Microsoft-Windows-EDP-Audit-Regular
2 events across 1 channel
| Event | Title | Channel | Sample |
|---|---|---|---|
| 201 | DataInfo has been copied (Policy) from SourceAppName (tagged as … | Admin | N |
| 301 | Object has been changed from SourceName (tagged as SourceEnterpriseId) to … | Admin | N |
Event ID 201: DataInfo has been copied (Policy) from SourceAppName (tagged as SourceEnterpriseId) to DestinationAppName (tagged as DestinationEnterpriseId).
#Description
DataInfo has been copied (Policy) from SourceAppName (tagged as SourceEnterpriseId) to DestinationAppName (tagged as DestinationEnterpriseId).
Message #
Fields #
| Name | Description |
|---|---|
UserId SID | |
Policy UnicodeString | |
Justification UnicodeString | |
SourceEnterpriseId UnicodeString | |
SourceAppName UnicodeString | |
DestinationEnterpriseId UnicodeString | |
DestinationAppName UnicodeString | |
DataInfo UnicodeString |
Event ID 301: Object has been changed from SourceName (tagged as SourceEnterpriseId) to DestinationName (tagged as DestinationEnterpriseId) in ApplicationName.
#Description
Object has been changed from SourceName (tagged as SourceEnterpriseId) to DestinationName (tagged as DestinationEnterpriseId) in ApplicationName.
Message #
Fields #
| Name | Description |
|---|---|
UserId SID | |
Policy UnicodeString | |
Object UnicodeString | |
Action UInt32 | |
SourceName UnicodeString | |
SourceEnterpriseId UnicodeString | |
DestinationName UnicodeString | |
DestinationEnterpriseId UnicodeString | |
ApplicationName UnicodeString |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 50f99b2d-96d2-421f-be4c-222c4140da9f
Defined in edpauditapi.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.2849, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1882, captured 2026-06-02