6 +12,7 @@ appliesto:
- ✅ Windows 10
- ✅ Windows 11
ms.technology: itpro-security
+ms.topic: how-to
---
# How to configure Diffie Hellman protocol over IKEv2 VPN connections
diff --git a/windows/security/identity-protection/vpn/how-to-use-single-sign-on-sso-over-vpn-and-wi-fi-connections.md b/windows/security/identity-protection/vpn/how-to-use-single-sign-on-sso-over-vpn-and-wi-fi-connections.md
index 4b167fab27..371193641b 100644
--- a/windows/security/identity-protection/vpn/how-to-use-single-sign-on-sso-over-vpn-and-wi-fi-connections.md
+++ b/windows/security/identity-protection/vpn/how-to-use-single-sign-on-sso-over-vpn-and-wi-fi-connections.md
@@ -11,6 +11,7 @@ appliesto:
- ✅ Windows 10
- ✅ Windows 11
ms.technology: itpro-security
+ms.topic: how-to
---
# How to use Single Sign-On (SSO) over VPN and Wi-Fi connections
diff --git a/windows/security/identity-protection/vpn/vpn-authentication.md b/windows/security/identity-protection/vpn/vpn-authentication.md
index fa541c4f87..a44aa1b079 100644
--- a/windows/security/identity-protection/vpn/vpn-authentication.md
+++ b/windows/security/identity-protection/vpn/vpn-authentication.md
@@ -12,6 +12,7 @@ appliesto:
- ✅ Windows 10
- ✅ Windows 11
ms.technology: itpro-security
+ms.topic: conceptual
---
# VPN authentication options
diff --git a/windows/security/identity-protection/vpn/vpn-auto-trigger-profile.md b/windows/security/identity-protection/vpn/vpn-auto-trigger-profile.md
index e7e1f831ab..61044232d2 100644
--- a/windows/security/identity-protection/vpn/vpn-auto-trigger-profile.md
+++ b/windows/security/identity-protection/vpn/vpn-auto-trigger-profile.md
@@ -12,6 +12,7 @@ appliesto:
- ✅ Windows 10
- ✅ Windows 11
ms.technology: itpro-security
+ms.topic: conceptual
---
# VPN auto-triggered profile options
diff --git a/windows/security/identity-protection/vpn/vpn-conditional-access.md b/windows/security/identity-protection/vpn/vpn-conditional-access.md
index 5d7a695376..5da2a635a4 100644
--- a/windows/security/identity-protection/vpn/vpn-conditional-access.md
+++ b/windows/security/identity-protection/vpn/vpn-conditional-access.md
@@ -12,6 +12,7 @@ appliesto:
- ✅ Windows 10
- ✅ Windows 11
ms.technology: itpro-security
+ms.topic: conceptual
---
# VPN and conditional access
diff --git a/windows/security/identity-protection/vpn/vpn-connection-type.md b/windows/security/identity-protection/vpn/vpn-connection-type.md
index c3b4995351..e9eecdbbb9 100644
--- a/windows/security/identity-protection/vpn/vpn-connection-type.md
+++ b/windows/security/identity-protection/vpn/vpn-connection-type.md
@@ -12,6 +12,7 @@ appliesto:
- ✅ Windows 10
- ✅ Windows 11
ms.technology: itpro-security
+ms.topic: conceptual
---
# VPN connection types
diff --git a/windows/security/identity-protection/vpn/vpn-guide.md b/windows/security/identity-protection/vpn/vpn-guide.md
index 40331b878d..f8cf27d242 100644
--- a/windows/security/identity-protection/vpn/vpn-guide.md
+++ b/windows/security/identity-protection/vpn/vpn-guide.md
@@ -12,6 +12,7 @@ appliesto:
- ✅ Windows 10
- ✅ Windows 11
ms.technology: itpro-security
+ms.topic: conceptual
---
# Windows VPN technical guide
diff --git a/windows/security/identity-protection/vpn/vpn-name-resolution.md b/windows/security/identity-protection/vpn/vpn-name-resolution.md
index 61fccf4518..34f201d00a 100644
--- a/windows/security/identity-protection/vpn/vpn-name-resolution.md
+++ b/windows/security/identity-protection/vpn/vpn-name-resolution.md
@@ -12,6 +12,7 @@ appliesto:
- ✅ Windows 10
- ✅ Windows 11
ms.technology: itpro-security
+ms.topic: conceptual
---
# VPN name resolution
diff --git a/windows/security/identity-protection/vpn/vpn-profile-options.md b/windows/security/identity-protection/vpn/vpn-profile-options.md
index ebd414e637..d5725508e4 100644
--- a/windows/security/identity-protection/vpn/vpn-profile-options.md
+++ b/windows/security/identity-protection/vpn/vpn-profile-options.md
@@ -12,6 +12,7 @@ appliesto:
- ✅ Windows 10
- ✅ Windows 11
ms.technology: itpro-security
+ms.topic: conceptual
---
# VPN profile options
diff --git a/windows/security/identity-protection/vpn/vpn-routing.md b/windows/security/identity-protection/vpn/vpn-routing.md
index 195202fe24..be5bc1caf0 100644
--- a/windows/security/identity-protection/vpn/vpn-routing.md
+++ b/windows/security/identity-protection/vpn/vpn-routing.md
@@ -12,6 +12,7 @@ appliesto:
- ✅ Windows 10
- ✅ Windows 11
ms.technology: itpro-security
+ms.topic: conceptual
---
# VPN routing decisions
diff --git a/windows/security/identity-protection/vpn/vpn-security-features.md b/windows/security/identity-protection/vpn/vpn-security-features.md
index d21e11182a..f8fb6861a0 100644
--- a/windows/security/identity-protection/vpn/vpn-security-features.md
+++ b/windows/security/identity-protection/vpn/vpn-security-features.md
@@ -12,6 +12,7 @@ appliesto:
- ✅ Windows 10
- ✅ Windows 11
ms.technology: itpro-security
+ms.topic: conceptual
---
# VPN security features
diff --git a/windows/security/information-protection/encrypted-hard-drive.md b/windows/security/information-protection/encrypted-hard-drive.md
index 765325f2f0..82af1b7c01 100644
--- a/windows/security/information-protection/encrypted-hard-drive.md
+++ b/windows/security/information-protection/encrypted-hard-drive.md
@@ -8,6 +8,7 @@ ms.prod: windows-client
author: frankroj
ms.date: 11/08/2022
ms.technology: itpro-security
+ms.topic: conceptual
---
# Encrypted Hard Drive
diff --git a/windows/security/threat-protection/auditing/appendix-a-security-monitoring-recommendations-for-many-audit-events.md b/windows/security/threat-protection/auditing/appendix-a-security-monitoring-recommendations-for-many-audit-events.md
index 3838e0f0f4..eb734ebf54 100644
--- a/windows/security/threat-protection/auditing/appendix-a-security-monitoring-recommendations-for-many-audit-events.md
+++ b/windows/security/threat-protection/auditing/appendix-a-security-monitoring-recommendations-for-many-audit-events.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# Appendix A: Security monitoring recommendations for many audit events
diff --git a/windows/security/threat-protection/auditing/audit-account-lockout.md b/windows/security/threat-protection/auditing/audit-account-lockout.md
index 9d49394e56..f2cf0cc5ec 100644
--- a/windows/security/threat-protection/auditing/audit-account-lockout.md
+++ b/windows/security/threat-protection/auditing/audit-account-lockout.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Account Lockout
diff --git a/windows/security/threat-protection/auditing/audit-application-generated.md b/windows/security/threat-protection/auditing/audit-application-generated.md
index f7ca99507d..36f8f451a0 100644
--- a/windows/security/threat-protection/auditing/audit-application-generated.md
+++ b/windows/security/threat-protection/auditing/audit-application-generated.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Application Generated
diff --git a/windows/security/threat-protection/auditing/audit-application-group-management.md b/windows/security/threat-protection/auditing/audit-application-group-management.md
index 706551065b..cb91f3fa61 100644
--- a/windows/security/threat-protection/auditing/audit-application-group-management.md
+++ b/windows/security/threat-protection/auditing/audit-application-group-management.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Application Group Management
diff --git a/windows/security/threat-protection/auditing/audit-audit-policy-change.md b/windows/security/threat-protection/auditing/audit-audit-policy-change.md
index aaf65be8db..c5cdf8c616 100644
--- a/windows/security/threat-protection/auditing/audit-audit-policy-change.md
+++ b/windows/security/threat-protection/auditing/audit-audit-policy-change.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Audit Policy Change
diff --git a/windows/security/threat-protection/auditing/audit-authentication-policy-change.md b/windows/security/threat-protection/auditing/audit-authentication-policy-change.md
index 6754a2796a..318f08b516 100644
--- a/windows/security/threat-protection/auditing/audit-authentication-policy-change.md
+++ b/windows/security/threat-protection/auditing/audit-authentication-policy-change.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Authentication Policy Change
diff --git a/windows/security/threat-protection/auditing/audit-authorization-policy-change.md b/windows/security/threat-protection/auditing/audit-authorization-policy-change.md
index e8c3a7d588..b7fd89b268 100644
--- a/windows/security/threat-protection/auditing/audit-authorization-policy-change.md
+++ b/windows/security/threat-protection/auditing/audit-authorization-policy-change.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Authorization Policy Change
diff --git a/windows/security/threat-protection/auditing/audit-central-access-policy-staging.md b/windows/security/threat-protection/auditing/audit-central-access-policy-staging.md
index 5e92817efe..62ac5c925c 100644
--- a/windows/security/threat-protection/auditing/audit-central-access-policy-staging.md
+++ b/windows/security/threat-protection/auditing/audit-central-access-policy-staging.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Central Access Policy Staging
diff --git a/windows/security/threat-protection/auditing/audit-certification-services.md b/windows/security/threat-protection/auditing/audit-certification-services.md
index bc1ec469f1..889edc295b 100644
--- a/windows/security/threat-protection/auditing/audit-certification-services.md
+++ b/windows/security/threat-protection/auditing/audit-certification-services.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Certification Services
diff --git a/windows/security/threat-protection/auditing/audit-computer-account-management.md b/windows/security/threat-protection/auditing/audit-computer-account-management.md
index 8c42317e94..63ad7eaac9 100644
--- a/windows/security/threat-protection/auditing/audit-computer-account-management.md
+++ b/windows/security/threat-protection/auditing/audit-computer-account-management.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Computer Account Management
diff --git a/windows/security/threat-protection/auditing/audit-credential-validation.md b/windows/security/threat-protection/auditing/audit-credential-validation.md
index b04f1cb5a9..a5a9dc7158 100644
--- a/windows/security/threat-protection/auditing/audit-credential-validation.md
+++ b/windows/security/threat-protection/auditing/audit-credential-validation.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Credential Validation
diff --git a/windows/security/threat-protection/auditing/audit-detailed-directory-service-replication.md b/windows/security/threat-protection/auditing/audit-detailed-directory-service-replication.md
index 72f481f66b..7fffbad3df 100644
--- a/windows/security/threat-protection/auditing/audit-detailed-directory-service-replication.md
+++ b/windows/security/threat-protection/auditing/audit-detailed-directory-service-replication.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Detailed Directory Service Replication
diff --git a/windows/security/threat-protection/auditing/audit-detailed-file-share.md b/windows/security/threat-protection/auditing/audit-detailed-file-share.md
index 16b1667db6..9ec6b5c148 100644
--- a/windows/security/threat-protection/auditing/audit-detailed-file-share.md
+++ b/windows/security/threat-protection/auditing/audit-detailed-file-share.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Detailed File Share
diff --git a/windows/security/threat-protection/auditing/audit-directory-service-access.md b/windows/security/threat-protection/auditing/audit-directory-service-access.md
index a70119e0d5..e58853650d 100644
--- a/windows/security/threat-protection/auditing/audit-directory-service-access.md
+++ b/windows/security/threat-protection/auditing/audit-directory-service-access.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Directory Service Access
diff --git a/windows/security/threat-protection/auditing/audit-directory-service-changes.md b/windows/security/threat-protection/auditing/audit-directory-service-changes.md
index 5aa0e36978..c9485389e9 100644
--- a/windows/security/threat-protection/auditing/audit-directory-service-changes.md
+++ b/windows/security/threat-protection/auditing/audit-directory-service-changes.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Directory Service Changes
diff --git a/windows/security/threat-protection/auditing/audit-directory-service-replication.md b/windows/security/threat-protection/auditing/audit-directory-service-replication.md
index f9c45299fe..046dd9a1e7 100644
--- a/windows/security/threat-protection/auditing/audit-directory-service-replication.md
+++ b/windows/security/threat-protection/auditing/audit-directory-service-replication.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Directory Service Replication
diff --git a/windows/security/threat-protection/auditing/audit-distribution-group-management.md b/windows/security/threat-protection/auditing/audit-distribution-group-management.md
index 23341f0d60..8eb5bb988c 100644
--- a/windows/security/threat-protection/auditing/audit-distribution-group-management.md
+++ b/windows/security/threat-protection/auditing/audit-distribution-group-management.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Distribution Group Management
diff --git a/windows/security/threat-protection/auditing/audit-dpapi-activity.md b/windows/security/threat-protection/auditing/audit-dpapi-activity.md
index bc24e85d75..79dbf17692 100644
--- a/windows/security/threat-protection/auditing/audit-dpapi-activity.md
+++ b/windows/security/threat-protection/auditing/audit-dpapi-activity.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit DPAPI Activity
diff --git a/windows/security/threat-protection/auditing/audit-file-share.md b/windows/security/threat-protection/auditing/audit-file-share.md
index 59c2d6638e..577c138f46 100644
--- a/windows/security/threat-protection/auditing/audit-file-share.md
+++ b/windows/security/threat-protection/auditing/audit-file-share.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit File Share
diff --git a/windows/security/threat-protection/auditing/audit-file-system.md b/windows/security/threat-protection/auditing/audit-file-system.md
index c9a66ed82e..037faaf8f4 100644
--- a/windows/security/threat-protection/auditing/audit-file-system.md
+++ b/windows/security/threat-protection/auditing/audit-file-system.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit File System
diff --git a/windows/security/threat-protection/auditing/audit-filtering-platform-connection.md b/windows/security/threat-protection/auditing/audit-filtering-platform-connection.md
index 7984928783..5877ab26f1 100644
--- a/windows/security/threat-protection/auditing/audit-filtering-platform-connection.md
+++ b/windows/security/threat-protection/auditing/audit-filtering-platform-connection.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Filtering Platform Connection
diff --git a/windows/security/threat-protection/auditing/audit-filtering-platform-packet-drop.md b/windows/security/threat-protection/auditing/audit-filtering-platform-packet-drop.md
index 15c0bc27d2..9003cab47c 100644
--- a/windows/security/threat-protection/auditing/audit-filtering-platform-packet-drop.md
+++ b/windows/security/threat-protection/auditing/audit-filtering-platform-packet-drop.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Filtering Platform Packet Drop
diff --git a/windows/security/threat-protection/auditing/audit-filtering-platform-policy-change.md b/windows/security/threat-protection/auditing/audit-filtering-platform-policy-change.md
index b8f192cccd..1a4cab1153 100644
--- a/windows/security/threat-protection/auditing/audit-filtering-platform-policy-change.md
+++ b/windows/security/threat-protection/auditing/audit-filtering-platform-policy-change.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Filtering Platform Policy Change
diff --git a/windows/security/threat-protection/auditing/audit-group-membership.md b/windows/security/threat-protection/auditing/audit-group-membership.md
index b3740aca1a..9f32d9d336 100644
--- a/windows/security/threat-protection/auditing/audit-group-membership.md
+++ b/windows/security/threat-protection/auditing/audit-group-membership.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Group Membership
diff --git a/windows/security/threat-protection/auditing/audit-handle-manipulation.md b/windows/security/threat-protection/auditing/audit-handle-manipulation.md
index c468ff02f3..50470902eb 100644
--- a/windows/security/threat-protection/auditing/audit-handle-manipulation.md
+++ b/windows/security/threat-protection/auditing/audit-handle-manipulation.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Handle Manipulation
diff --git a/windows/security/threat-protection/auditing/audit-ipsec-driver.md b/windows/security/threat-protection/auditing/audit-ipsec-driver.md
index dc52d2d90e..cfcefafd36 100644
--- a/windows/security/threat-protection/auditing/audit-ipsec-driver.md
+++ b/windows/security/threat-protection/auditing/audit-ipsec-driver.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit IPsec Driver
diff --git a/windows/security/threat-protection/auditing/audit-ipsec-extended-mode.md b/windows/security/threat-protection/auditing/audit-ipsec-extended-mode.md
index 92e2d71f5e..33bfbb485d 100644
--- a/windows/security/threat-protection/auditing/audit-ipsec-extended-mode.md
+++ b/windows/security/threat-protection/auditing/audit-ipsec-extended-mode.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit IPsec Extended Mode
diff --git a/windows/security/threat-protection/auditing/audit-ipsec-main-mode.md b/windows/security/threat-protection/auditing/audit-ipsec-main-mode.md
index 965715efa2..7f1d59e38c 100644
