24
792
Certificate Services denied a certificate request.
793
Certificate Services set the status of a certificate request to pending.
794
The certificate manager settings for Certificate Services changed.
795
A configuration entry changed in Certificate Services.
796
A property of Certificate Services changed.
797
Certificate Services archived a key.
798
Certificate Services imported and archived a key.
799
Certificate Services published the certificate authority (CA) certificate to Active Directory.
800
One or more rows have been deleted from the certificate database.
801
Role separation enabled.
Audit Policy Change
Member Server Default
Legacy Client
Enterprise Client
High Security Client
No Auditing
Success
Success
Success
The
Audit policy change
setting determines whether to audit every incident of a change to user rights
assignment policies, audit policies, or trust policies. This includes making changes to the audit policy
itself. Configuring this setting to
Success
generates an audit entry for each successful change to user
rights assignment policies, audit policies, or trust policies. Configuring this setting to
Failure
generates
an audit entry for each failed change to user rights assignment policies, audit policies, or trust
policies. The recommended settings would let administrators see any account privileges that an
attacker attempts to. Policy change auditing also includes making changes to the audit policy itself as
well as to trust relationships.
Note:
This guide recommends configuring the value for this setting to
Success
only because including
the setting value for
Failure
will not provide meaningful access information. Currently, setting this
value to
Failure
does not capture meaningful events.
Event ID
Event Description
608
A user right was assigned.
609
A user right was removed.
610
A trust relationship with another domain was created.
611
A trust relationship with another domain was removed.
612
An audit policy was changed.
613
An Internet Protocol security (IPSec) policy agent started.
614
An IPSec policy agent was disabled.
615
An IPSec policy agent changed.
616
An IPSec policy agent encountered a potentially serious failure.
617
A Kerberos version 5 policy changed.
618
Encrypted Data Recovery policy changed.
620
A trust relationship with another domain was modified.