Hello Yury,
The ACCESS_*_CALLBACK_OBJECT_ACE is a conditional ACE used by the AuthZ framework for Claims-Based Access Control. The AccessCheckByTypeResultListAndAuditAlarmByHandle API uses the common SeAccessCheck routine, which does not recognize Callback Object ACEs. The AuthZ API AuthZAccessCheck is used to assess conditional ACEs.
[MS-DTYP] accurately describes the ACE, but does not intend to discuss usage. For more information, see [MS-AZOD], and:
Checking Access with Authz API
https://learn.microsoft.com/en-us/windows/win32/secauthz/checking-access-with-authz-api
For this and other API questions, you may get better results by using the windows-api-system-services tag:
https://learn.microsoft.com/en-us/answers/topics/364719/windows-api-system-services.html
Best Regards,
Jeff McCashland
Microsoft Open Specifications