Audit system events
Verified with Windows Security Options 25H2 — updated on July 25, 2026
Security policy
This is a Security Options policy (Windows Settings > Security Settings), applied by the security engine — not an Administrative Template (ADMX). In GPMC/gpedit it is configured under Local Policies > Security Options.
Path in the GPO console
Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy Description
This security setting determines whether the OS audits any of the following events: • Attempted system time change • Attempted security system startup or shutdown • Attempt to load extensible authentication components • Loss of audited events due to auditing system failure • Security log size exceeding a configurable warning threshold level. If this policy setting is defined, the administrator can specify whether to audit only successes, only failures, both successes and failures, or to not audit these events at all (i.e. neither successes nor failures). If Success auditing is enabled, an audit entry is generated each time the OS performs one of these activities successfully. If Failure auditing is enabled, an audit entry is generated each time the OS attempts and fails to perform one of these activities. Default: Security State Change Success Security System Extension No Auditing System Integrity Success, Failure IPsec Driver No Auditing Other System Eve
Local security policy
AuditSystemEvents This setting has no registry key. It is stored in the local security database (LSA) and is configured through the Group Policy console or secpol.msc.