windows-itpro-docs/windows/keep-secure/audit-application-generated.md
Jan Backstrom f046a5fec0 tagging update
change W10 to w10 (lower case), add security pagetype to various
2016-05-26 17:07:01 -07:00

1.7 KiB

title, description, ms.assetid, ms.prod, ms.mktglfcycl, ms.sitesec, ms.pagetype, author
title description ms.assetid ms.prod ms.mktglfcycl ms.sitesec ms.pagetype author
Audit Application Generated (Windows 10) This topic for the IT professional describes the Advanced Security Audit policy setting, Audit Application Generated, which determines whether the operating system generates audit events when applications attempt to use the Windows Auditing application programming interfaces (APIs). 6c58a365-b25b-42b8-98ab-819002e31871 w10 deploy library security brianlic-msft

Audit Application Generated

Applies to

  • Windows 10

This topic for the IT professional describes the Advanced Security Audit policy setting, Audit Application Generated, which determines whether the operating system generates audit events when applications attempt to use the Windows Auditing application programming interfaces (APIs).

The following events can generate audit activity:

  • Creation, deletion, or initialization of an application client context
  • Application operations

Applications that are designed to use the Windows Auditing APIs can use this subcategory to log auditing events that are related to those APIs. The level, volume, relevance, and importance of these audit events depend on the application that generates them. The operating system logs the events as they are generated by the application.

Event volume: Depends on the installed app's use of the Windows Auditing APIs

Default: Not configured

Event ID Event message
4665 An attempt was made to create an application client context.
4666 An application attempted an operation:
4667 An application client context was deleted.