Audit Policy: Policy Change: Audit Policy Change (Failure)ID: oval:org.secpod.oval:def:18741 | Date: (C)2014-05-29 (M)2021-06-02 |
Class: COMPLIANCE | Family: windows |
Auditing of Policy Change: Audit Policy Change events on failure should be enabled or disabled as appropriate.
This security setting determines whether to audit every incident of a change to user rights assignment policies, audit policies, or trust policies. If you define this policy setting, you can specify whether to audit successes, audit failures, or not audit the event type at all. Success audits generate an audit entry when a change to user rights assignment policies, audit policies, or trust policies is successful. Failure audits generate an audit entry when a change to user rights assignment policies, audit policies, or trust policies fails.
Fix:
(1) GPO: Commandline: auditpol.exe
(2) REG: NO INFO
Platform: |
Microsoft Windows Server 2008 R2 |