This security policy setting determines whether the operating system generates audit events for the following distribution group management tasks:
- A distribution group is created, changed, or deleted.
- A member is added to or removed from a distribution group.
- This subcategory is logged only on domain controllers. (Note: Distribution groups cannot be used to manage access control permissions.)
Event volume: Low
If this policy setting is configured, the following events are generated. The events appear on computers running Windows Server 2008 R2 or Windows Server 2008.
- 4744: A security-disabled local group was created.
- 4745: A security-disabled local group was changed.
- 4746: A member was added to a security-disabled local group.
- 4747: A member was removed from a security-disabled local group.
- 4748: A security-disabled local group was deleted.
- 4749: A security-disabled global group was created.
- 4750: A security-disabled global group was changed.
- 4751: A member was added to a security-disabled global group.
- 4752: A member was removed from a security-disabled global group.
- 4753: A security-disabled global group was deleted.
- 4759: A security-disabled universal group was created.
- 4760: A security-disabled universal group was changed.
- 4761: A member was added to a security-disabled universal group.
- 4762: A member was removed from a security-disabled universal group.
Scope:
Computer
Default:
Not configured