3.3 KiB
title, description, ms.pagetype, ms.prod, ms.mktglfcycl, ms.sitesec, author
title | description | ms.pagetype | ms.prod | ms.mktglfcycl | ms.sitesec | author |
---|---|---|---|---|---|---|
4946(S) A change has been made to Windows Firewall exception list. A rule was added. (Windows 10) | Describes security event 4946(S) A change has been made to Windows Firewall exception list. A rule was added. | security | w10 | deploy | library | Mir0sh |
4946(S): A change has been made to Windows Firewall exception list. A rule was added.
Applies to
- Windows 10
- Windows Server 2016

Subcategory: Audit MPSSVC Rule-Level Policy Change
Event Description:
This event generates when new rule was locally added to Windows Firewall.
This event doesn't generate when new rule was added via Group Policy.
Note
For recommendations, see Security Monitoring Recommendations for this event.
Event XML:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
<Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
<EventID>4946</EventID>
<Version>0</Version>
<Level>0</Level>
<Task>13571</Task>
<Opcode>0</Opcode>
<Keywords>0x8020000000000000</Keywords>
<TimeCreated SystemTime="2015-10-03T20:05:42.078367200Z" />
<EventRecordID>1050893</EventRecordID>
<Correlation />
<Execution ProcessID="500" ThreadID="528" />
<Channel>Security</Channel>
<Computer>DC01.contoso.local</Computer>
<Security />
</System>
- <EventData>
<Data Name="ProfileChanged">All</Data>
<Data Name="RuleId">{F2649D59-1355-4E3C-B886-CDD08B683199}</Data>
<Data Name="RuleName">Allow All Rule</Data>
</EventData>
</Event>
Required Server Roles: None.
Minimum OS Version: Windows Server 2008, Windows Vista.
Event Versions: 0.
Field Descriptions:
Profile Changed [Type = UnicodeString]: the list of profiles to which new rule was applied. Examples:
-
All
-
Domain,Public
-
Domain,Private
-
Private,Public
-
Public
-
Domain
-
Private
Added Rule:
-
Rule ID [Type = UnicodeString]: the unique new firewall rule identifier.
To see the unique ID of the rule you need to navigate to “HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules” registry key and you will see the list of Windows Firewall rule IDs (Name column) with parameters:

- Rule Name [Type = UnicodeString]: the name of the rule which was added. You can see the name of Windows Firewall rule using Windows Firewall with Advanced Security management console (wf.msc), check “Name” column:

Security Monitoring Recommendations
For 4946(S): A change has been made to Windows Firewall exception list. A rule was added.
- This event can be helpful in case you want to monitor all creations of new Firewall rules which were done locally.