Audit Audit Policy Change

Applies To: Windows 7, Windows Server 2008 R2

This security policy setting determines whether the operating system generates audit events when changes are made to audit policy, including:

  • Permissions and audit settings on the audit policy object (by using auditpol /set /sd).

  • Changing the system audit policy.

  • Registration and de-registration of security event sources.

  • Changing per-user audit settings.

  • Changing the value of CrashOnAuditFail.

  • Changing audit settings on an object (for example, modifying the system access control list (SACL) for a file or registry key.)


SACL change auditing is performed when a SACL for an object has changed and the Policy Change category is configured. Discretionary access control list (DACL) and owner change auditing is performed when Object Access auditing is configured and the object's SACL is set for auditing of the DACL or owner change.

  • Changes made to the Special Groups list.


Changes to the audit policy are critical security events.

Event volume: Low

Default: Success

If this policy setting is configured, the following events are generated. The events appear on computers running Windows Server 2008 R2, Windows Server 2008, Windows 7, or Windows Vista, unless otherwise noted.

Event ID Event message


The audit policy (SACL) on an object was changed.


System audit policy was changed.


Auditing settings on an object were changed.

This event is logged only on computers running Windows Server 2008 R2 or Windows 7.


The Per-user audit policy table was created.


An attempt was made to register a security event source.


An attempt was made to unregister a security event source.


The CrashOnAuditFail value has changed.


Auditing settings on object were changed.


Special Groups Logon table modified.


Per User Audit Policy was changed.