PrivilegeUse_AuditSensitivePrivilegeUse
PrivilegeUse_AuditSensitivePrivilegeUse
Last updated
PrivilegeUse_AuditSensitivePrivilegeUse
Last updated
This policy setting allows you to audit events generated when sensitive privileges (user rights) are used such as the following: A privileged service is called. One of the following privileges are called: Act as part of the operating system. Back up files and directories. Create a token object. Debug programs. Enable computer and user accounts to be trusted for delegation. Generate security audits. Impersonate a client after authentication. Load and unload device drivers. Manage auditing and security log. Modify firmware environment values. Replace a process-level token. Restore files and directories. Take ownership of files or other objects.