Windows 10: How do I find the folders on which Audit policy is enabled?

Discus and support How do I find the folders on which Audit policy is enabled? in AntiVirus, Firewalls and System Security to solve the problem; Hello,I enabled Audit policy on a folder to delete files and folders within it. I enabled Audit policy on a folder to delete files and folders inside... Discussion in 'AntiVirus, Firewalls and System Security' started by Windows.Geek, Mar 10, 2025.

  1. How do I find the folders on which Audit policy is enabled?


    Hello,I enabled Audit policy on a folder to delete files and folders within it. I enabled Audit policy on a folder to delete files and folders inside it, but when I check the Security section in Event Viewer, I see that there are reports with ID 4663 for files like C:\Program Files x86\Kaspersky Lab\Kaspersky Security for Windows Server\kavfswp.exe and C:\Windows\System32\cmd.exe.How do I see a list of folders on which Audit policy is enabled?Thank you.

    :)
     
    Windows.Geek, Mar 10, 2025
    #1
  2. Amit_Sun Win User

    Folder Auditing/Effective Access

    Hi,



    Thank you for writing to Microsoft Community Forums.



    Yes, you will have to change the owner of the folder of file before changing the Effective access of a folder, if we don’t have the ownership and directly apply Effective Access, you will notice red cross on all the permission,
    which means it is not applied.



    You can apply audit policies
    to individual files and folders on your computer by setting the permission type to record successful access attempts or failed access attempts in the security log. To complete this procedure, you must be logged on as a member of the built-in Administrators
    group or you must have been granted the Manage auditing and security log right.



    Regards,

    Amit Sunar

    Microsoft Community – Moderator
     
    Amit_Sun, Mar 10, 2025
    #2
  3. Folder Auditing/Effective Access

    Does taking ownership also apply to the auditing tab not just the effective access?

    Would appreciate it if you can provide me with some clarification, again thanks in advance for your help!

     
    Karanza725, Mar 10, 2025
    #3
  4. aa4654 Win User

    How do I find the folders on which Audit policy is enabled?

    Audit policy

    Hi! I want to monitor user activities of each user, and I'm using winlogbeat on windows server VM to collect audit log. I enabled recommended policy following this link Audit Policy Recommendations

    I haven't login the machine for days, but the log still show many processes created by my user. For example, C:\Windows\System32\svchost.exe is created. It's has user test2, but I did not login as test2 for weeks. Another example, C:\Windows\System32\cleanmgr.exe is created with my user test2, and I did not run that process.

    So why does it have some created processes related to my user, while I did not do anything, and did not login? What does this mean? Thanks!
    How do I find the folders on which Audit policy is enabled? 752ba7bd-de3e-44b5-a70b-ec442867991f?upload=true.png

    How do I find the folders on which Audit policy is enabled? 15630fa5-90d7-4bc5-8331-e451765effe1?upload=true.png
     
    aa4654, Mar 10, 2025
    #4
Thema:

How do I find the folders on which Audit policy is enabled?

Loading...
  1. How do I find the folders on which Audit policy is enabled? - Similar Threads - find folders Audit

  2. How do I find the folders on which Audit policy is enabled?

    in Windows 10 Gaming
    How do I find the folders on which Audit policy is enabled?: Hello,I enabled Audit policy on a folder to delete files and folders within it. I enabled Audit policy on a folder to delete files and folders inside it, but when I check the Security section in Event Viewer, I see that there are reports with ID 4663 for files like C:\Program...
  3. How do I find the folders on which Audit policy is enabled?

    in Windows 10 Software and Apps
    How do I find the folders on which Audit policy is enabled?: Hello,I enabled Audit policy on a folder to delete files and folders within it. I enabled Audit policy on a folder to delete files and folders inside it, but when I check the Security section in Event Viewer, I see that there are reports with ID 4663 for files like C:\Program...
  4. Windows 10 Enterprise audit policy how to find out cost of implementation?

    in Windows 10 Network and Sharing
    Windows 10 Enterprise audit policy how to find out cost of implementation?: I am looking for support how to justify audit policy for network drive.Person name who last modified document is intermittently available on network drive but consistently available in SharePoint.How to know the Pros and Cons of implementing audit policy or is there a better...
  5. Windows 10 Enterprise audit policy how to find out cost of implementation?

    in Windows 10 Gaming
    Windows 10 Enterprise audit policy how to find out cost of implementation?: I am looking for support how to justify audit policy for network drive.Person name who last modified document is intermittently available on network drive but consistently available in SharePoint.How to know the Pros and Cons of implementing audit policy or is there a better...
  6. Windows 10 Enterprise audit policy how to find out cost of implementation?

    in Windows 10 Software and Apps
    Windows 10 Enterprise audit policy how to find out cost of implementation?: I am looking for support how to justify audit policy for network drive.Person name who last modified document is intermittently available on network drive but consistently available in SharePoint.How to know the Pros and Cons of implementing audit policy or is there a better...
  7. Audit policy

    in Windows 10 Gaming
    Audit policy: Hi! I want to monitor user activities of each user, and I'm using winlogbeat on windows server VM to collect audit log. I enabled recommended policy following this link...
  8. Audit policy

    in Windows 10 Software and Apps
    Audit policy: Hi! I want to monitor user activities of each user, and I'm using winlogbeat on windows server VM to collect audit log. I enabled recommended policy following this link...
  9. Audit policy

    in AntiVirus, Firewalls and System Security
    Audit policy: Hi! I want to monitor user activities of each user, and I'm using winlogbeat on windows server VM to collect audit log. I enabled recommended policy following this link...
  10. How do I enable Group Policy Editor.

    in AntiVirus, Firewalls and System Security
    How do I enable Group Policy Editor.: I have a window 10 laptop and am trying to download window group policy, I have searched everywhere online either am scare of virus or lose all my PC data....