--- a/windows/security/threat-protection/auditing/audit-ipsec-main-mode.md
+++ b/windows/security/threat-protection/auditing/audit-ipsec-main-mode.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit IPsec Main Mode
diff --git a/windows/security/threat-protection/auditing/audit-ipsec-quick-mode.md b/windows/security/threat-protection/auditing/audit-ipsec-quick-mode.md
index 7a8be4ff82..869e1f4dcf 100644
--- a/windows/security/threat-protection/auditing/audit-ipsec-quick-mode.md
+++ b/windows/security/threat-protection/auditing/audit-ipsec-quick-mode.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit IPsec Quick Mode
diff --git a/windows/security/threat-protection/auditing/audit-kerberos-authentication-service.md b/windows/security/threat-protection/auditing/audit-kerberos-authentication-service.md
index 98a1c8f558..4ed0bce866 100644
--- a/windows/security/threat-protection/auditing/audit-kerberos-authentication-service.md
+++ b/windows/security/threat-protection/auditing/audit-kerberos-authentication-service.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Kerberos Authentication Service
diff --git a/windows/security/threat-protection/auditing/audit-kerberos-service-ticket-operations.md b/windows/security/threat-protection/auditing/audit-kerberos-service-ticket-operations.md
index 135c2882b7..ed3c49dfef 100644
--- a/windows/security/threat-protection/auditing/audit-kerberos-service-ticket-operations.md
+++ b/windows/security/threat-protection/auditing/audit-kerberos-service-ticket-operations.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Kerberos Service Ticket Operations
diff --git a/windows/security/threat-protection/auditing/audit-kernel-object.md b/windows/security/threat-protection/auditing/audit-kernel-object.md
index bb5d6d221a..0dd8928c22 100644
--- a/windows/security/threat-protection/auditing/audit-kernel-object.md
+++ b/windows/security/threat-protection/auditing/audit-kernel-object.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Kernel Object
diff --git a/windows/security/threat-protection/auditing/audit-logoff.md b/windows/security/threat-protection/auditing/audit-logoff.md
index b6108a6488..6a1f7f33ef 100644
--- a/windows/security/threat-protection/auditing/audit-logoff.md
+++ b/windows/security/threat-protection/auditing/audit-logoff.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Logoff
diff --git a/windows/security/threat-protection/auditing/audit-logon.md b/windows/security/threat-protection/auditing/audit-logon.md
index 74e7fe7f8f..4b78d70722 100644
--- a/windows/security/threat-protection/auditing/audit-logon.md
+++ b/windows/security/threat-protection/auditing/audit-logon.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Logon
diff --git a/windows/security/threat-protection/auditing/audit-mpssvc-rule-level-policy-change.md b/windows/security/threat-protection/auditing/audit-mpssvc-rule-level-policy-change.md
index a441c97c4c..4081cf31a9 100644
--- a/windows/security/threat-protection/auditing/audit-mpssvc-rule-level-policy-change.md
+++ b/windows/security/threat-protection/auditing/audit-mpssvc-rule-level-policy-change.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit MPSSVC Rule-Level Policy Change
diff --git a/windows/security/threat-protection/auditing/audit-network-policy-server.md b/windows/security/threat-protection/auditing/audit-network-policy-server.md
index 6c9a0fb877..2501fecc08 100644
--- a/windows/security/threat-protection/auditing/audit-network-policy-server.md
+++ b/windows/security/threat-protection/auditing/audit-network-policy-server.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Network Policy Server
diff --git a/windows/security/threat-protection/auditing/audit-non-sensitive-privilege-use.md b/windows/security/threat-protection/auditing/audit-non-sensitive-privilege-use.md
index b9920a8900..01b3fb153f 100644
--- a/windows/security/threat-protection/auditing/audit-non-sensitive-privilege-use.md
+++ b/windows/security/threat-protection/auditing/audit-non-sensitive-privilege-use.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Non-Sensitive Privilege Use
diff --git a/windows/security/threat-protection/auditing/audit-other-account-logon-events.md b/windows/security/threat-protection/auditing/audit-other-account-logon-events.md
index 23ab2587a5..23ee128d63 100644
--- a/windows/security/threat-protection/auditing/audit-other-account-logon-events.md
+++ b/windows/security/threat-protection/auditing/audit-other-account-logon-events.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Other Account Logon Events
diff --git a/windows/security/threat-protection/auditing/audit-other-account-management-events.md b/windows/security/threat-protection/auditing/audit-other-account-management-events.md
index 7d8e27c634..8f3d985309 100644
--- a/windows/security/threat-protection/auditing/audit-other-account-management-events.md
+++ b/windows/security/threat-protection/auditing/audit-other-account-management-events.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Other Account Management Events
diff --git a/windows/security/threat-protection/auditing/audit-other-logonlogoff-events.md b/windows/security/threat-protection/auditing/audit-other-logonlogoff-events.md
index 43e4b822aa..789ab297be 100644
--- a/windows/security/threat-protection/auditing/audit-other-logonlogoff-events.md
+++ b/windows/security/threat-protection/auditing/audit-other-logonlogoff-events.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Other Logon/Logoff Events
diff --git a/windows/security/threat-protection/auditing/audit-other-object-access-events.md b/windows/security/threat-protection/auditing/audit-other-object-access-events.md
index 901c4b5a7e..5dc0923e42 100644
--- a/windows/security/threat-protection/auditing/audit-other-object-access-events.md
+++ b/windows/security/threat-protection/auditing/audit-other-object-access-events.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Other Object Access Events
diff --git a/windows/security/threat-protection/auditing/audit-other-policy-change-events.md b/windows/security/threat-protection/auditing/audit-other-policy-change-events.md
index 776b3fdec9..d088e9f929 100644
--- a/windows/security/threat-protection/auditing/audit-other-policy-change-events.md
+++ b/windows/security/threat-protection/auditing/audit-other-policy-change-events.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Other Policy Change Events
diff --git a/windows/security/threat-protection/auditing/audit-other-privilege-use-events.md b/windows/security/threat-protection/auditing/audit-other-privilege-use-events.md
index 97a8de3544..c2487a6b33 100644
--- a/windows/security/threat-protection/auditing/audit-other-privilege-use-events.md
+++ b/windows/security/threat-protection/auditing/audit-other-privilege-use-events.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Other Privilege Use Events
diff --git a/windows/security/threat-protection/auditing/audit-other-system-events.md b/windows/security/threat-protection/auditing/audit-other-system-events.md
index 015eb3ddea..63cfb375b0 100644
--- a/windows/security/threat-protection/auditing/audit-other-system-events.md
+++ b/windows/security/threat-protection/auditing/audit-other-system-events.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Other System Events
diff --git a/windows/security/threat-protection/auditing/audit-pnp-activity.md b/windows/security/threat-protection/auditing/audit-pnp-activity.md
index da07e88f35..224eae5fcb 100644
--- a/windows/security/threat-protection/auditing/audit-pnp-activity.md
+++ b/windows/security/threat-protection/auditing/audit-pnp-activity.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit PNP Activity
diff --git a/windows/security/threat-protection/auditing/audit-process-creation.md b/windows/security/threat-protection/auditing/audit-process-creation.md
index 3eb6dcf190..07b283ace9 100644
--- a/windows/security/threat-protection/auditing/audit-process-creation.md
+++ b/windows/security/threat-protection/auditing/audit-process-creation.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 03/16/2022
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Process Creation
diff --git a/windows/security/threat-protection/auditing/audit-process-termination.md b/windows/security/threat-protection/auditing/audit-process-termination.md
index 60a0a05de7..b156ba658a 100644
--- a/windows/security/threat-protection/auditing/audit-process-termination.md
+++ b/windows/security/threat-protection/auditing/audit-process-termination.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Process Termination
diff --git a/windows/security/threat-protection/auditing/audit-registry.md b/windows/security/threat-protection/auditing/audit-registry.md
index e67da43c3e..a4423aeb52 100644
--- a/windows/security/threat-protection/auditing/audit-registry.md
+++ b/windows/security/threat-protection/auditing/audit-registry.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 01/05/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Registry
diff --git a/windows/security/threat-protection/auditing/audit-removable-storage.md b/windows/security/threat-protection/auditing/audit-removable-storage.md
index 4277dd71c8..c9d2586107 100644
--- a/windows/security/threat-protection/auditing/audit-removable-storage.md
+++ b/windows/security/threat-protection/auditing/audit-removable-storage.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Removable Storage
diff --git a/windows/security/threat-protection/auditing/audit-rpc-events.md b/windows/security/threat-protection/auditing/audit-rpc-events.md
index 27dc6938be..bee389855a 100644
--- a/windows/security/threat-protection/auditing/audit-rpc-events.md
+++ b/windows/security/threat-protection/auditing/audit-rpc-events.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit RPC Events
diff --git a/windows/security/threat-protection/auditing/audit-sam.md b/windows/security/threat-protection/auditing/audit-sam.md
index 1f295079c7..c92e7d5ba5 100644
--- a/windows/security/threat-protection/auditing/audit-sam.md
+++ b/windows/security/threat-protection/auditing/audit-sam.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit SAM
diff --git a/windows/security/threat-protection/auditing/audit-security-group-management.md b/windows/security/threat-protection/auditing/audit-security-group-management.md
index 6fe81c704f..0564c257b6 100644
--- a/windows/security/threat-protection/auditing/audit-security-group-management.md
+++ b/windows/security/threat-protection/auditing/audit-security-group-management.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Security Group Management
diff --git a/windows/security/threat-protection/auditing/audit-security-state-change.md b/windows/security/threat-protection/auditing/audit-security-state-change.md
index 94c6d1f229..25686b4f33 100644
--- a/windows/security/threat-protection/auditing/audit-security-state-change.md
+++ b/windows/security/threat-protection/auditing/audit-security-state-change.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Security State Change
diff --git a/windows/security/threat-protection/auditing/audit-security-system-extension.md b/windows/security/threat-protection/auditing/audit-security-system-extension.md
index fbda6e4cbb..72a72a15aa 100644
--- a/windows/security/threat-protection/auditing/audit-security-system-extension.md
+++ b/windows/security/threat-protection/auditing/audit-security-system-extension.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Security System Extension
diff --git a/windows/security/threat-protection/auditing/audit-sensitive-privilege-use.md b/windows/security/threat-protection/auditing/audit-sensitive-privilege-use.md
index eb8714f152..c79520f698 100644
--- a/windows/security/threat-protection/auditing/audit-sensitive-privilege-use.md
+++ b/windows/security/threat-protection/auditing/audit-sensitive-privilege-use.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Sensitive Privilege Use
diff --git a/windows/security/threat-protection/auditing/audit-special-logon.md b/windows/security/threat-protection/auditing/audit-special-logon.md
index 8f865d11bc..e9958ffa2e 100644
--- a/windows/security/threat-protection/auditing/audit-special-logon.md
+++ b/windows/security/threat-protection/auditing/audit-special-logon.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit Special Logon
diff --git a/windows/security/threat-protection/auditing/audit-system-integrity.md b/windows/security/threat-protection/auditing/audit-system-integrity.md
index 761abff74a..4a313d8ae0 100644
--- a/windows/security/threat-protection/auditing/audit-system-integrity.md
+++ b/windows/security/threat-protection/auditing/audit-system-integrity.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit System Integrity
diff --git a/windows/security/threat-protection/auditing/audit-user-account-management.md b/windows/security/threat-protection/auditing/audit-user-account-management.md
index 7efa2301e3..2faba55a60 100644
--- a/windows/security/threat-protection/auditing/audit-user-account-management.md
+++ b/windows/security/threat-protection/auditing/audit-user-account-management.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit User Account Management
diff --git a/windows/security/threat-protection/auditing/audit-user-device-claims.md b/windows/security/threat-protection/auditing/audit-user-device-claims.md
index 750c5568ca..e22930f47a 100644
--- a/windows/security/threat-protection/auditing/audit-user-device-claims.md
+++ b/windows/security/threat-protection/auditing/audit-user-device-claims.md
@@ -13,6 +13,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/06/2021
ms.technology: itpro-security
+ms.topic: reference
---
# Audit User/Device Claims
diff --git a/windows/security/threat-protection/auditing/event-1100.md b/windows/security/threat-protection/auditing/event-1100.md
index b5e2bfaf89..b0606e87da 100644
--- a/windows/security/threat-protection/auditing/event-1100.md
+++ b/windows/security/threat-protection/auditing/event-1100.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 1100(S): The event logging service has shut down.
diff --git a/windows/security/threat-protection/auditing/event-1102.md b/windows/security/threat-protection/auditing/event-1102.md
index 3da9fc2a33..c319070f2a 100644
--- a/windows/security/threat-protection/auditing/event-1102.md
+++ b/windows/security/threat-protection/auditing/event-1102.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 1102(S): The audit log was cleared.
diff --git a/windows/security/threat-protection/auditing/event-1104.md b/windows/security/threat-protection/auditing/event-1104.md
index 71e08f1f79..7768b7a43a 100644
--- a/windows/security/threat-protection/auditing/event-1104.md
+++ b/windows/security/threat-protection/auditing/event-1104.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 1104(S): The security log is now full.
diff --git a/windows/security/threat-protection/auditing/event-1105.md b/windows/security/threat-protection/auditing/event-1105.md
index 6eea66a2d6..2c10dd205e 100644
--- a/windows/security/threat-protection/auditing/event-1105.md
+++ b/windows/security/threat-protection/auditing/event-1105.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 1105(S): Event log automatic backup
diff --git a/windows/security/threat-protection/auditing/event-1108.md b/windows/security/threat-protection/auditing/event-1108.md
index 3ef547a322..3412104704 100644
--- a/windows/security/threat-protection/auditing/event-1108.md
+++ b/windows/security/threat-protection/auditing/event-1108.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 1108(S): The event logging service encountered an error while processing an incoming event published from %1.
diff --git a/windows/security/threat-protection/auditing/event-4608.md b/windows/security/threat-protection/auditing/event-4608.md
index 51e0c51819..bbcb45e073 100644
--- a/windows/security/threat-protection/auditing/event-4608.md
+++ b/windows/security/threat-protection/auditing/event-4608.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4608(S): Windows is starting up.
diff --git a/windows/security/threat-protection/auditing/event-4610.md b/windows/security/threat-protection/auditing/event-4610.md
index cbb410b55d..2307a50732 100644
--- a/windows/security/threat-protection/auditing/event-4610.md
+++ b/windows/security/threat-protection/auditing/event-4610.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4610(S): An authentication package has been loaded by the Local Security Authority.
diff --git a/windows/security/threat-protection/auditing/event-4611.md b/windows/security/threat-protection/auditing/event-4611.md
index 0f4b7b7a55..54b57cc223 100644
--- a/windows/security/threat-protection/auditing/event-4611.md
+++ b/windows/security/threat-protection/auditing/event-4611.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4611(S): A trusted logon process has been registered with the Local Security Authority.
diff --git a/windows/security/threat-protection/auditing/event-4612.md b/windows/security/threat-protection/auditing/event-4612.md
index 15ba866bce..111fa80c83 100644
--- a/windows/security/threat-protection/auditing/event-4612.md
+++ b/windows/security/threat-protection/auditing/event-4612.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4612(S): Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits.
diff --git a/windows/security/threat-protection/auditing/event-4614.md b/windows/security/threat-protection/auditing/event-4614.md
index 1dbbdeeefe..edb915b91d 100644
--- a/windows/security/threat-protection/auditing/event-4614.md
+++ b/windows/security/threat-protection/auditing/event-4614.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4614(S): A notification package has been loaded by the Security Account Manager.
