Back to all events4719GPO & policyCRITLast updated:
System audit policy was changed
What it means
Someone changed what gets logged. Attackers disable auditing right before the real action — hence critical.
First steps
- 1Check the Subject and the source host.
- 2Compare with the approved policy (auditpol /get /category:*).
- 3If unplanned, treat as a security incident, not a glitch.
Related events
This reference is a starting point for investigation, not a replacement for your organisation's security policy.