Audit policy change
Verified with Windows Security Options 25H2 — updated on July 25, 2026
Security policy
This is a Security Options policy (Windows Settings > Security Settings), applied by the security engine — not an Administrative Template (ADMX). In GPMC/gpedit it is configured under Local Policies > Security Options.
Path in the GPO console
Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy Description
This security setting determines whether the OS audits each instance of attempts to change user rights assignment policy, audit policy, account policy, or trust policy. The administrator can specify whether to audit only successes, only failures, both successes and failures, or to not audit these events at all (i.e. neither successes nor failures). If Success auditing is enabled, an audit entry is generated when an attempted change to user rights assignment policy, audit policy, or trust policy is successful. If Failure auditing is enabled, an audit entry is generated when an attempted change to user rights assignment policy, audit policy, or trust policy is attempted by an account that is not authorized to make the requested policy change. Default: Audit Policy Change: Success Authentication Policy Change: Success Authorization Policy Change: No Auditing MPSSVC Rule-Level Policy Change: No Auditing Filtering Platform Policy Change: No Auditing Other
Local security policy
AuditPolicyChange This setting has no registry key. It is stored in the local security database (LSA) and is configured through the Group Policy console or secpol.msc.