mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-12 21:37:22 +00:00
Updated metadata
This commit is contained in:
parent
c3567ef40c
commit
c34b5a85ce
8
.vscode/settings.json
vendored
Normal file
8
.vscode/settings.json
vendored
Normal file
@ -0,0 +1,8 @@
|
||||
{
|
||||
"markdownlint.config": {
|
||||
"MD028": false,
|
||||
"MD025": {
|
||||
"front_matter_title": ""
|
||||
}
|
||||
}
|
||||
}
|
@ -15,7 +15,7 @@ audience: ITPro
|
||||
ms.collection: M365-security-compliance
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Advanced security audit policy settings
|
||||
|
@ -16,7 +16,7 @@ metadata:
|
||||
ms.collection: M365-security-compliance
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
|
||||
title: Advanced security auditing FAQ
|
||||
|
||||
|
@ -15,7 +15,7 @@ audience: ITPro
|
||||
ms.collection: M365-security-compliance
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/6/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Advanced security audit policies
|
||||
|
@ -11,7 +11,7 @@ ms.date: 09/06/2021
|
||||
ms.reviewer:
|
||||
manager: dansimp
|
||||
ms.author: dansimp
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Appendix A: Security monitoring recommendations for many audit events
|
||||
|
@ -15,7 +15,7 @@ audience: ITPro
|
||||
ms.collection: M365-security-compliance
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Apply a basic audit policy on a file or folder
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Account Lockout
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Application Generated
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Application Group Management
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Audit Policy Change
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Authentication Policy Change
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Authorization Policy Change
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Central Access Policy Staging
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Certification Services
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Computer Account Management
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Credential Validation
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Detailed Directory Service Replication
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Detailed File Share
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Directory Service Access
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Directory Service Changes
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Directory Service Replication
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Distribution Group Management
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit DPAPI Activity
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit File Share
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit File System
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Filtering Platform Connection
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Filtering Platform Packet Drop
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Filtering Platform Policy Change
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Group Membership
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Handle Manipulation
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit IPsec Driver
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit IPsec Extended Mode
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit IPsec Main Mode
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit IPsec Quick Mode
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Kerberos Authentication Service
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Kerberos Service Ticket Operations
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Kernel Object
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Logoff
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Logon
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit MPSSVC Rule-Level Policy Change
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Network Policy Server
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Non-Sensitive Privilege Use
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Other Account Logon Events
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Other Account Management Events
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Other Logon/Logoff Events
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Other Object Access Events
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Other Policy Change Events
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Other Privilege Use Events
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Other System Events
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit PNP Activity
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Process Creation
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Process Termination
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Registry
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Removable Storage
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit RPC Events
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit SAM
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Security Group Management
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Security State Change
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Security System Extension
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Sensitive Privilege Use
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Special Logon
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit System Integrity
|
||||
|
@ -6,7 +6,7 @@ author: dansimp
|
||||
ms.author: dansimp
|
||||
ms.pagetype: security
|
||||
ms.prod: m365-security
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit Token Right Adjusted
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit User Account Management
|
||||
|
@ -12,7 +12,7 @@ ms.sitesec: library
|
||||
ms.localizationpriority: none
|
||||
author: dansimp
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit User/Device Claims
|
||||
|
@ -15,7 +15,7 @@ audience: ITPro
|
||||
ms.collection: M365-security-compliance
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit account logon events
|
||||
|
@ -15,7 +15,7 @@ audience: ITPro
|
||||
ms.collection: M365-security-compliance
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit account management
|
||||
|
@ -15,7 +15,7 @@ audience: ITPro
|
||||
ms.collection: M365-security-compliance
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit directory service access
|
||||
|
@ -15,7 +15,7 @@ audience: ITPro
|
||||
ms.collection: M365-security-compliance
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit logon events
|
||||
|
@ -15,7 +15,7 @@ audience: ITPro
|
||||
ms.collection: M365-security-compliance
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit object access
|
||||
|
@ -15,7 +15,7 @@ audience: ITPro
|
||||
ms.collection: M365-security-compliance
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit policy change
|
||||
|
@ -15,7 +15,7 @@ audience: ITPro
|
||||
ms.collection: M365-security-compliance
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit privilege use
|
||||
|
@ -15,7 +15,7 @@ audience: ITPro
|
||||
ms.collection: M365-security-compliance
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit process tracking
|
||||
|
@ -15,7 +15,7 @@ audience: ITPro
|
||||
ms.collection: M365-security-compliance
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Audit system events
|
||||
|
@ -15,7 +15,7 @@ audience: ITPro
|
||||
ms.collection: M365-security-compliance
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Basic security audit policies
|
||||
|
@ -15,7 +15,7 @@ audience: ITPro
|
||||
ms.collection: M365-security-compliance
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/06/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Basic security audit policy settings
|
||||
|
@ -15,7 +15,7 @@ audience: ITPro
|
||||
ms.collection: M365-security-compliance
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/07/2021
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Create a basic audit policy for an event category
|
||||
|
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: dansimp
|
||||
ms.author: dansimp
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# 1100(S): The event logging service has shut down.
