Event Id4912
SourceMicrosoft-Windows-Security-Auditing
DescriptionPer User Audit Policy was changed.

Subject:
      Security ID: <Security ID>
      Account Name: <Account Name>
      Account Domain: <Domain Name>
      Logon ID: <Logon ID>     

Policy For Account:
      Security ID:<Security ID>     

Policy Change Details:
      Category: <Category>
      Subcategory: <Subcategory>
      Subcategory GUID: <Subcategory GUID>
      Changes: <Changes>     

Event InformationCause :
This event is logged when the user set audit policy as well as the category, subcategory and the nature of the change in terms of success/failure and include/exclude.
Reference Links


  Did this information help you to resolve the problem?
  Yes: My problem was resolved.
  No: The information was not helpful / Partially helpful.
  Comments:

Captcha  Refresh