17.9.4 (L1) Ensure 'Audit Security System Extension' is set to include 'Success' (Automated)
System_AuditSecuritySystemExtension
Last updated
System_AuditSecuritySystemExtension
Last updated
This policy setting allows you to audit events related to security system extensions or services such as the following: A security system extension, such as an authentication, notification, or security package is loaded and is registered with the Local Security Authority (LSA). It's used to authenticate logon attempts, submit logon requests, and any account or password changes. Examples of security system extensions are Kerberos and NTLM. A service is installed and registered with the Service Control Manager. The audit log contains information about the service name, binary, type, start type, and service account.