|
||||
|
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: dansimp
|
||||
ms.author: dansimp
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# 1102(S): The audit log was cleared.
|
||||
|
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: dansimp
|
||||
ms.author: dansimp
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# 1104(S): The security log is now full.
|
||||
|
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: dansimp
|
||||
ms.author: dansimp
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# 1105(S): Event log automatic backup
|
||||
|
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: dansimp
|
||||
ms.author: dansimp
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# 1108(S): The event logging service encountered an error while processing an incoming event published from %1.
|
||||
|
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: dansimp
|
||||
ms.author: dansimp
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# 4608(S): Windows is starting up.
|
||||
|
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: dansimp
|
||||
ms.author: dansimp
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# 4610(S): An authentication package has been loaded by the Local Security Authority.
|
||||
|
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: dansimp
|
||||
ms.author: dansimp
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# 4611(S): A trusted logon process has been registered with the Local Security Authority.
|
||||
|
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: dansimp
|
||||
ms.author: dansimp
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# 4612(S): Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits.
|
||||
|
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: dansimp
|
||||
ms.author: dansimp
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# 4614(S): A notification package has been loaded by the Security Account Manager.
|
||||
|
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: dansimp
|
||||
ms.author: dansimp
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# 4615(S): Invalid use of LPC port.
|
||||
|
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: dansimp
|
||||
ms.author: dansimp
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# 4616(S): The system time was changed.
|
||||
|
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: dansimp
|
||||
ms.author: dansimp
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# 4618(S): A monitored security event pattern has occurred.
|
||||
|
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: dansimp
|
||||
ms.author: dansimp
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# 4621(S): Administrator recovered system from CrashOnAuditFail.
|
||||
|
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: dansimp
|
||||
ms.author: dansimp
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# 4622(S): A security package has been loaded by the Local Security Authority.
|
||||
|
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: dansimp
|
||||
ms.author: dansimp
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# 4624(S): An account was successfully logged on.
|
||||
|
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: dansimp
|
||||
ms.author: dansimp
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# 4625(F): An account failed to log on.
|
||||
|
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: dansimp
|
||||
ms.author: dansimp
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# 4626(S): User/Device claims information.
|
||||
|
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: dansimp
|
||||
ms.author: dansimp
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# 4627(S): Group membership information.
|
||||
|
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: dansimp
|
||||
ms.author: dansimp
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# 4634(S): An account was logged off.
|
||||
|
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: dansimp
|
||||
ms.author: dansimp
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# 4647(S): User initiated logoff.
|
||||
|
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: dansimp
|
||||
ms.author: dansimp
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# 4648(S): A logon was attempted using explicit credentials.
|
||||
|
@ -11,7 +11,7 @@ ms.date: 09/07/2021
|
||||
ms.reviewer:
|
||||
manager: dansimp
|
||||
ms.author: dansimp
|
||||
ms.technology: mde
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# 4649(S): A replay attack was detected.
|
||||
|
Some files were not shown because too many files have changed in this diff Show More
Loading…
x
Reference in New Issue
Block a user