--- title: Generate security audits (Windows 10) description: Describes the best practices, location, values, policy management, and security considerations for the Generate security audits security policy setting. ms.assetid: c0e1cd80-840e-4c74-917c-5c2349de885f ms.prod: W10 ms.mktglfcycl: deploy ms.sitesec: library author: brianlic-msft --- # Generate security audits **Applies to** - Windows 10 Describes the best practices, location, values, policy management, and security considerations for the **Generate security audits** security policy setting. ## Reference This policy setting determines which accounts can be used by a process to generate audit records in the security event log. The Local Security Authority Subsystem Service (LSASS) writes events to the log. You can use the information in the security event log to trace unauthorized device access. Constant: SeAuditPrivilege ### Possible values - User-defined list of accounts - Local Service - Network Service ### Best practices - Because the audit log can potentially be an attack vector if an account is compromised, ensure that only the Local Service and Network Service accounts have the **Generate security audits** user right assigned to them. ### Location Computer Configuration\\Windows Settings\\Security Settings\\Local Policies\\User Rights Assignment ### Default values By default, this setting is Local Service and Network Service on domain controllers and stand-alone servers. The following table lists the actual and effective default policy values for the most recent supported versions of Windows. Default values are also listed on the policy’s property page.
Server type or GPO | Default value |
---|---|
Default Domain Policy |
Not defined |
Default Domain Controller Policy |
Local Service Network Service |
Stand-Alone Server Default Settings |
Local Service Network Service |
Domain Controller Effective Default Settings |
Local Service Network Service |
Member Server Effective Default Settings |
Local Service Network Service |
Client Computer Effective Default Settings |
Local Service Network Service |