Skip to content

Policy-Change

Windows Event ID 4670: Permissions on an object were changed

July 3, 2026

Windows Event ID 4703: A user right (token privilege) was adjusted

July 3, 2026

Windows Event ID 4704: A user right was assigned

July 3, 2026

Windows Event ID 4705: A user right was removed

July 3, 2026

Windows Event ID 4706: A new trust was created to a domain

July 3, 2026

Windows Event ID 4707: A trust to a domain was removed

July 3, 2026

Windows Event ID 4713: Kerberos policy was changed

July 3, 2026

Windows Event ID 4714: Encrypted data recovery policy was changed

July 3, 2026

Windows Event ID 4715: The audit policy (SACL) on an object was changed

July 3, 2026

Windows Event ID 4716: Trusted domain information was modified

July 3, 2026

Windows Event ID 4717: System security access was granted to an account

July 3, 2026

Windows Event ID 4718: System security access was removed from an account

July 3, 2026

Windows Event ID 4719: System audit policy was changed

July 3, 2026

Windows Event ID 4739: Domain Policy was changed

July 3, 2026

Windows Event ID 4817: Auditing settings on object were changed (Global Object Access)

July 3, 2026

Windows Event ID 4819: Central Access Policies on the machine have been changed

July 3, 2026

Windows Event ID 4826: Boot Configuration Data loaded

July 3, 2026

Windows Event ID 4864: A namespace collision was detected

July 3, 2026

Windows Event ID 4865: A trusted forest information entry was added

July 3, 2026

Windows Event ID 4866: A trusted forest information entry was removed

July 3, 2026

Windows Event ID 4867: A trusted forest information entry was modified

July 3, 2026

Windows Event ID 4902: The Per-user audit policy table was created

July 3, 2026

Windows Event ID 4904: An attempt was made to register a security event source

July 3, 2026

Windows Event ID 4905: An attempt was made to unregister a security event source

July 3, 2026

Windows Event ID 4906: The CrashOnAuditFail value has changed

July 3, 2026

Windows Event ID 4907: Auditing settings on object were changed

July 3, 2026

Windows Event ID 4908: Special Groups Logon table modified

July 3, 2026

Windows Event ID 4909: The local policy settings for the TBS were changed

July 3, 2026

Windows Event ID 4910: The group policy settings for the TBS were changed

July 3, 2026

Windows Event ID 4911: Resource attributes of the object were changed

July 3, 2026

Windows Event ID 4912: Per User Audit Policy was changed

July 3, 2026

Windows Event ID 4913: Central Access Policy on the object was changed

July 3, 2026

Windows Event ID 5063: A cryptographic provider operation was attempted

July 3, 2026

Windows Event ID 5064: A cryptographic context operation was attempted

July 3, 2026

Windows Event ID 5065: A cryptographic context modification was attempted

July 3, 2026

Windows Event ID 5066: A cryptographic function operation was attempted

July 3, 2026

Windows Event ID 5067: A cryptographic function modification was attempted

July 3, 2026

Windows Event ID 5068: A cryptographic function provider operation was attempted

July 3, 2026

Windows Event ID 5069: A cryptographic function property operation was attempted

July 3, 2026

Windows Event ID 5070: A cryptographic function property modification was attempted

July 3, 2026

Windows Event ID 5447: A Windows Filtering Platform filter has been changed

July 3, 2026

Windows Event ID 6144: Security policy in the Group Policy objects has been applied successfully

July 3, 2026

Windows Event ID 6145: One or more errors occurred while processing security policy in the Group Policy objects

July 3, 2026