2.9 KiB
title, description, ms.assetid, ms.reviewer, manager, ms.author, ms.pagetype, ms.prod, ms.mktglfcycl, ms.sitesec, ms.localizationpriority, author, ms.date
title | description | ms.assetid | ms.reviewer | manager | ms.author | ms.pagetype | ms.prod | ms.mktglfcycl | ms.sitesec | ms.localizationpriority | author | ms.date |
---|---|---|---|---|---|---|---|---|---|---|---|---|
Audit Other Object Access Events (Windows 10) | The policy setting, Audit Other Object Access Events, determines if audit events are generated for the management of Task Scheduler jobs or COM+ objects. | b9774595-595d-4199-b0c5-8dbc12b6c8b2 | dansimp | dansimp | security | w10 | deploy | library | none | dansimp | 05/29/2017 |
Audit Other Object Access Events
Applies to
- Windows 10
- Windows Server 2016
Audit Other Object Access Events allows you to monitor operations with scheduled tasks, COM+ objects and indirect object access requests.
Event volume: Low.
Computer Type | General Success | General Failure | Stronger Success | Stronger Failure | Comments |
---|---|---|---|---|---|
Domain Controller | Yes | Yes | Yes | Yes | We recommend Success auditing first of all because of scheduled tasks events. We recommend Failure auditing to get events about possible ICMP DoS attack. |
Member Server | Yes | Yes | Yes | Yes | We recommend Success auditing first of all because of scheduled tasks events. We recommend Failure auditing to get events about possible ICMP DoS attack. |
Workstation | Yes | Yes | Yes | Yes | We recommend Success auditing first of all because of scheduled tasks events. We recommend Failure auditing to get events about possible ICMP DoS attack. |
Events List:
-
4671(-): An application attempted to access a blocked ordinal through the TBS.
-
4691(S): Indirect access to an object was requested.
-
5148(F): The Windows Filtering Platform has detected a DoS attack and entered a defensive mode; packets associated with this attack will be discarded.
-
5149(F): The DoS attack has subsided and normal processing is being resumed.
-
4698(S): A scheduled task was created.
-
4699(S): A scheduled task was deleted.
-
4700(S): A scheduled task was enabled.
-
4701(S): A scheduled task was disabled.
-
4702(S): A scheduled task was updated.
-
5888(S): An object in the COM+ Catalog was modified.
-
5889(S): An object was deleted from the COM+ Catalog.
-
5890(S): An object was added to the COM+ Catalog.