Audit policy change

This security setting determines whether the OS audits each instance of attempts to change user rights assignment policy, audit policy, account policy, or trust policy.

The administrator can specify whether to audit only successes, only failures, both successes and failures, or to not audit these events at all (i.e. neither successes nor failures).

If Success auditing is enabled, an audit entry is generated when an attempted change to user rights assignment policy, audit policy, or trust policy is successful.

If Failure auditing is enabled, an audit entry is generated when an attempted change to user rights assignment policy, audit policy, or trust policy is attempted by an account that is not authorized to make the requested policy change.

Policy path: 

Computer Configuration\Windows Settings\Local Policies\Audit Policy

Default: 

Success on domain controllers. No auditing on member servers.

Supported on: 

At least Windows XP SP2, Windows Server 2003

Registry settings: 

Audit Policy security settings are not registry keys.

Reboot required: 

No

Related content