| Previous | Next |
| STATUS_DS_VERSION_CHECK_FAILURE | STATUS_PRENT4_MACHINE_ACCOUNT |
STATUS_AUDITING_DISABLED
Current audit policy does not record this event
Audit generation depends on system policy and, for object access, matching SACL entries. A component can request an event that the effective subcategory excludes. This status does not mean access was denied or that the event data itself was invalid.
Determine the precise audit subcategory and whether success, failure, or both are enabled. Domain policy can override local settings, and basic and advanced audit policies should not be configured inconsistently. Enable only the required scope to avoid excessive Security-log volume.
What to inspect
- Identify the audit category/subcategory and success-or-failure flag.
- Compare local settings with effective Group Policy.
- Confirm any required object SACL is also present.
References
- Microsoft: Advanced Audit Policy Configuration
- Microsoft: Audit policy recommendations
- Microsoft: AuthzReportSecurityEvent
- Microsoft Open Specifications: NTSTATUS values
Looking for a different code? Search another status or error code.