IT Toolbox

Event ID 4719 — Modification of the audit strategy

View my favorites

Windows audit strategy has been modified.

Source of event

Microsoft-Windows-Security-Auditing — Security category.

Possible causes

  • Application of a GPO
  • Legitimate hardening
  • Attempts to reduce logging

Verifications to be carried out

  1. Identify modified categories
  2. Correlate with GPO changes
  3. Check the author of the change

Useful orders….

Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4719} -MaxEvents 20

To be retained….

An Event ID must always be interpreted with its source, its full message, its timing and the context of the system. The same number may exist in several providers of events.

♡ 0