Files
windows-itpro-docs/windows/keep-secure/audit-registry.md
2016-03-21 11:28:01 -07:00

1.9 KiB

title, description, ms.assetid, ms.prod, ms.mktglfcycl, ms.sitesec, author
title description ms.assetid ms.prod ms.mktglfcycl ms.sitesec author
Audit Registry (Windows 10) This topic for the IT professional describes the Advanced Security Audit policy setting, Audit Registry, which determines whether the operating system generates audit events when users attempt to access registry objects. 02bcc23b-4823-46ac-b822-67beedf56b32 W10 deploy library brianlic-msft

Audit Registry

Applies to

  • Windows 10
  • Windows 10 Mobile

This topic for the IT professional describes the Advanced Security Audit policy setting, Audit Registry, which determines whether the operating system generates audit events when users attempt to access registry objects.

Audit events are generated only for objects that have configured system access control lists (SACLs) specified, and only if the type of access requested (such as Write, Read, or Modify) and the account making the request match the settings in the SACL.

If success auditing is enabled, an audit entry is generated each time any account successfully accesses a registry object that has a matching SACL. If failure auditing is enabled, an audit entry is generated each time any user unsuccessfully attempts to access a registry object that has a matching SACL.

Event volume: Low to medium, depending on how registry SACLs are configured

Default: Not configured

Event ID Event message

4657

A registry value was modified.

5039

A registry key was virtualized.

 

Advanced security audit policy settings