Audit Policy: Privilege Use: Other Privilege Use Events (Failure)ID: oval:org.secpod.oval:def:18753 | Date: (C)2014-05-29 (M)2021-06-02 |
Class: COMPLIANCE | Family: windows |
Auditing of Privilege Use: Other Privilege Use Events events on failure should be enabled or disabled as appropriate.
This security setting determines whether to audit each instance of a user exercising a user right. If you define this policy setting, you can specify whether to audit successes, audit failures, or not audit this type of event at all. Success audits generate an audit entry when the exercise of a user right succeeds. Failure audits generate an audit entry when the exercise of a user right fails.
Fix:
(1) GPO: Computer Configuration\Windows Settings\Security Settings\Advanced Audit Policy Configuration\System Audit Policies\Privilege Use\Audit Policy: Privilege Use: Other Privilege Use Events
(2) REG: NO INFO
Platform: |
Microsoft Windows Server 2008 R2 |