| Event Id | 4912 |
| Source | Microsoft-Windows-Security-Auditing |
| Description | Per User Audit Policy was changed.
Subject:
Security ID: <Security ID>
Account Name: <Account Name>
Account Domain: <Domain Name>
Logon ID: <Logon ID>
Policy For Account:
Security ID:<Security ID>
Policy Change Details:
Category: <Category>
Subcategory: <Subcategory>
Subcategory GUID: <Subcategory GUID>
Changes: <Changes>
|
| Event Information | Cause : This event is logged when the user set audit policy as well as the category, subcategory and the nature of the change in terms of success/failure and include/exclude. |
| Reference Links | |