4.8 KiB
title, description, ms.assetid, ms.pagetype, ms.prod, ms.mktglfcycl, ms.sitesec, author
title | description | ms.assetid | ms.pagetype | ms.prod | ms.mktglfcycl | ms.sitesec | author |
---|---|---|---|---|---|---|---|
Generate security audits (Windows 10) | Describes the best practices, location, values, policy management, and security considerations for the Generate security audits security policy setting. | c0e1cd80-840e-4c74-917c-5c2349de885f | security | W10 | deploy | library | brianlic-msft |
Generate security audits
Applies to
- Windows 10 Describes the best practices, location, values, policy management, and security considerations for the Generate security audits security policy setting.
Reference
This policy setting determines which accounts can be used by a process to generate audit records in the security event log. The Local Security Authority Subsystem Service (LSASS) writes events to the log. You can use the information in the security event log to trace unauthorized device access. Constant: SeAuditPrivilege
Possible values
- User-defined list of accounts
- Local Service
- Network Service
Best practices
- Because the audit log can potentially be an attack vector if an account is compromised, ensure that only the Local Service and Network Service accounts have the Generate security audits user right assigned to them.
Location
Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment
Default values
By default, this setting is Local Service and Network Service on domain controllers and stand-alone servers. The following table lists the actual and effective default policy values for the most recent supported versions of Windows. Default values are also listed on the policy’s property page.
Server type or GPO | Default value |
---|---|
Default Domain Policy |
Not defined |
Default Domain Controller Policy |
Local Service Network Service |
Stand-Alone Server Default Settings |
Local Service Network Service |
Domain Controller Effective Default Settings |
Local Service Network Service |
Member Server Effective Default Settings |
Local Service Network Service |
Client Computer Effective Default Settings |
Local Service Network Service |