Audit privilege use

Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy

Description

Determines whether to audit each instance of a user exercising a user right.

If you define this policy setting, you can specify whether to audit successes, audit failures, or not audit the event type at all. Success audits generate an audit entry when the exercise of a user right succeeds. Failure audits generate an audit entry when the exercise of a user right fails. To set this value to no auditing, in the Properties dialog box for this policy setting, select the Define these policy settings check box and clear the Success and Failure check boxes.

Default: Audits are not generated for use of the following user rights, even if success audits or failure audits are specified for "Audit privilege use":

Bypass traverse checking

Debug programs

Create a token object

Replace process level token

Generate security audits

Back up files and directories

Restore files and directories

For more information, see:

Security Configuration Manager Tools



© 2013 Microsoft Corporation. All rights reserved. Contact Us |Terms of Use |Trademarks |Privacy Statement