diff --git a/windows/security/threat-protection/auditing/event-4615.md b/windows/security/threat-protection/auditing/event-4615.md
index d3cd763690..f74209909e 100644
--- a/windows/security/threat-protection/auditing/event-4615.md
+++ b/windows/security/threat-protection/auditing/event-4615.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4615(S): Invalid use of LPC port.
diff --git a/windows/security/threat-protection/auditing/event-4616.md b/windows/security/threat-protection/auditing/event-4616.md
index dfd4eb58db..166b695ebb 100644
--- a/windows/security/threat-protection/auditing/event-4616.md
+++ b/windows/security/threat-protection/auditing/event-4616.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4616(S): The system time was changed.
diff --git a/windows/security/threat-protection/auditing/event-4618.md b/windows/security/threat-protection/auditing/event-4618.md
index dcbe79c3ac..f35815a20c 100644
--- a/windows/security/threat-protection/auditing/event-4618.md
+++ b/windows/security/threat-protection/auditing/event-4618.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4618(S): A monitored security event pattern has occurred.
diff --git a/windows/security/threat-protection/auditing/event-4621.md b/windows/security/threat-protection/auditing/event-4621.md
index 8d85ca11c8..64e4f81134 100644
--- a/windows/security/threat-protection/auditing/event-4621.md
+++ b/windows/security/threat-protection/auditing/event-4621.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4621(S): Administrator recovered system from CrashOnAuditFail.
diff --git a/windows/security/threat-protection/auditing/event-4622.md b/windows/security/threat-protection/auditing/event-4622.md
index b4d338e351..5dc147c077 100644
--- a/windows/security/threat-protection/auditing/event-4622.md
+++ b/windows/security/threat-protection/auditing/event-4622.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4622(S): A security package has been loaded by the Local Security Authority.
diff --git a/windows/security/threat-protection/auditing/event-4624.md b/windows/security/threat-protection/auditing/event-4624.md
index 9a2a4e5b64..d505b5d9ef 100644
--- a/windows/security/threat-protection/auditing/event-4624.md
+++ b/windows/security/threat-protection/auditing/event-4624.md
@@ -14,6 +14,7 @@ ms.author: vinpa
ms.technology: itpro-security
ms.collection:
- highpri
+ms.topic: reference
---
# 4624(S): An account was successfully logged on.
diff --git a/windows/security/threat-protection/auditing/event-4625.md b/windows/security/threat-protection/auditing/event-4625.md
index 8030b3d479..81657a6361 100644
--- a/windows/security/threat-protection/auditing/event-4625.md
+++ b/windows/security/threat-protection/auditing/event-4625.md
@@ -14,6 +14,7 @@ ms.author: vinpa
ms.technology: itpro-security
ms.collection:
- highpri
+ms.topic: reference
---
# 4625(F): An account failed to log on.
diff --git a/windows/security/threat-protection/auditing/event-4626.md b/windows/security/threat-protection/auditing/event-4626.md
index d855d40847..addb26abce 100644
--- a/windows/security/threat-protection/auditing/event-4626.md
+++ b/windows/security/threat-protection/auditing/event-4626.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4626(S): User/Device claims information.
diff --git a/windows/security/threat-protection/auditing/event-4627.md b/windows/security/threat-protection/auditing/event-4627.md
index b86dcd5739..0da1f08aee 100644
--- a/windows/security/threat-protection/auditing/event-4627.md
+++ b/windows/security/threat-protection/auditing/event-4627.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4627(S): Group membership information.
diff --git a/windows/security/threat-protection/auditing/event-4634.md b/windows/security/threat-protection/auditing/event-4634.md
index 467dedd19f..6d8ed22539 100644
--- a/windows/security/threat-protection/auditing/event-4634.md
+++ b/windows/security/threat-protection/auditing/event-4634.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4634(S): An account was logged off.
diff --git a/windows/security/threat-protection/auditing/event-4647.md b/windows/security/threat-protection/auditing/event-4647.md
index 9ff4d6507e..64c7e02466 100644
--- a/windows/security/threat-protection/auditing/event-4647.md
+++ b/windows/security/threat-protection/auditing/event-4647.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4647(S): User initiated logoff.
diff --git a/windows/security/threat-protection/auditing/event-4648.md b/windows/security/threat-protection/auditing/event-4648.md
index b0cab6c7cd..5ffebb9c04 100644
--- a/windows/security/threat-protection/auditing/event-4648.md
+++ b/windows/security/threat-protection/auditing/event-4648.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4648(S): A logon was attempted using explicit credentials.
diff --git a/windows/security/threat-protection/auditing/event-4649.md b/windows/security/threat-protection/auditing/event-4649.md
index 4447ed9ef5..98a1c9ad18 100644
--- a/windows/security/threat-protection/auditing/event-4649.md
+++ b/windows/security/threat-protection/auditing/event-4649.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4649(S): A replay attack was detected.
diff --git a/windows/security/threat-protection/auditing/event-4656.md b/windows/security/threat-protection/auditing/event-4656.md
index 4f9aa3d55a..7d974fa3fa 100644
--- a/windows/security/threat-protection/auditing/event-4656.md
+++ b/windows/security/threat-protection/auditing/event-4656.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4656(S, F): A handle to an object was requested.
diff --git a/windows/security/threat-protection/auditing/event-4657.md b/windows/security/threat-protection/auditing/event-4657.md
index fbe96e603d..cb4ecc3ae1 100644
--- a/windows/security/threat-protection/auditing/event-4657.md
+++ b/windows/security/threat-protection/auditing/event-4657.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4657(S): A registry value was modified.
diff --git a/windows/security/threat-protection/auditing/event-4658.md b/windows/security/threat-protection/auditing/event-4658.md
index c577dd8cb1..532558cd00 100644
--- a/windows/security/threat-protection/auditing/event-4658.md
+++ b/windows/security/threat-protection/auditing/event-4658.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4658(S): The handle to an object was closed.
diff --git a/windows/security/threat-protection/auditing/event-4660.md b/windows/security/threat-protection/auditing/event-4660.md
index 52e57a1502..b0124437c6 100644
--- a/windows/security/threat-protection/auditing/event-4660.md
+++ b/windows/security/threat-protection/auditing/event-4660.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4660(S): An object was deleted.
diff --git a/windows/security/threat-protection/auditing/event-4661.md b/windows/security/threat-protection/auditing/event-4661.md
index bf8b9b0543..383989f443 100644
--- a/windows/security/threat-protection/auditing/event-4661.md
+++ b/windows/security/threat-protection/auditing/event-4661.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4661(S, F): A handle to an object was requested.
diff --git a/windows/security/threat-protection/auditing/event-4662.md b/windows/security/threat-protection/auditing/event-4662.md
index cdc37e9ac3..cf19827489 100644
--- a/windows/security/threat-protection/auditing/event-4662.md
+++ b/windows/security/threat-protection/auditing/event-4662.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4662(S, F): An operation was performed on an object.
diff --git a/windows/security/threat-protection/auditing/event-4663.md b/windows/security/threat-protection/auditing/event-4663.md
index e92604294e..cf790af491 100644
--- a/windows/security/threat-protection/auditing/event-4663.md
+++ b/windows/security/threat-protection/auditing/event-4663.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4663(S): An attempt was made to access an object.
diff --git a/windows/security/threat-protection/auditing/event-4664.md b/windows/security/threat-protection/auditing/event-4664.md
index 5d20d8cbda..0a27e27f7d 100644
--- a/windows/security/threat-protection/auditing/event-4664.md
+++ b/windows/security/threat-protection/auditing/event-4664.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4664(S): An attempt was made to create a hard link.
diff --git a/windows/security/threat-protection/auditing/event-4670.md b/windows/security/threat-protection/auditing/event-4670.md
index 1775901f8b..9509f490e5 100644
--- a/windows/security/threat-protection/auditing/event-4670.md
+++ b/windows/security/threat-protection/auditing/event-4670.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4670(S): Permissions on an object were changed.
diff --git a/windows/security/threat-protection/auditing/event-4671.md b/windows/security/threat-protection/auditing/event-4671.md
index 7a1ee6965a..3215da12d8 100644
--- a/windows/security/threat-protection/auditing/event-4671.md
+++ b/windows/security/threat-protection/auditing/event-4671.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4671(-): An application attempted to access a blocked ordinal through the TBS.
diff --git a/windows/security/threat-protection/auditing/event-4672.md b/windows/security/threat-protection/auditing/event-4672.md
index 25a4365bb7..3b61e352a2 100644
--- a/windows/security/threat-protection/auditing/event-4672.md
+++ b/windows/security/threat-protection/auditing/event-4672.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4672(S): Special privileges assigned to new logon.
diff --git a/windows/security/threat-protection/auditing/event-4673.md b/windows/security/threat-protection/auditing/event-4673.md
index e4ba4b8a01..e63486e9fa 100644
--- a/windows/security/threat-protection/auditing/event-4673.md
+++ b/windows/security/threat-protection/auditing/event-4673.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4673(S, F): A privileged service was called.
diff --git a/windows/security/threat-protection/auditing/event-4674.md b/windows/security/threat-protection/auditing/event-4674.md
index 09b8e8a50e..11f8c3fb62 100644
--- a/windows/security/threat-protection/auditing/event-4674.md
+++ b/windows/security/threat-protection/auditing/event-4674.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4674(S, F): An operation was attempted on a privileged object.
diff --git a/windows/security/threat-protection/auditing/event-4675.md b/windows/security/threat-protection/auditing/event-4675.md
index 8a6b84b8e9..6daf08eef3 100644
--- a/windows/security/threat-protection/auditing/event-4675.md
+++ b/windows/security/threat-protection/auditing/event-4675.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4675(S): SIDs were filtered.
diff --git a/windows/security/threat-protection/auditing/event-4688.md b/windows/security/threat-protection/auditing/event-4688.md
index 2416040af7..5742fbd554 100644
--- a/windows/security/threat-protection/auditing/event-4688.md
+++ b/windows/security/threat-protection/auditing/event-4688.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4688(S): A new process has been created. (Windows 10)
diff --git a/windows/security/threat-protection/auditing/event-4689.md b/windows/security/threat-protection/auditing/event-4689.md
index e64fd85f5a..f2014c9a1e 100644
--- a/windows/security/threat-protection/auditing/event-4689.md
+++ b/windows/security/threat-protection/auditing/event-4689.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4689(S): A process has exited.
diff --git a/windows/security/threat-protection/auditing/event-4690.md b/windows/security/threat-protection/auditing/event-4690.md
index 25c57686e5..e0b54b2afe 100644
--- a/windows/security/threat-protection/auditing/event-4690.md
+++ b/windows/security/threat-protection/auditing/event-4690.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4690(S): An attempt was made to duplicate a handle to an object.
diff --git a/windows/security/threat-protection/auditing/event-4691.md b/windows/security/threat-protection/auditing/event-4691.md
index 140889746d..62f92ce75d 100644
--- a/windows/security/threat-protection/auditing/event-4691.md
+++ b/windows/security/threat-protection/auditing/event-4691.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4691(S): Indirect access to an object was requested.
diff --git a/windows/security/threat-protection/auditing/event-4692.md b/windows/security/threat-protection/auditing/event-4692.md
index ac9b7268ca..fb56e8e4c9 100644
--- a/windows/security/threat-protection/auditing/event-4692.md
+++ b/windows/security/threat-protection/auditing/event-4692.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4692(S, F): Backup of data protection master key was attempted.
diff --git a/windows/security/threat-protection/auditing/event-4693.md b/windows/security/threat-protection/auditing/event-4693.md
index 219798f08e..bd99d76424 100644
--- a/windows/security/threat-protection/auditing/event-4693.md
+++ b/windows/security/threat-protection/auditing/event-4693.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4693(S, F): Recovery of data protection master key was attempted.
diff --git a/windows/security/threat-protection/auditing/event-4694.md b/windows/security/threat-protection/auditing/event-4694.md
index dc24a37fc9..f66fb36e4d 100644
--- a/windows/security/threat-protection/auditing/event-4694.md
+++ b/windows/security/threat-protection/auditing/event-4694.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4694(S, F): Protection of auditable protected data was attempted.
diff --git a/windows/security/threat-protection/auditing/event-4695.md b/windows/security/threat-protection/auditing/event-4695.md
index 78c1b43834..68c0ac644a 100644
--- a/windows/security/threat-protection/auditing/event-4695.md
+++ b/windows/security/threat-protection/auditing/event-4695.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4695(S, F): Unprotection of auditable protected data was attempted.
diff --git a/windows/security/threat-protection/auditing/event-4696.md b/windows/security/threat-protection/auditing/event-4696.md
index 16c7a8e333..fc3d8432ee 100644
--- a/windows/security/threat-protection/auditing/event-4696.md
+++ b/windows/security/threat-protection/auditing/event-4696.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4696(S): A primary token was assigned to process.
diff --git a/windows/security/threat-protection/auditing/event-4697.md b/windows/security/threat-protection/auditing/event-4697.md
index 348ae3a7a9..5d1072f99b 100644
--- a/windows/security/threat-protection/auditing/event-4697.md
+++ b/windows/security/threat-protection/auditing/event-4697.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4697(S): A service was installed in the system.
diff --git a/windows/security/threat-protection/auditing/event-4698.md b/windows/security/threat-protection/auditing/event-4698.md
index 7eb2d41a68..cfbe0e3f96 100644
--- a/windows/security/threat-protection/auditing/event-4698.md
+++ b/windows/security/threat-protection/auditing/event-4698.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4698(S): A scheduled task was created.
diff --git a/windows/security/threat-protection/auditing/event-4699.md b/windows/security/threat-protection/auditing/event-4699.md
index 258b0a31d3..56935a1da0 100644
--- a/windows/security/threat-protection/auditing/event-4699.md
+++ b/windows/security/threat-protection/auditing/event-4699.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4699(S): A scheduled task was deleted.
diff --git a/windows/security/threat-protection/auditing/event-4700.md b/windows/security/threat-protection/auditing/event-4700.md
index aa1ef1cc10..3c45c92cf4 100644
--- a/windows/security/threat-protection/auditing/event-4700.md
+++ b/windows/security/threat-protection/auditing/event-4700.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4700(S): A scheduled task was enabled.
diff --git a/windows/security/threat-protection/auditing/event-4701.md b/windows/security/threat-protection/auditing/event-4701.md
index 11a6147179..0a9639837b 100644
--- a/windows/security/threat-protection/auditing/event-4701.md
+++ b/windows/security/threat-protection/auditing/event-4701.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4701(S): A scheduled task was disabled.
diff --git a/windows/security/threat-protection/auditing/event-4702.md b/windows/security/threat-protection/auditing/event-4702.md
index a738b7753e..96c7f0b93b 100644
--- a/windows/security/threat-protection/auditing/event-4702.md
+++ b/windows/security/threat-protection/auditing/event-4702.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4702(S): A scheduled task was updated.
diff --git a/windows/security/threat-protection/auditing/event-4703.md b/windows/security/threat-protection/auditing/event-4703.md
index b4571317fc..f10d935aa1 100644
--- a/windows/security/threat-protection/auditing/event-4703.md
+++ b/windows/security/threat-protection/auditing/event-4703.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4703(S): A user right was adjusted.
diff --git a/windows/security/threat-protection/auditing/event-4704.md b/windows/security/threat-protection/auditing/event-4704.md
index 0780690284..4b0b4ef478 100644
--- a/windows/security/threat-protection/auditing/event-4704.md
+++ b/windows/security/threat-protection/auditing/event-4704.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4704(S): A user right was assigned.
diff --git a/windows/security/threat-protection/auditing/event-4705.md b/windows/security/threat-protection/auditing/event-4705.md
index afd7149169..c66295ce0d 100644
--- a/windows/security/threat-protection/auditing/event-4705.md
+++ b/windows/security/threat-protection/auditing/event-4705.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4705(S): A user right was removed.
diff --git a/windows/security/threat-protection/auditing/event-4706.md b/windows/security/threat-protection/auditing/event-4706.md
index c6ff0bb373..01ce8db4cd 100644
--- a/windows/security/threat-protection/auditing/event-4706.md
+++ b/windows/security/threat-protection/auditing/event-4706.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4706(S): A new trust was created to a domain.
