| Previous | Next |
| SL_E_TAMPER_RECOVERY_REQUIRES_ACTIVATION | ERROR_ALL_SIDS_FILTERED |
ERROR_AUDITING_DISABLED
Investigate security event not covered by current audit policy at the first returning call, before a wrapper substitutes a generic message. The caller requested or expected auditing for an event category that is not enabled in the effective audit policy.
The relevant contract
An audit-disabled result is not evidence that the protected operation itself failed; it says the requested audit record is not currently produced. Keep ERROR_AUDITING_DISABLED, its numeric value, and the first returning operation together.
Capture before changing state
| Capture | Diagnostic value |
|---|---|
| Audit subcategory GUID/name, effective policy, local/domain policy source, event producer, and caller token. | Identifies the concrete object and operation associated with security event not covered by current audit policy. |
| Auditpol output and the expected Security log event ID before changing policy. | Separates argument or lifecycle state from a lower-layer provider failure. |
| First security/authorization event and the exact API returning the HRESULT. | Creates a stable before-and-after comparison. |
| Effective identity and policy version at the time of the call. | Shows whether this condition is the first result or a translated summary. |
For ERROR_AUDITING_DISABLED preserve effective identity and policy version at the time of the call while evaluating this condition before reinstalling, rebooting, clearing state, or substituting another device or provider. A success observed only after such a change is useful comparison data for this HRESULT but it does not identify the original cause.
Focused experiments
- Enable only the relevant subcategory in a controlled policy scope. Repeat the original supported operation so the check remains tied to the same API boundary.
- Generate one known test event and confirm both success/failure settings. Keep unrelated inputs fixed so the changed result remains attributable to the tested variable.
- Repeat after one policy refresh without changing the resource ACL or application data.
A defensible resolution
Targeted correction. Enable the required audit subcategory through the authoritative policy source and document log volume/retention impact.
Acceptance criterion. The controlled event creates the expected record and policy refresh does not revert the setting.
Technical references
References for ERROR_AUDITING_DISABLED on the deployed platform version.
- Microsoft Open Specifications: HRESULT values — defines the status namespace used.
- Microsoft: HRESULT facility extraction — documents the API or lifecycle behind this condition.
- Microsoft: Windows security auditing overview — provides ABI, implementation, or protocol context.
- Microsoft: Authorization Manager — supports the portability and verification limits.
Looking for a different code? Search another status or error code.