--- title: 4902(S) The Per-user audit policy table was created. (Windows 10) description: Describes security event 4902(S) The Per-user audit policy table was created. ms.pagetype: security ms.prod: w10 ms.mktglfcycl: deploy ms.sitesec: library author: Mir0sh --- # 4902(S): The Per-user audit policy table was created. **Applies to** - Windows 10 - Windows Server 2016 Event 4902 illustration ***Subcategory:*** [Audit Policy Change](audit-audit-policy-change.md) ***Event Description:*** This event generates during system startup if Per-user audit policy is defined on the computer. > **Note**  For recommendations, see [Security Monitoring Recommendations](#security-monitoring-recommendations) for this event.
***Event XML:*** ``` - - 4902 0 0 13568 0 0x8020000000000000 1049490 Security DC01.contoso.local - 1 0x703e ``` ***Required Server Roles:*** None. ***Minimum OS Version:*** Windows Server 2008, Windows Vista. ***Event Versions:*** 0. ***Field Descriptions:*** **Number of Elements** \[Type = UInt32\]: number of users for which Per-user policies were defined (number of unique users). You can get the list of users for which Per-user policies are defined using “auditpol /list /user” command: Auditpol list user illustration **Policy ID** \[Type = HexInt64\]: unique per-User Audit Policy hexadecimal identifier. ## Security Monitoring Recommendations For 4902(S): The Per-user audit policy table was created. - If you don’t expect to see any per-User Audit Policies enabled on specific computers (**Computer**), monitor for these events. - If you don’t use per-User Audit Policies in your network, monitor for these events. - Typically this is an informational event and has little to no security relevance.