diff --git a/windows/security/threat-protection/auditing/event-4707.md b/windows/security/threat-protection/auditing/event-4707.md
index 28b13b2cb0..a47a9ea3ea 100644
--- a/windows/security/threat-protection/auditing/event-4707.md
+++ b/windows/security/threat-protection/auditing/event-4707.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4707(S): A trust to a domain was removed.
diff --git a/windows/security/threat-protection/auditing/event-4713.md b/windows/security/threat-protection/auditing/event-4713.md
index e92aa50675..218134046e 100644
--- a/windows/security/threat-protection/auditing/event-4713.md
+++ b/windows/security/threat-protection/auditing/event-4713.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4713(S): Kerberos policy was changed.
diff --git a/windows/security/threat-protection/auditing/event-4714.md b/windows/security/threat-protection/auditing/event-4714.md
index 77709fc5c7..fc40a49c6e 100644
--- a/windows/security/threat-protection/auditing/event-4714.md
+++ b/windows/security/threat-protection/auditing/event-4714.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4714(S): Encrypted data recovery policy was changed.
diff --git a/windows/security/threat-protection/auditing/event-4715.md b/windows/security/threat-protection/auditing/event-4715.md
index 82b24bae92..f128397767 100644
--- a/windows/security/threat-protection/auditing/event-4715.md
+++ b/windows/security/threat-protection/auditing/event-4715.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4715(S): The audit policy (SACL) on an object was changed.
diff --git a/windows/security/threat-protection/auditing/event-4716.md b/windows/security/threat-protection/auditing/event-4716.md
index f6d57fece2..64f3140ad0 100644
--- a/windows/security/threat-protection/auditing/event-4716.md
+++ b/windows/security/threat-protection/auditing/event-4716.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4716(S): Trusted domain information was modified.
diff --git a/windows/security/threat-protection/auditing/event-4717.md b/windows/security/threat-protection/auditing/event-4717.md
index dc449a8758..8a1f14e022 100644
--- a/windows/security/threat-protection/auditing/event-4717.md
+++ b/windows/security/threat-protection/auditing/event-4717.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4717(S): System security access was granted to an account.
diff --git a/windows/security/threat-protection/auditing/event-4718.md b/windows/security/threat-protection/auditing/event-4718.md
index 7a47fa5d37..e8ec6b8039 100644
--- a/windows/security/threat-protection/auditing/event-4718.md
+++ b/windows/security/threat-protection/auditing/event-4718.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4718(S): System security access was removed from an account.
diff --git a/windows/security/threat-protection/auditing/event-4719.md b/windows/security/threat-protection/auditing/event-4719.md
index 97711ffdf7..dae615acf4 100644
--- a/windows/security/threat-protection/auditing/event-4719.md
+++ b/windows/security/threat-protection/auditing/event-4719.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4719(S): System audit policy was changed.
diff --git a/windows/security/threat-protection/auditing/event-4720.md b/windows/security/threat-protection/auditing/event-4720.md
index bb732fd1dd..b53966664d 100644
--- a/windows/security/threat-protection/auditing/event-4720.md
+++ b/windows/security/threat-protection/auditing/event-4720.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4720(S): A user account was created.
diff --git a/windows/security/threat-protection/auditing/event-4722.md b/windows/security/threat-protection/auditing/event-4722.md
index 1d82961714..4388873aa0 100644
--- a/windows/security/threat-protection/auditing/event-4722.md
+++ b/windows/security/threat-protection/auditing/event-4722.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4722(S): A user account was enabled.
diff --git a/windows/security/threat-protection/auditing/event-4723.md b/windows/security/threat-protection/auditing/event-4723.md
index f63004d706..8b8b7975a1 100644
--- a/windows/security/threat-protection/auditing/event-4723.md
+++ b/windows/security/threat-protection/auditing/event-4723.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4723(S, F): An attempt was made to change an account's password.
diff --git a/windows/security/threat-protection/auditing/event-4724.md b/windows/security/threat-protection/auditing/event-4724.md
index a36b61acac..00c98b63e4 100644
--- a/windows/security/threat-protection/auditing/event-4724.md
+++ b/windows/security/threat-protection/auditing/event-4724.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4724(S, F): An attempt was made to reset an account's password.
diff --git a/windows/security/threat-protection/auditing/event-4725.md b/windows/security/threat-protection/auditing/event-4725.md
index 731fa570ad..ad5b546a6d 100644
--- a/windows/security/threat-protection/auditing/event-4725.md
+++ b/windows/security/threat-protection/auditing/event-4725.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4725(S): A user account was disabled.
diff --git a/windows/security/threat-protection/auditing/event-4726.md b/windows/security/threat-protection/auditing/event-4726.md
index 620ba8bbeb..7df0779c4a 100644
--- a/windows/security/threat-protection/auditing/event-4726.md
+++ b/windows/security/threat-protection/auditing/event-4726.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4726(S): A user account was deleted.
diff --git a/windows/security/threat-protection/auditing/event-4731.md b/windows/security/threat-protection/auditing/event-4731.md
index 39426b84ac..ca1c673af4 100644
--- a/windows/security/threat-protection/auditing/event-4731.md
+++ b/windows/security/threat-protection/auditing/event-4731.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4731(S): A security-enabled local group was created.
diff --git a/windows/security/threat-protection/auditing/event-4732.md b/windows/security/threat-protection/auditing/event-4732.md
index e68eecbb3d..8afb300906 100644
--- a/windows/security/threat-protection/auditing/event-4732.md
+++ b/windows/security/threat-protection/auditing/event-4732.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4732(S): A member was added to a security-enabled local group.
diff --git a/windows/security/threat-protection/auditing/event-4733.md b/windows/security/threat-protection/auditing/event-4733.md
index b3dcf94109..3a24b2ef0f 100644
--- a/windows/security/threat-protection/auditing/event-4733.md
+++ b/windows/security/threat-protection/auditing/event-4733.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4733(S): A member was removed from a security-enabled local group.
diff --git a/windows/security/threat-protection/auditing/event-4734.md b/windows/security/threat-protection/auditing/event-4734.md
index 2f83cfa9a5..ac2c5d7b93 100644
--- a/windows/security/threat-protection/auditing/event-4734.md
+++ b/windows/security/threat-protection/auditing/event-4734.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4734(S): A security-enabled local group was deleted.
diff --git a/windows/security/threat-protection/auditing/event-4735.md b/windows/security/threat-protection/auditing/event-4735.md
index f590b87f44..4842263179 100644
--- a/windows/security/threat-protection/auditing/event-4735.md
+++ b/windows/security/threat-protection/auditing/event-4735.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4735(S): A security-enabled local group was changed.
diff --git a/windows/security/threat-protection/auditing/event-4738.md b/windows/security/threat-protection/auditing/event-4738.md
index ef5a72da75..63352ed67e 100644
--- a/windows/security/threat-protection/auditing/event-4738.md
+++ b/windows/security/threat-protection/auditing/event-4738.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4738(S): A user account was changed.
diff --git a/windows/security/threat-protection/auditing/event-4739.md b/windows/security/threat-protection/auditing/event-4739.md
index 4ecbfdf064..d43bdb27e2 100644
--- a/windows/security/threat-protection/auditing/event-4739.md
+++ b/windows/security/threat-protection/auditing/event-4739.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4739(S): Domain Policy was changed.
diff --git a/windows/security/threat-protection/auditing/event-4740.md b/windows/security/threat-protection/auditing/event-4740.md
index 63c75713f7..46c0cdcb9d 100644
--- a/windows/security/threat-protection/auditing/event-4740.md
+++ b/windows/security/threat-protection/auditing/event-4740.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4740(S): A user account was locked out.
diff --git a/windows/security/threat-protection/auditing/event-4741.md b/windows/security/threat-protection/auditing/event-4741.md
index 0152e427a6..5245280f11 100644
--- a/windows/security/threat-protection/auditing/event-4741.md
+++ b/windows/security/threat-protection/auditing/event-4741.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4741(S): A computer account was created.
diff --git a/windows/security/threat-protection/auditing/event-4742.md b/windows/security/threat-protection/auditing/event-4742.md
index de51f96421..3f5f9c2eb6 100644
--- a/windows/security/threat-protection/auditing/event-4742.md
+++ b/windows/security/threat-protection/auditing/event-4742.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4742(S): A computer account was changed.
diff --git a/windows/security/threat-protection/auditing/event-4743.md b/windows/security/threat-protection/auditing/event-4743.md
index cfa007a9b7..50411689a9 100644
--- a/windows/security/threat-protection/auditing/event-4743.md
+++ b/windows/security/threat-protection/auditing/event-4743.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4743(S): A computer account was deleted.
diff --git a/windows/security/threat-protection/auditing/event-4749.md b/windows/security/threat-protection/auditing/event-4749.md
index f49d9f6c7c..8293c95b2b 100644
--- a/windows/security/threat-protection/auditing/event-4749.md
+++ b/windows/security/threat-protection/auditing/event-4749.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4749(S): A security-disabled global group was created.
diff --git a/windows/security/threat-protection/auditing/event-4750.md b/windows/security/threat-protection/auditing/event-4750.md
index aa3be8fba0..d106e10077 100644
--- a/windows/security/threat-protection/auditing/event-4750.md
+++ b/windows/security/threat-protection/auditing/event-4750.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4750(S): A security-disabled global group was changed.
diff --git a/windows/security/threat-protection/auditing/event-4751.md b/windows/security/threat-protection/auditing/event-4751.md
index fdd8a37fcc..e3bdca780e 100644
--- a/windows/security/threat-protection/auditing/event-4751.md
+++ b/windows/security/threat-protection/auditing/event-4751.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4751(S): A member was added to a security-disabled global group.
diff --git a/windows/security/threat-protection/auditing/event-4752.md b/windows/security/threat-protection/auditing/event-4752.md
index d49e422f9e..f6b4fc37dd 100644
--- a/windows/security/threat-protection/auditing/event-4752.md
+++ b/windows/security/threat-protection/auditing/event-4752.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4752(S): A member was removed from a security-disabled global group.
diff --git a/windows/security/threat-protection/auditing/event-4753.md b/windows/security/threat-protection/auditing/event-4753.md
index b5f941a040..6bdf28a86b 100644
--- a/windows/security/threat-protection/auditing/event-4753.md
+++ b/windows/security/threat-protection/auditing/event-4753.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4753(S): A security-disabled global group was deleted.
diff --git a/windows/security/threat-protection/auditing/event-4764.md b/windows/security/threat-protection/auditing/event-4764.md
index 85824b3df3..f959fc103a 100644
--- a/windows/security/threat-protection/auditing/event-4764.md
+++ b/windows/security/threat-protection/auditing/event-4764.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4764(S): A group’s type was changed.
diff --git a/windows/security/threat-protection/auditing/event-4765.md b/windows/security/threat-protection/auditing/event-4765.md
index cf78144c6a..5789319e57 100644
--- a/windows/security/threat-protection/auditing/event-4765.md
+++ b/windows/security/threat-protection/auditing/event-4765.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4765(S): SID History was added to an account.
diff --git a/windows/security/threat-protection/auditing/event-4766.md b/windows/security/threat-protection/auditing/event-4766.md
index 4178c53a80..4d0ec7ae25 100644
--- a/windows/security/threat-protection/auditing/event-4766.md
+++ b/windows/security/threat-protection/auditing/event-4766.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4766(F): An attempt to add SID History to an account failed.
diff --git a/windows/security/threat-protection/auditing/event-4767.md b/windows/security/threat-protection/auditing/event-4767.md
index 21beb6c3ec..9dbf921ebf 100644
--- a/windows/security/threat-protection/auditing/event-4767.md
+++ b/windows/security/threat-protection/auditing/event-4767.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4767(S): A user account was unlocked.
diff --git a/windows/security/threat-protection/auditing/event-4768.md b/windows/security/threat-protection/auditing/event-4768.md
index 1eded19698..936074fc72 100644
--- a/windows/security/threat-protection/auditing/event-4768.md
+++ b/windows/security/threat-protection/auditing/event-4768.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4768(S, F): A Kerberos authentication ticket (TGT) was requested.
diff --git a/windows/security/threat-protection/auditing/event-4769.md b/windows/security/threat-protection/auditing/event-4769.md
index bcf3312248..e82434467c 100644
--- a/windows/security/threat-protection/auditing/event-4769.md
+++ b/windows/security/threat-protection/auditing/event-4769.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4769(S, F): A Kerberos service ticket was requested.
diff --git a/windows/security/threat-protection/auditing/event-4770.md b/windows/security/threat-protection/auditing/event-4770.md
index b24835b3ba..2027d8504f 100644
--- a/windows/security/threat-protection/auditing/event-4770.md
+++ b/windows/security/threat-protection/auditing/event-4770.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4770(S): A Kerberos service ticket was renewed.
diff --git a/windows/security/threat-protection/auditing/event-4771.md b/windows/security/threat-protection/auditing/event-4771.md
index 0d4c72e45f..3ca1095e98 100644
--- a/windows/security/threat-protection/auditing/event-4771.md
+++ b/windows/security/threat-protection/auditing/event-4771.md
@@ -14,6 +14,7 @@ ms.author: vinpa
ms.technology: itpro-security
ms.collection:
- highpri
+ms.topic: reference
---
# 4771(F): Kerberos pre-authentication failed.
diff --git a/windows/security/threat-protection/auditing/event-4772.md b/windows/security/threat-protection/auditing/event-4772.md
index 54fdd53057..3c378ccc0b 100644
--- a/windows/security/threat-protection/auditing/event-4772.md
+++ b/windows/security/threat-protection/auditing/event-4772.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4772(F): A Kerberos authentication ticket request failed.
diff --git a/windows/security/threat-protection/auditing/event-4773.md b/windows/security/threat-protection/auditing/event-4773.md
index e3ad7e5b20..30c32b9f8d 100644
--- a/windows/security/threat-protection/auditing/event-4773.md
+++ b/windows/security/threat-protection/auditing/event-4773.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4773(F): A Kerberos service ticket request failed.
diff --git a/windows/security/threat-protection/auditing/event-4774.md b/windows/security/threat-protection/auditing/event-4774.md
index 4cf831e05b..2f9b37c352 100644
--- a/windows/security/threat-protection/auditing/event-4774.md
+++ b/windows/security/threat-protection/auditing/event-4774.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4774(S, F): An account was mapped for logon
diff --git a/windows/security/threat-protection/auditing/event-4775.md b/windows/security/threat-protection/auditing/event-4775.md
index 285efe300f..8281bb27e5 100644
--- a/windows/security/threat-protection/auditing/event-4775.md
+++ b/windows/security/threat-protection/auditing/event-4775.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4775(F): An account could not be mapped for logon.
diff --git a/windows/security/threat-protection/auditing/event-4776.md b/windows/security/threat-protection/auditing/event-4776.md
index cebb01a7c7..e411b647ce 100644
--- a/windows/security/threat-protection/auditing/event-4776.md
+++ b/windows/security/threat-protection/auditing/event-4776.md
@@ -14,6 +14,7 @@ ms.author: vinpa
ms.technology: itpro-security
ms.collection:
- highpri
+ms.topic: reference
---
# 4776(S, F): The computer attempted to validate the credentials for an account.
diff --git a/windows/security/threat-protection/auditing/event-4777.md b/windows/security/threat-protection/auditing/event-4777.md
index 21749ac3ac..e534dbee25 100644
--- a/windows/security/threat-protection/auditing/event-4777.md
+++ b/windows/security/threat-protection/auditing/event-4777.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4777(F): The domain controller failed to validate the credentials for an account.
diff --git a/windows/security/threat-protection/auditing/event-4778.md b/windows/security/threat-protection/auditing/event-4778.md
index f9f3175763..76aac3738e 100644
--- a/windows/security/threat-protection/auditing/event-4778.md
+++ b/windows/security/threat-protection/auditing/event-4778.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4778(S): A session was reconnected to a Window Station.
diff --git a/windows/security/threat-protection/auditing/event-4779.md b/windows/security/threat-protection/auditing/event-4779.md
index 4edf0f6668..7f6568c1cb 100644
--- a/windows/security/threat-protection/auditing/event-4779.md
+++ b/windows/security/threat-protection/auditing/event-4779.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4779(S): A session was disconnected from a Window Station.
diff --git a/windows/security/threat-protection/auditing/event-4780.md b/windows/security/threat-protection/auditing/event-4780.md
index 982fa983de..5195929a0e 100644
--- a/windows/security/threat-protection/auditing/event-4780.md
+++ b/windows/security/threat-protection/auditing/event-4780.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4780(S): The ACL was set on accounts which are members of administrators groups.
