---
title: 4947(S) A change has been made to Windows Firewall exception list. A rule was modified. (Windows 10)
description: Describes security event 4947(S) A change has been made to Windows Firewall exception list. A rule was modified.
ms.pagetype: security
ms.prod: w10
ms.mktglfcycl: deploy
ms.sitesec: library
author: Mir0sh
---
# 4947(S): A change has been made to Windows Firewall exception list. A rule was modified.
**Applies to**
- Windows 10
- Windows Server 2016
***Subcategory:*** [Audit MPSSVC Rule-Level Policy Change](audit-mpssvc-rule-level-policy-change.md)
***Event Description:***
This event generates when Windows Firewall rule was modified.
This event doesn't generate when Firewall rule was modified via Group Policy.
> **Note** For recommendations, see [Security Monitoring Recommendations](#security-monitoring-recommendations) for this event.
***Event XML:***
```
-
-
4947
0
0
13571
0
0x8020000000000000
1050908
Security
DC01.contoso.local
-
All
{F2649D59-1355-4E3C-B886-CDD08B683199}
Allow All Rule
```
***Required Server Roles:*** None.
***Minimum OS Version:*** Windows Server 2008, Windows Vista.
***Event Versions:*** 0.
***Field Descriptions:***
**Profile Changed** \[Type = UnicodeString\]**:** the list of profiles to which changed rule is applied. Examples:
- All
- Domain,Public
- Domain,Private
- Private,Public
- Public
- Domain
- Private
**Modified Rule:**
- **Rule ID** \[Type = UnicodeString\]: the unique identifier for modified firewall rule.
To see the unique ID of the rule you need to navigate to “**HKEY\_LOCAL\_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SharedAccess\\Parameters\\FirewallPolicy\\FirewallRules”** registry key and you will see the list of Windows Firewall rule IDs (Name column) with parameters:
- **Rule Name** \[Type = UnicodeString\]: the name of the rule which was modified. You can see the name of Windows Firewall rule using Windows Firewall with Advanced Security management console (**wf.msc**), check “Name” column:
## Security Monitoring Recommendations
For 4947(S): A change has been made to Windows Firewall exception list. A rule was modified.
- This event can be helpful in case you want to monitor all Firewall rules modifications which were done locally.