What does Windows error code 785 (ERROR_ACCESS_AUDIT_BY_POLICY) mean?

 
Previous Next
ERROR_MCA_EXCEPTION ERROR_ACCESS_DISABLED_NO_SAFER_UI_BY_POLICY

ERROR_ACCESS_AUDIT_BY_POLICY

access to the object is being audited because of a policy rule.

ERROR_ACCESS_AUDIT_BY_POLICY indicates this condition. This code is informational: an access attempt matched a policy that requests auditing. It does not necessarily say that access was denied. The formatted message normally identifies both the object and the rule that caused monitoring.

Where the result appears

  • Windows security auditing and advanced audit policy processing.
  • resource access controlled by central access policies.
  • file-server or compliance software presenting policy evaluation details.
  • security telemetry that records why an otherwise successful open generated an audit.

What to collect

  • the object path or resource identifier and requested access mask.
  • the user, group, device, and claims used during evaluation.
  • the central access or audit rule name and policy version.
  • the matching Security log event, outcome, and correlation identifier.

Handling and recovery

Record the event as policy-driven visibility. If audit volume is unexpectedly high, adjust the rule scope rather than suppressing the status in application code. When access also failed, keep the denial code separately because this value alone does not express authorization failure.

Common misinterpretation

Do not display “access denied” solely from it. A request may succeed and still be audited.

References


Looking for a different code? Search another status or error code.