diff --git a/windows/security/threat-protection/auditing/event-4781.md b/windows/security/threat-protection/auditing/event-4781.md
index 856cd7cb4b..fc2aaffc53 100644
--- a/windows/security/threat-protection/auditing/event-4781.md
+++ b/windows/security/threat-protection/auditing/event-4781.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4781(S): The name of an account was changed.
diff --git a/windows/security/threat-protection/auditing/event-4782.md b/windows/security/threat-protection/auditing/event-4782.md
index 3a6d312600..a0615135c6 100644
--- a/windows/security/threat-protection/auditing/event-4782.md
+++ b/windows/security/threat-protection/auditing/event-4782.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4782(S): The password hash of an account was accessed.
diff --git a/windows/security/threat-protection/auditing/event-4793.md b/windows/security/threat-protection/auditing/event-4793.md
index 7c64bea4eb..cc197ccb60 100644
--- a/windows/security/threat-protection/auditing/event-4793.md
+++ b/windows/security/threat-protection/auditing/event-4793.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4793(S): The Password Policy Checking API was called.
diff --git a/windows/security/threat-protection/auditing/event-4794.md b/windows/security/threat-protection/auditing/event-4794.md
index 8519e79e9d..6bcb12e02c 100644
--- a/windows/security/threat-protection/auditing/event-4794.md
+++ b/windows/security/threat-protection/auditing/event-4794.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4794(S, F): An attempt was made to set the Directory Services Restore Mode administrator password.
diff --git a/windows/security/threat-protection/auditing/event-4798.md b/windows/security/threat-protection/auditing/event-4798.md
index 396f15d0b2..696366f22d 100644
--- a/windows/security/threat-protection/auditing/event-4798.md
+++ b/windows/security/threat-protection/auditing/event-4798.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4798(S): A user's local group membership was enumerated.
diff --git a/windows/security/threat-protection/auditing/event-4799.md b/windows/security/threat-protection/auditing/event-4799.md
index ad750b391e..1cf362be1d 100644
--- a/windows/security/threat-protection/auditing/event-4799.md
+++ b/windows/security/threat-protection/auditing/event-4799.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4799(S): A security-enabled local group membership was enumerated.
diff --git a/windows/security/threat-protection/auditing/event-4800.md b/windows/security/threat-protection/auditing/event-4800.md
index 87f46d5a18..89c94ade64 100644
--- a/windows/security/threat-protection/auditing/event-4800.md
+++ b/windows/security/threat-protection/auditing/event-4800.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4800(S): The workstation was locked.
diff --git a/windows/security/threat-protection/auditing/event-4801.md b/windows/security/threat-protection/auditing/event-4801.md
index f94c08e08f..906e46fcd3 100644
--- a/windows/security/threat-protection/auditing/event-4801.md
+++ b/windows/security/threat-protection/auditing/event-4801.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4801(S): The workstation was unlocked.
diff --git a/windows/security/threat-protection/auditing/event-4802.md b/windows/security/threat-protection/auditing/event-4802.md
index 6590d5bd4b..1b423f29ee 100644
--- a/windows/security/threat-protection/auditing/event-4802.md
+++ b/windows/security/threat-protection/auditing/event-4802.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4802(S): The screen saver was invoked.
diff --git a/windows/security/threat-protection/auditing/event-4803.md b/windows/security/threat-protection/auditing/event-4803.md
index 2c0e8d441b..247e3c704d 100644
--- a/windows/security/threat-protection/auditing/event-4803.md
+++ b/windows/security/threat-protection/auditing/event-4803.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4803(S): The screen saver was dismissed.
diff --git a/windows/security/threat-protection/auditing/event-4816.md b/windows/security/threat-protection/auditing/event-4816.md
index 8d61ef6f9a..8636e1abef 100644
--- a/windows/security/threat-protection/auditing/event-4816.md
+++ b/windows/security/threat-protection/auditing/event-4816.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4816(S): RPC detected an integrity violation while decrypting an incoming message.
diff --git a/windows/security/threat-protection/auditing/event-4817.md b/windows/security/threat-protection/auditing/event-4817.md
index 2cb3ae3794..ff20520062 100644
--- a/windows/security/threat-protection/auditing/event-4817.md
+++ b/windows/security/threat-protection/auditing/event-4817.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4817(S): Auditing settings on object were changed.
diff --git a/windows/security/threat-protection/auditing/event-4818.md b/windows/security/threat-protection/auditing/event-4818.md
index 25c2111bd2..c884c2e7a8 100644
--- a/windows/security/threat-protection/auditing/event-4818.md
+++ b/windows/security/threat-protection/auditing/event-4818.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4818(S): Proposed Central Access Policy does not grant the same access permissions as the current Central Access Policy.
diff --git a/windows/security/threat-protection/auditing/event-4819.md b/windows/security/threat-protection/auditing/event-4819.md
index 69743c28c7..e8bca4427e 100644
--- a/windows/security/threat-protection/auditing/event-4819.md
+++ b/windows/security/threat-protection/auditing/event-4819.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4819(S): Central Access Policies on the machine have been changed.
diff --git a/windows/security/threat-protection/auditing/event-4826.md b/windows/security/threat-protection/auditing/event-4826.md
index 914961945b..001e6c6026 100644
--- a/windows/security/threat-protection/auditing/event-4826.md
+++ b/windows/security/threat-protection/auditing/event-4826.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4826(S): Boot Configuration Data loaded.
diff --git a/windows/security/threat-protection/auditing/event-4864.md b/windows/security/threat-protection/auditing/event-4864.md
index e70836a75b..a26b552f4a 100644
--- a/windows/security/threat-protection/auditing/event-4864.md
+++ b/windows/security/threat-protection/auditing/event-4864.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4864(S): A namespace collision was detected.
diff --git a/windows/security/threat-protection/auditing/event-4865.md b/windows/security/threat-protection/auditing/event-4865.md
index 76624588fc..aa44c9bb6a 100644
--- a/windows/security/threat-protection/auditing/event-4865.md
+++ b/windows/security/threat-protection/auditing/event-4865.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4865(S): A trusted forest information entry was added.
diff --git a/windows/security/threat-protection/auditing/event-4866.md b/windows/security/threat-protection/auditing/event-4866.md
index 1e1b870506..1fcc07f446 100644
--- a/windows/security/threat-protection/auditing/event-4866.md
+++ b/windows/security/threat-protection/auditing/event-4866.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4866(S): A trusted forest information entry was removed.
diff --git a/windows/security/threat-protection/auditing/event-4867.md b/windows/security/threat-protection/auditing/event-4867.md
index 24063dad9d..ce30699bfa 100644
--- a/windows/security/threat-protection/auditing/event-4867.md
+++ b/windows/security/threat-protection/auditing/event-4867.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4867(S): A trusted forest information entry was modified.
diff --git a/windows/security/threat-protection/auditing/event-4902.md b/windows/security/threat-protection/auditing/event-4902.md
index 5b2a94af52..7185b9f3da 100644
--- a/windows/security/threat-protection/auditing/event-4902.md
+++ b/windows/security/threat-protection/auditing/event-4902.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4902(S): The Per-user audit policy table was created.
diff --git a/windows/security/threat-protection/auditing/event-4904.md b/windows/security/threat-protection/auditing/event-4904.md
index fd9ee497a2..90858c5844 100644
--- a/windows/security/threat-protection/auditing/event-4904.md
+++ b/windows/security/threat-protection/auditing/event-4904.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4904(S): An attempt was made to register a security event source.
diff --git a/windows/security/threat-protection/auditing/event-4905.md b/windows/security/threat-protection/auditing/event-4905.md
index c8ba9bb9c9..14eb6cfa8b 100644
--- a/windows/security/threat-protection/auditing/event-4905.md
+++ b/windows/security/threat-protection/auditing/event-4905.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4905(S): An attempt was made to unregister a security event source.
diff --git a/windows/security/threat-protection/auditing/event-4906.md b/windows/security/threat-protection/auditing/event-4906.md
index 4913d0d431..2058342aa0 100644
--- a/windows/security/threat-protection/auditing/event-4906.md
+++ b/windows/security/threat-protection/auditing/event-4906.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4906(S): The CrashOnAuditFail value has changed.
diff --git a/windows/security/threat-protection/auditing/event-4907.md b/windows/security/threat-protection/auditing/event-4907.md
index 70de13eecf..c38b66d51b 100644
--- a/windows/security/threat-protection/auditing/event-4907.md
+++ b/windows/security/threat-protection/auditing/event-4907.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4907(S): Auditing settings on object were changed.
diff --git a/windows/security/threat-protection/auditing/event-4908.md b/windows/security/threat-protection/auditing/event-4908.md
index b5351ecbd4..3314e94436 100644
--- a/windows/security/threat-protection/auditing/event-4908.md
+++ b/windows/security/threat-protection/auditing/event-4908.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4908(S): Special Groups Logon table modified.
diff --git a/windows/security/threat-protection/auditing/event-4909.md b/windows/security/threat-protection/auditing/event-4909.md
index ab35104b88..8a8631489a 100644
--- a/windows/security/threat-protection/auditing/event-4909.md
+++ b/windows/security/threat-protection/auditing/event-4909.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4909(-): The local policy settings for the TBS were changed.
diff --git a/windows/security/threat-protection/auditing/event-4910.md b/windows/security/threat-protection/auditing/event-4910.md
index 2e46e4e49e..15276f29ce 100644
--- a/windows/security/threat-protection/auditing/event-4910.md
+++ b/windows/security/threat-protection/auditing/event-4910.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4910(-): The group policy settings for the TBS were changed.
diff --git a/windows/security/threat-protection/auditing/event-4911.md b/windows/security/threat-protection/auditing/event-4911.md
index b72644a868..abc112dbb4 100644
--- a/windows/security/threat-protection/auditing/event-4911.md
+++ b/windows/security/threat-protection/auditing/event-4911.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4911(S): Resource attributes of the object were changed.
diff --git a/windows/security/threat-protection/auditing/event-4912.md b/windows/security/threat-protection/auditing/event-4912.md
index 3ac8a96880..0c0e66f90e 100644
--- a/windows/security/threat-protection/auditing/event-4912.md
+++ b/windows/security/threat-protection/auditing/event-4912.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4912(S): Per User Audit Policy was changed.
diff --git a/windows/security/threat-protection/auditing/event-4913.md b/windows/security/threat-protection/auditing/event-4913.md
index 949b10bd58..e15a691617 100644
--- a/windows/security/threat-protection/auditing/event-4913.md
+++ b/windows/security/threat-protection/auditing/event-4913.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4913(S): Central Access Policy on the object was changed.
diff --git a/windows/security/threat-protection/auditing/event-4928.md b/windows/security/threat-protection/auditing/event-4928.md
index d39db3ef25..902113bb5c 100644
--- a/windows/security/threat-protection/auditing/event-4928.md
+++ b/windows/security/threat-protection/auditing/event-4928.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4928(S, F): An Active Directory replica source naming context was established.
diff --git a/windows/security/threat-protection/auditing/event-4929.md b/windows/security/threat-protection/auditing/event-4929.md
index 596b209eb4..3fd978d0e3 100644
--- a/windows/security/threat-protection/auditing/event-4929.md
+++ b/windows/security/threat-protection/auditing/event-4929.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4929(S, F): An Active Directory replica source naming context was removed.
diff --git a/windows/security/threat-protection/auditing/event-4930.md b/windows/security/threat-protection/auditing/event-4930.md
index e66843285f..1b7bee26bf 100644
--- a/windows/security/threat-protection/auditing/event-4930.md
+++ b/windows/security/threat-protection/auditing/event-4930.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4930(S, F): An Active Directory replica source naming context was modified.
diff --git a/windows/security/threat-protection/auditing/event-4931.md b/windows/security/threat-protection/auditing/event-4931.md
index 27be6fe7ed..75acecb89f 100644
--- a/windows/security/threat-protection/auditing/event-4931.md
+++ b/windows/security/threat-protection/auditing/event-4931.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4931(S, F): An Active Directory replica destination naming context was modified.
diff --git a/windows/security/threat-protection/auditing/event-4932.md b/windows/security/threat-protection/auditing/event-4932.md
index 71e22cd118..4cdd6b7bdd 100644
--- a/windows/security/threat-protection/auditing/event-4932.md
+++ b/windows/security/threat-protection/auditing/event-4932.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4932(S): Synchronization of a replica of an Active Directory naming context has begun.
diff --git a/windows/security/threat-protection/auditing/event-4933.md b/windows/security/threat-protection/auditing/event-4933.md
index 3937b0e178..b1636e8e63 100644
--- a/windows/security/threat-protection/auditing/event-4933.md
+++ b/windows/security/threat-protection/auditing/event-4933.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4933(S, F): Synchronization of a replica of an Active Directory naming context has ended.
diff --git a/windows/security/threat-protection/auditing/event-4934.md b/windows/security/threat-protection/auditing/event-4934.md
index 90e2db1e04..efafcb9b79 100644
--- a/windows/security/threat-protection/auditing/event-4934.md
+++ b/windows/security/threat-protection/auditing/event-4934.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4934(S): Attributes of an Active Directory object were replicated.
diff --git a/windows/security/threat-protection/auditing/event-4935.md b/windows/security/threat-protection/auditing/event-4935.md
index 79ef8d6e1c..a126742afb 100644
--- a/windows/security/threat-protection/auditing/event-4935.md
+++ b/windows/security/threat-protection/auditing/event-4935.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4935(F): Replication failure begins.
diff --git a/windows/security/threat-protection/auditing/event-4936.md b/windows/security/threat-protection/auditing/event-4936.md
index 16a640d3bb..e2818ec6ee 100644
--- a/windows/security/threat-protection/auditing/event-4936.md
+++ b/windows/security/threat-protection/auditing/event-4936.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4936(S): Replication failure ends.
diff --git a/windows/security/threat-protection/auditing/event-4937.md b/windows/security/threat-protection/auditing/event-4937.md
index 731aceca7a..8296ce75c4 100644
--- a/windows/security/threat-protection/auditing/event-4937.md
+++ b/windows/security/threat-protection/auditing/event-4937.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4937(S): A lingering object was removed from a replica.
diff --git a/windows/security/threat-protection/auditing/event-4944.md b/windows/security/threat-protection/auditing/event-4944.md
index 7db0bee853..bb08c3a077 100644
--- a/windows/security/threat-protection/auditing/event-4944.md
+++ b/windows/security/threat-protection/auditing/event-4944.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4944(S): The following policy was active when the Windows Firewall started.
diff --git a/windows/security/threat-protection/auditing/event-4945.md b/windows/security/threat-protection/auditing/event-4945.md
index 8d73c9f148..852ed5f03e 100644
--- a/windows/security/threat-protection/auditing/event-4945.md
+++ b/windows/security/threat-protection/auditing/event-4945.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4945(S): A rule was listed when the Windows Firewall started.
diff --git a/windows/security/threat-protection/auditing/event-4946.md b/windows/security/threat-protection/auditing/event-4946.md
index d2fafe1dfc..ab355b85c1 100644
--- a/windows/security/threat-protection/auditing/event-4946.md
+++ b/windows/security/threat-protection/auditing/event-4946.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4946(S): A change has been made to Windows Firewall exception list. A rule was added.
diff --git a/windows/security/threat-protection/auditing/event-4947.md b/windows/security/threat-protection/auditing/event-4947.md
index 674449382b..284d2d4303 100644
--- a/windows/security/threat-protection/auditing/event-4947.md
+++ b/windows/security/threat-protection/auditing/event-4947.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4947(S): A change has been made to Windows Firewall exception list. A rule was modified.
diff --git a/windows/security/threat-protection/auditing/event-4948.md b/windows/security/threat-protection/auditing/event-4948.md
index 43acd0b7a9..da8f423b29 100644
--- a/windows/security/threat-protection/auditing/event-4948.md
+++ b/windows/security/threat-protection/auditing/event-4948.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4948(S): A change has been made to Windows Firewall exception list. A rule was deleted.
diff --git a/windows/security/threat-protection/auditing/event-4949.md b/windows/security/threat-protection/auditing/event-4949.md
index 81db5c36c6..528ad262bb 100644
--- a/windows/security/threat-protection/auditing/event-4949.md
+++ b/windows/security/threat-protection/auditing/event-4949.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4949(S): Windows Firewall settings were restored to the default values.
