TopicWindows Server →
Windows audit strategy has been modified.
Source of event
Microsoft-Windows-Security-Auditing — Security category.
Possible causes
- Application of a GPO
- Legitimate hardening
- Attempts to reduce logging
Verifications to be carried out
- Identify modified categories
- Correlate with GPO changes
- Check the author of the change
Useful orders….
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4719} -MaxEvents 20
To be retained….
An Event ID must always be interpreted with its source, its full message, its timing and the context of the system. The same number may exist in several providers of events.