Microsoft-Windows-Security-Audit-Configuration-Client
32 events across 2 channels
Event ID 100: Group policy processing for audit settings initiated.
#Description
Group policy processing for audit settings initiated.
Message #
Event ID 101: Group policy processing for audit settings could not be started.
#Event ID 102: List of applicable GPOs.
#Description
List of applicable GPOs.
Message #
Fields #
| Name | Description |
|---|---|
GPOList UnicodeString | List of applicable GPOs |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Security-Audit-Configuration-Client",
"guid": "08466062-AED4-4834-8B04-CDDB414504E5",
"event_source_name": "",
"event_id": 102,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2023-11-05T23:49:58.045589+00:00",
"event_record_id": 40,
"correlation": {
"ActivityID": "AA63BEC0-3996-4133-A97D-DB5DB9617FF3"
},
"execution": {
"process_id": 8540,
"thread_id": 9876
},
"channel": "Microsoft-Windows-Security-Audit-Configuration-Client/Operational",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"GPOList": "Local Group Policy\n"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 103: Group policy processing for audit settings started.
#Description
Group policy processing for audit settings started.
Message #
Event ID 104: Failed to create local directory for downloading audit settings.
#Event ID 105: Processing audit settings from the following GPO.
#Event ID 106: Successfully downloaded the audit settings file as follows.
#Event ID 107: Failed to downloaded the audit settings file as follows.
#Event ID 108: Successfully configured the audit settings on the system.
#Description
Successfully configured the audit settings on the system.
Message #
Event ID 109: Failed to configure the audit settings on the system.
#Event ID 110: Successfully generated RSoP data in WMI.
#Description
Successfully generated RSoP data in WMI.
Message #
Event ID 111: Failed to generate RSoP data in WMI.
#Event ID 112: Group policy processing for audit settings finished successfully.
#Description
Group policy processing for audit settings finished successfully.
Message #
Event ID 113: Group policy processing for audit settings finished with error.
#Description
Group policy processing for audit settings finished with error. Error: ErrorCode.
Message #
Fields #
| Name | Description |
|---|---|
ErrorCode UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Security-Audit-Configuration-Client",
"event_id": 113,
"level": "Error",
"task": null,
"opcode": "Stop",
"time_created": "2026-05-27T17:42:31.5884058+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Microsoft-Windows-Security-Audit-Configuration-Client/Operational"
},
"event_data": {
"ErrorCode": "2147944105"
}
}
Event ID 114: Successfully communicated the results of the operation to group policy engine.
#Description
Successfully communicated the results of the operation to group policy engine.
Message #
Event ID 115: Failed to communicate the results of the operation to group policy engine.
#Event ID 200: Group policy processing for central access policy settings initiated.
#Description
Group policy processing for central access policy settings initiated.
Message #
Event ID 201: Group policy processing for central access policy settings could not be started.
#Event ID 202: List of applicable GPOs.
#Event ID 203: Group policy processing for central access policy settings started.
#Description
Group policy processing for central access policy settings started.
Message #
Event ID 204: Failed to create local directory for downloading central access policy settings.
#Event ID 205: Processing central access policy settings from the following GPO.
#Event ID 206: Successfully downloaded the central access policy settings file as follows.
#Event ID 207: Failed to downloaded the central access policy settings file as follows.
#Event ID 208: Successfully configured the central access policy settings on the system.
#Description
Successfully configured the central access policy settings on the system.
Message #
Event ID 209: Failed to configure the central access policy settings on the system.
#Event ID 210: Successfully generated RSoP data in WMI.
#Description
Successfully generated RSoP data in WMI.
Message #
Event ID 211: Failed to generate RSoP data in WMI.
#Event ID 212: Group policy processing for central access policy settings finished successfully.
#Description
Group policy processing for central access policy settings finished successfully.
Message #
Event ID 213: Group policy processing for central access policy settings finished with error.
#Event ID 214: Successfully communicated the results of the operation to group policy engine.
#Description
Successfully communicated the results of the operation to group policy engine.
Message #
Event ID 215: Failed to communicate the results of the operation to group policy engine.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 08466062-aed4-4834-8b04-cddb414504e5
Defined in auditcse.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02