diff --git a/windows/security/threat-protection/auditing/event-4950.md b/windows/security/threat-protection/auditing/event-4950.md
index b4bd969a10..8a3aa4274a 100644
--- a/windows/security/threat-protection/auditing/event-4950.md
+++ b/windows/security/threat-protection/auditing/event-4950.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4950(S): A Windows Firewall setting has changed.
diff --git a/windows/security/threat-protection/auditing/event-4951.md b/windows/security/threat-protection/auditing/event-4951.md
index f585ac4615..7addb69d77 100644
--- a/windows/security/threat-protection/auditing/event-4951.md
+++ b/windows/security/threat-protection/auditing/event-4951.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4951(F): A rule has been ignored because its major version number wasn't recognized by Windows Firewall.
diff --git a/windows/security/threat-protection/auditing/event-4952.md b/windows/security/threat-protection/auditing/event-4952.md
index f95423f1c1..1dd166db54 100644
--- a/windows/security/threat-protection/auditing/event-4952.md
+++ b/windows/security/threat-protection/auditing/event-4952.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4952(F): Parts of a rule have been ignored because its minor version number was not recognized by Windows Firewall. The other parts of the rule will be enforced.
diff --git a/windows/security/threat-protection/auditing/event-4953.md b/windows/security/threat-protection/auditing/event-4953.md
index dfce2c4545..5a5a97d56a 100644
--- a/windows/security/threat-protection/auditing/event-4953.md
+++ b/windows/security/threat-protection/auditing/event-4953.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4953(F): Windows Firewall ignored a rule because it couldn't be parsed.
diff --git a/windows/security/threat-protection/auditing/event-4954.md b/windows/security/threat-protection/auditing/event-4954.md
index 09f0a2ce76..07977d6aff 100644
--- a/windows/security/threat-protection/auditing/event-4954.md
+++ b/windows/security/threat-protection/auditing/event-4954.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4954(S): Windows Firewall Group Policy settings have changed. The new settings have been applied.
diff --git a/windows/security/threat-protection/auditing/event-4956.md b/windows/security/threat-protection/auditing/event-4956.md
index 2344350879..105b780984 100644
--- a/windows/security/threat-protection/auditing/event-4956.md
+++ b/windows/security/threat-protection/auditing/event-4956.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4956(S): Windows Firewall has changed the active profile.
diff --git a/windows/security/threat-protection/auditing/event-4957.md b/windows/security/threat-protection/auditing/event-4957.md
index c408811451..49fae3fef5 100644
--- a/windows/security/threat-protection/auditing/event-4957.md
+++ b/windows/security/threat-protection/auditing/event-4957.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4957(F): Windows Firewall did not apply the following rule.
diff --git a/windows/security/threat-protection/auditing/event-4958.md b/windows/security/threat-protection/auditing/event-4958.md
index e05fc62bfa..45964176a6 100644
--- a/windows/security/threat-protection/auditing/event-4958.md
+++ b/windows/security/threat-protection/auditing/event-4958.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4958(F): Windows Firewall did not apply the following rule because the rule referred to items not configured on this computer.
diff --git a/windows/security/threat-protection/auditing/event-4964.md b/windows/security/threat-protection/auditing/event-4964.md
index 6c8452f0d6..51893d2572 100644
--- a/windows/security/threat-protection/auditing/event-4964.md
+++ b/windows/security/threat-protection/auditing/event-4964.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4964(S): Special groups have been assigned to a new logon.
diff --git a/windows/security/threat-protection/auditing/event-4985.md b/windows/security/threat-protection/auditing/event-4985.md
index b5cdedc6a7..8150e62b11 100644
--- a/windows/security/threat-protection/auditing/event-4985.md
+++ b/windows/security/threat-protection/auditing/event-4985.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 4985(S): The state of a transaction has changed.
diff --git a/windows/security/threat-protection/auditing/event-5024.md b/windows/security/threat-protection/auditing/event-5024.md
index c6f473df75..9e06608869 100644
--- a/windows/security/threat-protection/auditing/event-5024.md
+++ b/windows/security/threat-protection/auditing/event-5024.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5024(S): The Windows Firewall Service has started successfully.
diff --git a/windows/security/threat-protection/auditing/event-5025.md b/windows/security/threat-protection/auditing/event-5025.md
index 4dd4c320c6..9ae2fe14d0 100644
--- a/windows/security/threat-protection/auditing/event-5025.md
+++ b/windows/security/threat-protection/auditing/event-5025.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5025(S): The Windows Firewall Service has been stopped.
diff --git a/windows/security/threat-protection/auditing/event-5027.md b/windows/security/threat-protection/auditing/event-5027.md
index 652dac8c47..d654b82a01 100644
--- a/windows/security/threat-protection/auditing/event-5027.md
+++ b/windows/security/threat-protection/auditing/event-5027.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5027(F): The Windows Firewall Service was unable to retrieve the security policy from the local storage. The service will continue enforcing the current policy.
diff --git a/windows/security/threat-protection/auditing/event-5028.md b/windows/security/threat-protection/auditing/event-5028.md
index 6650d79ec5..bf9c62d91a 100644
--- a/windows/security/threat-protection/auditing/event-5028.md
+++ b/windows/security/threat-protection/auditing/event-5028.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5028(F): The Windows Firewall Service was unable to parse the new security policy. The service will continue with currently enforced policy.
diff --git a/windows/security/threat-protection/auditing/event-5029.md b/windows/security/threat-protection/auditing/event-5029.md
index 7ca1bb4522..4a36c10d4d 100644
--- a/windows/security/threat-protection/auditing/event-5029.md
+++ b/windows/security/threat-protection/auditing/event-5029.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5029(F): The Windows Firewall Service failed to initialize the driver. The service will continue to enforce the current policy.
diff --git a/windows/security/threat-protection/auditing/event-5030.md b/windows/security/threat-protection/auditing/event-5030.md
index 24660d6d45..aa78cb3b62 100644
--- a/windows/security/threat-protection/auditing/event-5030.md
+++ b/windows/security/threat-protection/auditing/event-5030.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5030(F): The Windows Firewall Service failed to start.
diff --git a/windows/security/threat-protection/auditing/event-5031.md b/windows/security/threat-protection/auditing/event-5031.md
index c328c46107..04c03b1ee6 100644
--- a/windows/security/threat-protection/auditing/event-5031.md
+++ b/windows/security/threat-protection/auditing/event-5031.md
@@ -12,6 +12,7 @@ ms.localizationpriority: none
author: vinaypamnani-msft
ms.date: 09/08/2021
ms.technology: itpro-security
+ms.topic: reference
---
# 5031(F): The Windows Firewall Service blocked an application from accepting incoming connections on the network.
diff --git a/windows/security/threat-protection/auditing/event-5032.md b/windows/security/threat-protection/auditing/event-5032.md
index 231acb67b1..af43e8ea73 100644
--- a/windows/security/threat-protection/auditing/event-5032.md
+++ b/windows/security/threat-protection/auditing/event-5032.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5032(F): Windows Firewall was unable to notify the user that it blocked an application from accepting incoming connections on the network.
diff --git a/windows/security/threat-protection/auditing/event-5033.md b/windows/security/threat-protection/auditing/event-5033.md
index ce127dad94..467ba04e40 100644
--- a/windows/security/threat-protection/auditing/event-5033.md
+++ b/windows/security/threat-protection/auditing/event-5033.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5033(S): The Windows Firewall Driver has started successfully.
diff --git a/windows/security/threat-protection/auditing/event-5034.md b/windows/security/threat-protection/auditing/event-5034.md
index 52c8c2522d..dc2d097c4a 100644
--- a/windows/security/threat-protection/auditing/event-5034.md
+++ b/windows/security/threat-protection/auditing/event-5034.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5034(S): The Windows Firewall Driver was stopped.
diff --git a/windows/security/threat-protection/auditing/event-5035.md b/windows/security/threat-protection/auditing/event-5035.md
index 3cf63d5224..88a49892a6 100644
--- a/windows/security/threat-protection/auditing/event-5035.md
+++ b/windows/security/threat-protection/auditing/event-5035.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5035(F): The Windows Firewall Driver failed to start.
diff --git a/windows/security/threat-protection/auditing/event-5037.md b/windows/security/threat-protection/auditing/event-5037.md
index bf6d42a9ef..f25a054fe7 100644
--- a/windows/security/threat-protection/auditing/event-5037.md
+++ b/windows/security/threat-protection/auditing/event-5037.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5037(F): The Windows Firewall Driver detected critical runtime error. Terminating.
diff --git a/windows/security/threat-protection/auditing/event-5038.md b/windows/security/threat-protection/auditing/event-5038.md
index 3b4aa0d998..e824e93afe 100644
--- a/windows/security/threat-protection/auditing/event-5038.md
+++ b/windows/security/threat-protection/auditing/event-5038.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5038(F): Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.
diff --git a/windows/security/threat-protection/auditing/event-5039.md b/windows/security/threat-protection/auditing/event-5039.md
index e1f249411a..7bf2bf5471 100644
--- a/windows/security/threat-protection/auditing/event-5039.md
+++ b/windows/security/threat-protection/auditing/event-5039.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5039(-): A registry key was virtualized.
diff --git a/windows/security/threat-protection/auditing/event-5051.md b/windows/security/threat-protection/auditing/event-5051.md
index 79d4e4b789..38a07353b3 100644
--- a/windows/security/threat-protection/auditing/event-5051.md
+++ b/windows/security/threat-protection/auditing/event-5051.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5051(-): A file was virtualized.
diff --git a/windows/security/threat-protection/auditing/event-5056.md b/windows/security/threat-protection/auditing/event-5056.md
index bac056b217..3711acef2d 100644
--- a/windows/security/threat-protection/auditing/event-5056.md
+++ b/windows/security/threat-protection/auditing/event-5056.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5056(S): A cryptographic self-test was performed.
diff --git a/windows/security/threat-protection/auditing/event-5057.md b/windows/security/threat-protection/auditing/event-5057.md
index 2013fda273..4fc7113c1b 100644
--- a/windows/security/threat-protection/auditing/event-5057.md
+++ b/windows/security/threat-protection/auditing/event-5057.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5057(F): A cryptographic primitive operation failed.
diff --git a/windows/security/threat-protection/auditing/event-5058.md b/windows/security/threat-protection/auditing/event-5058.md
index 2dae2d1e2f..b95c545e7c 100644
--- a/windows/security/threat-protection/auditing/event-5058.md
+++ b/windows/security/threat-protection/auditing/event-5058.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5058(S, F): Key file operation.
diff --git a/windows/security/threat-protection/auditing/event-5059.md b/windows/security/threat-protection/auditing/event-5059.md
index 26cd95b0d4..cdbae47721 100644
--- a/windows/security/threat-protection/auditing/event-5059.md
+++ b/windows/security/threat-protection/auditing/event-5059.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5059(S, F): Key migration operation.
diff --git a/windows/security/threat-protection/auditing/event-5060.md b/windows/security/threat-protection/auditing/event-5060.md
index 1a65f76633..60ec2cbd3e 100644
--- a/windows/security/threat-protection/auditing/event-5060.md
+++ b/windows/security/threat-protection/auditing/event-5060.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5060(F): Verification operation failed.
diff --git a/windows/security/threat-protection/auditing/event-5061.md b/windows/security/threat-protection/auditing/event-5061.md
index d47254485f..802ee6cc60 100644
--- a/windows/security/threat-protection/auditing/event-5061.md
+++ b/windows/security/threat-protection/auditing/event-5061.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5061(S, F): Cryptographic operation.
diff --git a/windows/security/threat-protection/auditing/event-5062.md b/windows/security/threat-protection/auditing/event-5062.md
index 08b0f7bce0..a76dabb95e 100644
--- a/windows/security/threat-protection/auditing/event-5062.md
+++ b/windows/security/threat-protection/auditing/event-5062.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5062(S): A kernel-mode cryptographic self-test was performed.
diff --git a/windows/security/threat-protection/auditing/event-5063.md b/windows/security/threat-protection/auditing/event-5063.md
index 784019bc18..41ac047786 100644
--- a/windows/security/threat-protection/auditing/event-5063.md
+++ b/windows/security/threat-protection/auditing/event-5063.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5063(S, F): A cryptographic provider operation was attempted.
diff --git a/windows/security/threat-protection/auditing/event-5064.md b/windows/security/threat-protection/auditing/event-5064.md
index 807d3ee45d..3467a2816a 100644
--- a/windows/security/threat-protection/auditing/event-5064.md
+++ b/windows/security/threat-protection/auditing/event-5064.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5064(S, F): A cryptographic context operation was attempted.
diff --git a/windows/security/threat-protection/auditing/event-5065.md b/windows/security/threat-protection/auditing/event-5065.md
index 3e978d64a3..66bfddb1d1 100644
--- a/windows/security/threat-protection/auditing/event-5065.md
+++ b/windows/security/threat-protection/auditing/event-5065.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5065(S, F): A cryptographic context modification was attempted.
diff --git a/windows/security/threat-protection/auditing/event-5066.md b/windows/security/threat-protection/auditing/event-5066.md
index e834a9e584..62a0920fb7 100644
--- a/windows/security/threat-protection/auditing/event-5066.md
+++ b/windows/security/threat-protection/auditing/event-5066.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5066(S, F): A cryptographic function operation was attempted.
diff --git a/windows/security/threat-protection/auditing/event-5067.md b/windows/security/threat-protection/auditing/event-5067.md
index 5aa395a688..78cd9d24aa 100644
--- a/windows/security/threat-protection/auditing/event-5067.md
+++ b/windows/security/threat-protection/auditing/event-5067.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5067(S, F): A cryptographic function modification was attempted.
diff --git a/windows/security/threat-protection/auditing/event-5068.md b/windows/security/threat-protection/auditing/event-5068.md
index 814ea02d50..791301bc3b 100644
--- a/windows/security/threat-protection/auditing/event-5068.md
+++ b/windows/security/threat-protection/auditing/event-5068.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5068(S, F): A cryptographic function provider operation was attempted.
diff --git a/windows/security/threat-protection/auditing/event-5069.md b/windows/security/threat-protection/auditing/event-5069.md
index b8d6466c09..9894285dad 100644
--- a/windows/security/threat-protection/auditing/event-5069.md
+++ b/windows/security/threat-protection/auditing/event-5069.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5069(S, F): A cryptographic function property operation was attempted.
diff --git a/windows/security/threat-protection/auditing/event-5070.md b/windows/security/threat-protection/auditing/event-5070.md
index 1232c68bd4..ba4785e01b 100644
--- a/windows/security/threat-protection/auditing/event-5070.md
+++ b/windows/security/threat-protection/auditing/event-5070.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5070(S, F): A cryptographic function property modification was attempted.
diff --git a/windows/security/threat-protection/auditing/event-5136.md b/windows/security/threat-protection/auditing/event-5136.md
index 97f862f3a6..97c0977a60 100644
--- a/windows/security/threat-protection/auditing/event-5136.md
+++ b/windows/security/threat-protection/auditing/event-5136.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5136(S): A directory service object was modified.
diff --git a/windows/security/threat-protection/auditing/event-5137.md b/windows/security/threat-protection/auditing/event-5137.md
index 072f6dede2..bed5eae208 100644
--- a/windows/security/threat-protection/auditing/event-5137.md
+++ b/windows/security/threat-protection/auditing/event-5137.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5137(S): A directory service object was created.
diff --git a/windows/security/threat-protection/auditing/event-5138.md b/windows/security/threat-protection/auditing/event-5138.md
index 5fcb9a3381..12d981909a 100644
--- a/windows/security/threat-protection/auditing/event-5138.md
+++ b/windows/security/threat-protection/auditing/event-5138.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5138(S): A directory service object was undeleted.
diff --git a/windows/security/threat-protection/auditing/event-5139.md b/windows/security/threat-protection/auditing/event-5139.md
index e89fd1eb91..6799a4e50d 100644
--- a/windows/security/threat-protection/auditing/event-5139.md
+++ b/windows/security/threat-protection/auditing/event-5139.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5139(S): A directory service object was moved.
diff --git a/windows/security/threat-protection/auditing/event-5140.md b/windows/security/threat-protection/auditing/event-5140.md
index 5d72bf2c8c..522cf1b652 100644
--- a/windows/security/threat-protection/auditing/event-5140.md
+++ b/windows/security/threat-protection/auditing/event-5140.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5140(S, F): A network share object was accessed.
