| Previous | Next |
| ERROR_BAD_COMPRESSION_BUFFER | ERROR_TIMER_RESOLUTION_NOT_SET |
ERROR_AUDIT_FAILED
What ERROR_AUDIT_FAILED means
The code concerns the auditing path, not merely the business operation being audited. Depending on security policy, failure to record an audit can cause the original operation to fail because allowing it without an audit trail would violate policy.
Where it commonly appears
- Security-sensitive logon and authorization paths
- Services generating mandatory object-access audits
- Systems with strict audit-failure policy
- Security event-log or LSA failures
Likely causes
- The security event log or audit subsystem is unavailable
- Audit storage is full or cannot be written
- A required audit parameter is invalid
- Policy requires auditing but the caller cannot complete it
- A security service is shutting down or unhealthy
Troubleshooting checklist
- Check the Security and System logs for audit-service and event-log failures
- Verify event-log capacity, retention policy, and disk free space
- Identify whether the operation succeeds when the relevant audit policy is not mandatory in a controlled test
- Record the privilege set, object, operation, and policy category involved
- Check for service restarts or policy refresh at the same time
Guidance for developers
Do not bypass mandatory auditing or silently downgrade the operation. Return the failure to the caller and preserve the security context. Avoid recursive logging paths where reporting the audit failure itself requires the same unavailable audit channel.
Guidance for administrators
Restore the event-log and security services, free or archive log space according to policy, and verify audit configuration. Changes to audit policy should follow organizational security controls rather than being used as an ad hoc workaround.
Example
A privileged configuration change requires a success audit, but the Security log cannot accept new records. Windows rejects the change with this code. Expanding or repairing the log restores the operation while preserving the audit requirement.
Related conditions
This is not equivalent to ERROR_ACCESS_DENIED. Authorization may have succeeded; the operation failed because the required audit record could not be completed.
References
Looking for a different code? Search another status or error code.