diff --git a/windows/security/threat-protection/auditing/event-5141.md b/windows/security/threat-protection/auditing/event-5141.md
index d7ba9c67d4..046ca20f9d 100644
--- a/windows/security/threat-protection/auditing/event-5141.md
+++ b/windows/security/threat-protection/auditing/event-5141.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5141(S): A directory service object was deleted.
diff --git a/windows/security/threat-protection/auditing/event-5142.md b/windows/security/threat-protection/auditing/event-5142.md
index 6930a066d4..3a69208c29 100644
--- a/windows/security/threat-protection/auditing/event-5142.md
+++ b/windows/security/threat-protection/auditing/event-5142.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5142(S): A network share object was added.
diff --git a/windows/security/threat-protection/auditing/event-5143.md b/windows/security/threat-protection/auditing/event-5143.md
index ccfe6641b0..e92068c93a 100644
--- a/windows/security/threat-protection/auditing/event-5143.md
+++ b/windows/security/threat-protection/auditing/event-5143.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5143(S): A network share object was modified.
diff --git a/windows/security/threat-protection/auditing/event-5144.md b/windows/security/threat-protection/auditing/event-5144.md
index 69aa754e48..da401f212d 100644
--- a/windows/security/threat-protection/auditing/event-5144.md
+++ b/windows/security/threat-protection/auditing/event-5144.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5144(S): A network share object was deleted.
diff --git a/windows/security/threat-protection/auditing/event-5145.md b/windows/security/threat-protection/auditing/event-5145.md
index 8f47f2b4d1..02c531c5fd 100644
--- a/windows/security/threat-protection/auditing/event-5145.md
+++ b/windows/security/threat-protection/auditing/event-5145.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5145(S, F): A network share object was checked to see whether client can be granted desired access.
diff --git a/windows/security/threat-protection/auditing/event-5148.md b/windows/security/threat-protection/auditing/event-5148.md
index bb9ab2267c..5442a8a705 100644
--- a/windows/security/threat-protection/auditing/event-5148.md
+++ b/windows/security/threat-protection/auditing/event-5148.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5148(F): The Windows Filtering Platform has detected a DoS attack and entered a defensive mode; packets associated with this attack will be discarded.
diff --git a/windows/security/threat-protection/auditing/event-5149.md b/windows/security/threat-protection/auditing/event-5149.md
index 0e4b73fcde..7e0dc6dd45 100644
--- a/windows/security/threat-protection/auditing/event-5149.md
+++ b/windows/security/threat-protection/auditing/event-5149.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5149(F): The DoS attack has subsided and normal processing is being resumed.
diff --git a/windows/security/threat-protection/auditing/event-5150.md b/windows/security/threat-protection/auditing/event-5150.md
index f1310cde61..80c82d807e 100644
--- a/windows/security/threat-protection/auditing/event-5150.md
+++ b/windows/security/threat-protection/auditing/event-5150.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5150(-): The Windows Filtering Platform blocked a packet.
diff --git a/windows/security/threat-protection/auditing/event-5151.md b/windows/security/threat-protection/auditing/event-5151.md
index bf55e6a6eb..6b7d1453bf 100644
--- a/windows/security/threat-protection/auditing/event-5151.md
+++ b/windows/security/threat-protection/auditing/event-5151.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5151(-): A more restrictive Windows Filtering Platform filter has blocked a packet.
diff --git a/windows/security/threat-protection/auditing/event-5152.md b/windows/security/threat-protection/auditing/event-5152.md
index 27438881cb..e5a76da383 100644
--- a/windows/security/threat-protection/auditing/event-5152.md
+++ b/windows/security/threat-protection/auditing/event-5152.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5152(F): The Windows Filtering Platform blocked a packet.
diff --git a/windows/security/threat-protection/auditing/event-5153.md b/windows/security/threat-protection/auditing/event-5153.md
index f7a61cc8fe..a321b76f20 100644
--- a/windows/security/threat-protection/auditing/event-5153.md
+++ b/windows/security/threat-protection/auditing/event-5153.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5153(S): A more restrictive Windows Filtering Platform filter has blocked a packet.
diff --git a/windows/security/threat-protection/auditing/event-5154.md b/windows/security/threat-protection/auditing/event-5154.md
index 2002fbb907..9b2425ff9c 100644
--- a/windows/security/threat-protection/auditing/event-5154.md
+++ b/windows/security/threat-protection/auditing/event-5154.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5154(S): The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections.
diff --git a/windows/security/threat-protection/auditing/event-5155.md b/windows/security/threat-protection/auditing/event-5155.md
index 94377b1098..e6efebdae1 100644
--- a/windows/security/threat-protection/auditing/event-5155.md
+++ b/windows/security/threat-protection/auditing/event-5155.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5155(F): The Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections.
diff --git a/windows/security/threat-protection/auditing/event-5156.md b/windows/security/threat-protection/auditing/event-5156.md
index fbe87f79bc..3d56301b24 100644
--- a/windows/security/threat-protection/auditing/event-5156.md
+++ b/windows/security/threat-protection/auditing/event-5156.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5156(S): The Windows Filtering Platform has permitted a connection.
diff --git a/windows/security/threat-protection/auditing/event-5157.md b/windows/security/threat-protection/auditing/event-5157.md
index 6967921a48..4f62c99d51 100644
--- a/windows/security/threat-protection/auditing/event-5157.md
+++ b/windows/security/threat-protection/auditing/event-5157.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5157(F): The Windows Filtering Platform has blocked a connection.
diff --git a/windows/security/threat-protection/auditing/event-5158.md b/windows/security/threat-protection/auditing/event-5158.md
index af16821b1f..cbc0d2d4ee 100644
--- a/windows/security/threat-protection/auditing/event-5158.md
+++ b/windows/security/threat-protection/auditing/event-5158.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5158(S): The Windows Filtering Platform has permitted a bind to a local port.
diff --git a/windows/security/threat-protection/auditing/event-5159.md b/windows/security/threat-protection/auditing/event-5159.md
index 5ecd816d89..ffe34518c5 100644
--- a/windows/security/threat-protection/auditing/event-5159.md
+++ b/windows/security/threat-protection/auditing/event-5159.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5159(F): The Windows Filtering Platform has blocked a bind to a local port.
diff --git a/windows/security/threat-protection/auditing/event-5168.md b/windows/security/threat-protection/auditing/event-5168.md
index 3b59d54629..f0ae1f47a8 100644
--- a/windows/security/threat-protection/auditing/event-5168.md
+++ b/windows/security/threat-protection/auditing/event-5168.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5168(F): SPN check for SMB/SMB2 failed.
diff --git a/windows/security/threat-protection/auditing/event-5376.md b/windows/security/threat-protection/auditing/event-5376.md
index 3145af538e..ee08c45c93 100644
--- a/windows/security/threat-protection/auditing/event-5376.md
+++ b/windows/security/threat-protection/auditing/event-5376.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5376(S): Credential Manager credentials were backed up.
diff --git a/windows/security/threat-protection/auditing/event-5377.md b/windows/security/threat-protection/auditing/event-5377.md
index a60bd13f29..a6f12f74f5 100644
--- a/windows/security/threat-protection/auditing/event-5377.md
+++ b/windows/security/threat-protection/auditing/event-5377.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5377(S): Credential Manager credentials were restored from a backup.
diff --git a/windows/security/threat-protection/auditing/event-5378.md b/windows/security/threat-protection/auditing/event-5378.md
index 64f48471be..b6391769da 100644
--- a/windows/security/threat-protection/auditing/event-5378.md
+++ b/windows/security/threat-protection/auditing/event-5378.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5378(F): The requested credentials delegation was disallowed by policy.
diff --git a/windows/security/threat-protection/auditing/event-5447.md b/windows/security/threat-protection/auditing/event-5447.md
index 732d1ae81e..96b013cf8c 100644
--- a/windows/security/threat-protection/auditing/event-5447.md
+++ b/windows/security/threat-protection/auditing/event-5447.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5447(S): A Windows Filtering Platform filter has been changed.
diff --git a/windows/security/threat-protection/auditing/event-5632.md b/windows/security/threat-protection/auditing/event-5632.md
index b5af7f21a3..676a79172e 100644
--- a/windows/security/threat-protection/auditing/event-5632.md
+++ b/windows/security/threat-protection/auditing/event-5632.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5632(S, F): A request was made to authenticate to a wireless network.
diff --git a/windows/security/threat-protection/auditing/event-5633.md b/windows/security/threat-protection/auditing/event-5633.md
index 1583b0b945..e661c80301 100644
--- a/windows/security/threat-protection/auditing/event-5633.md
+++ b/windows/security/threat-protection/auditing/event-5633.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5633(S, F): A request was made to authenticate to a wired network.
diff --git a/windows/security/threat-protection/auditing/event-5712.md b/windows/security/threat-protection/auditing/event-5712.md
index d0dc85fe45..32d5ba732a 100644
--- a/windows/security/threat-protection/auditing/event-5712.md
+++ b/windows/security/threat-protection/auditing/event-5712.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5712(S): A Remote Procedure Call (RPC) was attempted.
diff --git a/windows/security/threat-protection/auditing/event-5888.md b/windows/security/threat-protection/auditing/event-5888.md
index 5c45a9698a..72e18b5e28 100644
--- a/windows/security/threat-protection/auditing/event-5888.md
+++ b/windows/security/threat-protection/auditing/event-5888.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5888(S): An object in the COM+ Catalog was modified.
diff --git a/windows/security/threat-protection/auditing/event-5889.md b/windows/security/threat-protection/auditing/event-5889.md
index 3b60e803d9..178ec29a4f 100644
--- a/windows/security/threat-protection/auditing/event-5889.md
+++ b/windows/security/threat-protection/auditing/event-5889.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5889(S): An object was deleted from the COM+ Catalog.
diff --git a/windows/security/threat-protection/auditing/event-5890.md b/windows/security/threat-protection/auditing/event-5890.md
index 09c79bee05..4f473d2a4e 100644
--- a/windows/security/threat-protection/auditing/event-5890.md
+++ b/windows/security/threat-protection/auditing/event-5890.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 5890(S): An object was added to the COM+ Catalog.
diff --git a/windows/security/threat-protection/auditing/event-6144.md b/windows/security/threat-protection/auditing/event-6144.md
index dfad64c1da..3eb1181321 100644
--- a/windows/security/threat-protection/auditing/event-6144.md
+++ b/windows/security/threat-protection/auditing/event-6144.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 6144(S): Security policy in the group policy objects has been applied successfully.
diff --git a/windows/security/threat-protection/auditing/event-6145.md b/windows/security/threat-protection/auditing/event-6145.md
index 60ed2e8ad8..b062b5e023 100644
--- a/windows/security/threat-protection/auditing/event-6145.md
+++ b/windows/security/threat-protection/auditing/event-6145.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 6145(F): One or more errors occurred while processing security policy in the group policy objects.
diff --git a/windows/security/threat-protection/auditing/event-6281.md b/windows/security/threat-protection/auditing/event-6281.md
index 76f546a222..38f432d51a 100644
--- a/windows/security/threat-protection/auditing/event-6281.md
+++ b/windows/security/threat-protection/auditing/event-6281.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 6281(F): Code Integrity determined that the page hashes of an image file aren't valid. The file could be improperly signed without page hashes or corrupt due to unauthorized modification. The invalid hashes could indicate a potential disk device error.
diff --git a/windows/security/threat-protection/auditing/event-6400.md b/windows/security/threat-protection/auditing/event-6400.md
index d8bcc6f1c7..a588c35204 100644
--- a/windows/security/threat-protection/auditing/event-6400.md
+++ b/windows/security/threat-protection/auditing/event-6400.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 6400(-): BranchCache: Received an incorrectly formatted response while discovering availability of content.
diff --git a/windows/security/threat-protection/auditing/event-6401.md b/windows/security/threat-protection/auditing/event-6401.md
index 3e60d3515a..82502eb7ff 100644
--- a/windows/security/threat-protection/auditing/event-6401.md
+++ b/windows/security/threat-protection/auditing/event-6401.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 6401(-): BranchCache: Received invalid data from a peer. Data discarded.
diff --git a/windows/security/threat-protection/auditing/event-6402.md b/windows/security/threat-protection/auditing/event-6402.md
index 3148f9b03e..d5d3febf63 100644
--- a/windows/security/threat-protection/auditing/event-6402.md
+++ b/windows/security/threat-protection/auditing/event-6402.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 6402(-): BranchCache: The message to the hosted cache offering it data is incorrectly formatted.
diff --git a/windows/security/threat-protection/auditing/event-6403.md b/windows/security/threat-protection/auditing/event-6403.md
index ad426fdacc..2f9d945388 100644
--- a/windows/security/threat-protection/auditing/event-6403.md
+++ b/windows/security/threat-protection/auditing/event-6403.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 6403(-): BranchCache: The hosted cache sent an incorrectly formatted response to the client.
diff --git a/windows/security/threat-protection/auditing/event-6404.md b/windows/security/threat-protection/auditing/event-6404.md
index e2fed0d583..f37bea1b9e 100644
--- a/windows/security/threat-protection/auditing/event-6404.md
+++ b/windows/security/threat-protection/auditing/event-6404.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 6404(-): BranchCache: Hosted cache could not be authenticated using the provisioned SSL certificate.
diff --git a/windows/security/threat-protection/auditing/event-6405.md b/windows/security/threat-protection/auditing/event-6405.md
index 48746ad277..1feed0f6a6 100644
--- a/windows/security/threat-protection/auditing/event-6405.md
+++ b/windows/security/threat-protection/auditing/event-6405.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 6405(-): BranchCache: %2 instance(s) of event id %1 occurred.
diff --git a/windows/security/threat-protection/auditing/event-6406.md b/windows/security/threat-protection/auditing/event-6406.md
index 42541a3842..fdd75af38b 100644
--- a/windows/security/threat-protection/auditing/event-6406.md
+++ b/windows/security/threat-protection/auditing/event-6406.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 6406(-): %1 registered to Windows Firewall to control filtering for the following: %2.
diff --git a/windows/security/threat-protection/auditing/event-6407.md b/windows/security/threat-protection/auditing/event-6407.md
index 68aba98482..c2f279466e 100644
--- a/windows/security/threat-protection/auditing/event-6407.md
+++ b/windows/security/threat-protection/auditing/event-6407.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 6407(-): 1%.
diff --git a/windows/security/threat-protection/auditing/event-6408.md b/windows/security/threat-protection/auditing/event-6408.md
index 28c11c16f5..36f25a9b69 100644
--- a/windows/security/threat-protection/auditing/event-6408.md
+++ b/windows/security/threat-protection/auditing/event-6408.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 6408(-): Registered product %1 failed and Windows Firewall is now controlling the filtering for %2.
diff --git a/windows/security/threat-protection/auditing/event-6409.md b/windows/security/threat-protection/auditing/event-6409.md
index c1c419c09d..3f406625b5 100644
--- a/windows/security/threat-protection/auditing/event-6409.md
+++ b/windows/security/threat-protection/auditing/event-6409.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 6409(-): BranchCache: A service connection point object could not be parsed.
diff --git a/windows/security/threat-protection/auditing/event-6410.md b/windows/security/threat-protection/auditing/event-6410.md
index b921dbea1c..958db95565 100644
--- a/windows/security/threat-protection/auditing/event-6410.md
+++ b/windows/security/threat-protection/auditing/event-6410.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 6410(F): Code integrity determined that a file does not meet the security requirements to load into a process.
diff --git a/windows/security/threat-protection/auditing/event-6416.md b/windows/security/threat-protection/auditing/event-6416.md
index 7d254bf9ef..64cdb17ee1 100644
--- a/windows/security/threat-protection/auditing/event-6416.md
+++ b/windows/security/threat-protection/auditing/event-6416.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 6416(S): A new external device was recognized by the System.
diff --git a/windows/security/threat-protection/auditing/event-6419.md b/windows/security/threat-protection/auditing/event-6419.md
index 108315501c..7368059899 100644
--- a/windows/security/threat-protection/auditing/event-6419.md
+++ b/windows/security/threat-protection/auditing/event-6419.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 6419(S): A request was made to disable a device.
diff --git a/windows/security/threat-protection/auditing/event-6420.md b/windows/security/threat-protection/auditing/event-6420.md
index 2efdfa78aa..2c7166a78d 100644
--- a/windows/security/threat-protection/auditing/event-6420.md
+++ b/windows/security/threat-protection/auditing/event-6420.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 6420(S): A device was disabled.
diff --git a/windows/security/threat-protection/auditing/event-6421.md b/windows/security/threat-protection/auditing/event-6421.md
index 3780d8b15e..ae72b11254 100644
--- a/windows/security/threat-protection/auditing/event-6421.md
+++ b/windows/security/threat-protection/auditing/event-6421.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 6421(S): A request was made to enable a device.
diff --git a/windows/security/threat-protection/auditing/event-6422.md b/windows/security/threat-protection/auditing/event-6422.md
index 02752c9163..bf594b6937 100644
--- a/windows/security/threat-protection/auditing/event-6422.md
+++ b/windows/security/threat-protection/auditing/event-6422.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 6422(S): A device was enabled.
diff --git a/windows/security/threat-protection/auditing/event-6423.md b/windows/security/threat-protection/auditing/event-6423.md
index 5e62ebe6c7..4f7fcb614c 100644
--- a/windows/security/threat-protection/auditing/event-6423.md
+++ b/windows/security/threat-protection/auditing/event-6423.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 6423(S): The installation of this device is forbidden by system policy.
diff --git a/windows/security/threat-protection/auditing/event-6424.md b/windows/security/threat-protection/auditing/event-6424.md
index 699e5ad030..10d33c2820 100644
--- a/windows/security/threat-protection/auditing/event-6424.md
+++ b/windows/security/threat-protection/auditing/event-6424.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# 6424(S): The installation of this device was allowed, after having previously been forbidden by policy.
diff --git a/windows/security/threat-protection/auditing/how-to-list-xml-elements-in-eventdata.md b/windows/security/threat-protection/auditing/how-to-list-xml-elements-in-eventdata.md
index 4ee793c896..d2af1d3d31 100644
--- a/windows/security/threat-protection/auditing/how-to-list-xml-elements-in-eventdata.md
+++ b/windows/security/threat-protection/auditing/how-to-list-xml-elements-in-eventdata.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: how-to
---
# How to get a list of XML data name elements in EventData
diff --git a/windows/security/threat-protection/auditing/other-events.md b/windows/security/threat-protection/auditing/other-events.md
index 6854674959..800961629e 100644
--- a/windows/security/threat-protection/auditing/other-events.md
+++ b/windows/security/threat-protection/auditing/other-events.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# Other Events
diff --git a/windows/security/threat-protection/block-untrusted-fonts-in-enterprise.md b/windows/security/threat-protection/block-untrusted-fonts-in-enterprise.md
index b13c6f8d8c..fdc4c5d757 100644
--- a/windows/security/threat-protection/block-untrusted-fonts-in-enterprise.md
+++ b/windows/security/threat-protection/block-untrusted-fonts-in-enterprise.md
@@ -9,6 +9,7 @@ ms.author: dansimp
ms.date: 08/14/2017
ms.localizationpriority: medium
ms.technology: itpro-security
+ms.topic: reference
---
# Block untrusted fonts in an enterprise
diff --git a/windows/security/threat-protection/microsoft-defender-application-guard/configure-md-app-guard.md b/windows/security/threat-protection/microsoft-defender-application-guard/configure-md-app-guard.md
index c71d2b029e..5ab3f50909 100644
--- a/windows/security/threat-protection/microsoft-defender-application-guard/configure-md-app-guard.md
+++ b/windows/security/threat-protection/microsoft-defender-application-guard/configure-md-app-guard.md
@@ -13,6 +13,7 @@ ms.reviewer:
manager: aaroncz
ms.custom: sasr
ms.technology: itpro-security
+ms.topic: how-to
---
# Configure Microsoft Defender Application Guard policy settings
diff --git a/windows/security/threat-protection/microsoft-defender-application-guard/install-md-app-guard.md b/windows/security/threat-protection/microsoft-defender-application-guard/install-md-app-guard.md
index b4fb01a3c6..765a61fcb9 100644
--- a/windows/security/threat-protection/microsoft-defender-application-guard/install-md-app-guard.md
+++ b/windows/security/threat-protection/microsoft-defender-application-guard/install-md-app-guard.md
@@ -15,6 +15,7 @@ ms.custom: asr
ms.technology: itpro-security
ms.collection:
- highpri
+ms.topic: how-to
---
# Prepare to install Microsoft Defender Application Guard
diff --git a/windows/security/threat-protection/microsoft-defender-application-guard/md-app-guard-browser-extension.md b/windows/security/threat-protection/microsoft-defender-application-guard/md-app-guard-browser-extension.md
index 631bbc75fd..0f2bca60b2 100644
--- a/windows/security/threat-protection/microsoft-defender-application-guard/md-app-guard-browser-extension.md
+++ b/windows/security/threat-protection/microsoft-defender-application-guard/md-app-guard-browser-extension.md
@@ -10,6 +10,7 @@ ms.reviewer:
manager: aaroncz
ms.custom: asr
ms.technology: itpro-security
+ms.topic: conceptual
---
# Microsoft Defender Application Guard Extension
diff --git a/windows/security/threat-protection/microsoft-defender-application-guard/md-app-guard-overview.md b/windows/security/threat-protection/microsoft-defender-application-guard/md-app-guard-overview.md
index 1ba47ee970..6b284c9344 100644
--- a/windows/security/threat-protection/microsoft-defender-application-guard/md-app-guard-overview.md
+++ b/windows/security/threat-protection/microsoft-defender-application-guard/md-app-guard-overview.md
@@ -15,6 +15,7 @@ ms.custom: asr
ms.technology: itpro-security
ms.collection:
- highpri
+ms.topic: conceptual
---
# Microsoft Defender Application Guard overview
diff --git a/windows/security/threat-protection/microsoft-defender-application-guard/test-scenarios-md-app-guard.md b/windows/security/threat-protection/microsoft-defender-application-guard/test-scenarios-md-app-guard.md
index d8461e69f2..4357712bc7 100644
--- a/windows/security/threat-protection/microsoft-defender-application-guard/test-scenarios-md-app-guard.md
+++ b/windows/security/threat-protection/microsoft-defender-application-guard/test-scenarios-md-app-guard.md
@@ -10,6 +10,7 @@ ms.reviewer: sazankha
manager: aaroncz
ms.date: 09/23/2022
ms.custom: asr
+ms.topic: conceptual
---
# Application Guard testing scenarios
diff --git a/windows/security/threat-protection/microsoft-defender-smartscreen/microsoft-defender-smartscreen-available-settings.md b/windows/security/threat-protection/microsoft-defender-smartscreen/microsoft-defender-smartscreen-available-settings.md
index 5d2279fcc0..8723d513d2 100644
--- a/windows/security/threat-protection/microsoft-defender-smartscreen/microsoft-defender-smartscreen-available-settings.md
+++ b/windows/security/threat-protection/microsoft-defender-smartscreen/microsoft-defender-smartscreen-available-settings.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: reference
---
# Available Microsoft Defender SmartScreen Group Policy and mobile device management (MDM) settings
**Applies to:**
diff --git a/windows/security/threat-protection/microsoft-defender-smartscreen/microsoft-defender-smartscreen-set-individual-device.md b/windows/security/threat-protection/microsoft-defender-smartscreen/microsoft-defender-smartscreen-set-individual-device.md
index 4d099ef9e6..0ee92c6736 100644
--- a/windows/security/threat-protection/microsoft-defender-smartscreen/microsoft-defender-smartscreen-set-individual-device.md
+++ b/windows/security/threat-protection/microsoft-defender-smartscreen/microsoft-defender-smartscreen-set-individual-device.md
@@ -12,6 +12,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: how-to
---
# Set up and use Microsoft Defender SmartScreen on individual devices
diff --git a/windows/security/threat-protection/microsoft-defender-smartscreen/phishing-protection-microsoft-defender-smartscreen.md b/windows/security/threat-protection/microsoft-defender-smartscreen/phishing-protection-microsoft-defender-smartscreen.md
index db57203dd5..8597ee9893 100644
--- a/windows/security/threat-protection/microsoft-defender-smartscreen/phishing-protection-microsoft-defender-smartscreen.md
+++ b/windows/security/threat-protection/microsoft-defender-smartscreen/phishing-protection-microsoft-defender-smartscreen.md
@@ -12,6 +12,7 @@ ms.date: 10/07/2022
adobe-target: true
appliesto:
- ✅ Windows 11, version 22H2
+ms.topic: conceptual
---
# Enhanced Phishing Protection in Microsoft Defender SmartScreen
diff --git a/windows/security/threat-protection/protect-high-value-assets-by-controlling-the-health-of-windows-10-based-devices.md b/windows/security/threat-protection/protect-high-value-assets-by-controlling-the-health-of-windows-10-based-devices.md
index ae2b7dcea6..fa79c1116f 100644
--- a/windows/security/threat-protection/protect-high-value-assets-by-controlling-the-health-of-windows-10-based-devices.md
+++ b/windows/security/threat-protection/protect-high-value-assets-by-controlling-the-health-of-windows-10-based-devices.md
@@ -9,6 +9,7 @@ author: dulcemontemayor
ms.date: 10/13/2017
ms.localizationpriority: medium
ms.technology: itpro-security
+ms.topic: conceptual
---
# Control the health of Windows 10-based devices
diff --git a/windows/security/threat-protection/security-policy-settings/microsoft-network-client-digitally-sign-communications-always.md b/windows/security/threat-protection/security-policy-settings/microsoft-network-client-digitally-sign-communications-always.md
index bde8daf5f1..9a86d20cd0 100644
--- a/windows/security/threat-protection/security-policy-settings/microsoft-network-client-digitally-sign-communications-always.md
+++ b/windows/security/threat-protection/security-policy-settings/microsoft-network-client-digitally-sign-communications-always.md
@@ -13,6 +13,7 @@ ms.localizationpriority: medium
author: vinaypamnani-msft
ms.date: 06/28/2018
ms.technology: itpro-security
+ms.topic: conceptual
---
# Microsoft network client: Digitally sign communications (always)
diff --git a/windows/security/threat-protection/security-policy-settings/minimum-password-age.md b/windows/security/threat-protection/security-policy-settings/minimum-password-age.md
index f6ce6b41e1..76babb8a47 100644
--- a/windows/security/threat-protection/security-policy-settings/minimum-password-age.md
+++ b/windows/security/threat-protection/security-policy-settings/minimum-password-age.md
@@ -13,6 +13,7 @@ ms.localizationpriority: medium
author: vinaypamnani-msft
ms.date: 11/13/2018
ms.technology: itpro-security
+ms.topic: conceptual
---
# Minimum password age
diff --git a/windows/security/threat-protection/security-policy-settings/network-access-restrict-clients-allowed-to-make-remote-sam-calls.md b/windows/security/threat-protection/security-policy-settings/network-access-restrict-clients-allowed-to-make-remote-sam-calls.md
index 48d6693d11..67f28accd4 100644
--- a/windows/security/threat-protection/security-policy-settings/network-access-restrict-clients-allowed-to-make-remote-sam-calls.md
+++ b/windows/security/threat-protection/security-policy-settings/network-access-restrict-clients-allowed-to-make-remote-sam-calls.md
@@ -11,6 +11,7 @@ ms.reviewer:
manager: aaroncz
ms.collection:
- highpri
+ms.topic: conceptual
---
# Network access: Restrict clients allowed to make remote calls to SAM
diff --git a/windows/security/threat-protection/security-policy-settings/security-options.md b/windows/security/threat-protection/security-policy-settings/security-options.md
index 2617bbe979..6a88de5b89 100644
--- a/windows/security/threat-protection/security-policy-settings/security-options.md
+++ b/windows/security/threat-protection/security-policy-settings/security-options.md
@@ -13,6 +13,7 @@ ms.localizationpriority: medium
author: vinaypamnani-msft
ms.date: 06/28/2018
ms.technology: itpro-security
+ms.topic: conceptual
---
# Security Options
diff --git a/windows/security/threat-protection/use-windows-event-forwarding-to-assist-in-intrusion-detection.md b/windows/security/threat-protection/use-windows-event-forwarding-to-assist-in-intrusion-detection.md
index d48d5da38b..83eddad140 100644
--- a/windows/security/threat-protection/use-windows-event-forwarding-to-assist-in-intrusion-detection.md
+++ b/windows/security/threat-protection/use-windows-event-forwarding-to-assist-in-intrusion-detection.md
@@ -9,6 +9,7 @@ author: dulcemontemayor
ms.date: 02/28/2019
ms.localizationpriority: medium
ms.technology: itpro-security
+ms.topic: how-to
---
# Use Windows Event Forwarding to help with intrusion detection
diff --git a/windows/security/threat-protection/windows-defender-application-control/applocker/working-with-applocker-rules.md b/windows/security/threat-protection/windows-defender-application-control/applocker/working-with-applocker-rules.md
index e5b9ec21cc..e746c84f0f 100644
--- a/windows/security/threat-protection/windows-defender-application-control/applocker/working-with-applocker-rules.md
+++ b/windows/security/threat-protection/windows-defender-application-control/applocker/working-with-applocker-rules.md
@@ -14,6 +14,7 @@ ms.localizationpriority: medium
msauthor: v-anbic
ms.date: 08/27/2018
ms.technology: itpro-security
+ms.topic: conceptual
---
# Working with AppLocker rules
diff --git a/windows/security/threat-protection/windows-defender-security-center/wdsc-windows-10-in-s-mode.md b/windows/security/threat-protection/windows-defender-security-center/wdsc-windows-10-in-s-mode.md
index 4777c6863d..a3773ffe67 100644
--- a/windows/security/threat-protection/windows-defender-security-center/wdsc-windows-10-in-s-mode.md
+++ b/windows/security/threat-protection/windows-defender-security-center/wdsc-windows-10-in-s-mode.md
@@ -14,6 +14,7 @@ ms.date: 04/30/2018
ms.reviewer:
manager: aaroncz
ms.technology: itpro-security
+ms.topic: how-to
---
# Manage Windows Security in Windows 10 in S mode
diff --git a/windows/security/threat-protection/windows-defender-system-guard/how-hardware-based-root-of-trust-helps-protect-windows.md b/windows/security/threat-protection/windows-defender-system-guard/how-hardware-based-root-of-trust-helps-protect-windows.md
index a5a4b985e6..1404209dea 100644
--- a/windows/security/threat-protection/windows-defender-system-guard/how-hardware-based-root-of-trust-helps-protect-windows.md
+++ b/windows/security/threat-protection/windows-defender-system-guard/how-hardware-based-root-of-trust-helps-protect-windows.md
@@ -14,6 +14,7 @@ ms.localizationpriority: medium
author: vinaypamnani-msft
ms.date: 03/01/2019
ms.technology: itpro-security
+ms.topic: conceptual
---
# Windows Defender System Guard: How a hardware-based root of trust helps protect Windows 10
diff --git a/windows/security/threat-protection/windows-defender-system-guard/system-guard-secure-launch-and-smm-protection.md b/windows/security/threat-protection/windows-defender-system-guard/system-guard-secure-launch-and-smm-protection.md
index e4715791d7..929c7d815b 100644
--- a/windows/security/threat-protection/windows-defender-system-guard/system-guard-secure-launch-and-smm-protection.md
+++ b/windows/security/threat-protection/windows-defender-system-guard/system-guard-secure-launch-and-smm-protection.md
@@ -13,6 +13,7 @@ ms.reviewer:
manager: aaroncz
ms.author: vinpa
ms.technology: itpro-security
+ms.topic: conceptual
---
# System Guard Secure Launch and SMM protection
diff --git a/windows/security/threat-protection/windows-firewall/configure-the-workstation-authentication-certificate-template.md b/windows/security/threat-protection/windows-firewall/configure-the-workstation-authentication-certificate-template.md
index df6d6a8219..3e77330596 100644
--- a/windows/security/threat-protection/windows-firewall/configure-the-workstation-authentication-certificate-template.md
+++ b/windows/security/threat-protection/windows-firewall/configure-the-workstation-authentication-certificate-template.md
@@ -19,6 +19,7 @@ appliesto:
- ✅ Windows Server 2016
- ✅ Windows Server 2019
- ✅ Windows Server 2022
+ms.topic: conceptual
---
# Configure the Workstation Authentication Certificate Template