en-US windows computer

Limit remote access to the Event Log Service

Verified with Windows 11 25H2 — updated on July 12, 2026

Windows 11 25H2

Supported on: At least Windows 11 Version 22H1

Path in the GPO console

Computer Configuration\Administrative Templates\Windows Components\Event Log Service

Description

This policy setting controls which remote users will be allowed to connect to the Event Log service on this machine. If you enable this policy, you can restrict which group remote users must be a member of in order to connect to the Event Log Service on this machine. You can require that remote users be a member of one of the following builtin groups: • Authenticated Users • EventLog Readers • Administrators If you disable or do not configure this policy, the default value will be Authenticated Users. For prior versions of Windows, only Authenticated Users was supported. To maintain backwards compatability, local connections to the service will always be allowed from Authenticated Users. This setting does not control access to individual logs. Once a remote connection is allowed, it will still need access to the specific resources it is attempting to use.

Registry

HKLM Software\Policies\Microsoft\Windows\EventLog

Value name: EnableRemoteRpcAccessRestrictions

Enabled: EnableRemoteRpcAccessRestrictions = 1

Disabled: EnableRemoteRpcAccessRestrictions = 0

More options available

Options

Pick one of the following settings:
RpcAccess_Remote_Setting enum
  • Authenticated Users -> 0 (default)
  • Event Log Readers -> 1
  • Administrators -> 2

Export Builder

BETA

Configure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.

These exports write the registry — this is not a managed GPO.

.reg file

Windows Registry Editor Version 5.00

; Exported from gporais.com
; Policy: Limit remote access to the Event Log Service
; State: Enabled
; Supported on: At least Windows 11 Version 22H1

[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\EventLog]
"EnableRemoteRpcAccessRestrictions"=dword:00000001
"RpcAccess_Remote_Setting"=dword:00000000
More formats (PowerShell, Intune, SCCM)

PowerShell

# Exported from gporais.com
# Policy: Limit remote access to the Event Log Service
# State: Enabled
# Supported on: At least Windows 11 Version 22H1

$path = 'HKLM:\Software\Policies\Microsoft\Windows\EventLog'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'EnableRemoteRpcAccessRestrictions' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'RpcAccess_Remote_Setting' -Value 0 -Type DWord

Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.

Open the Builder

Embed this policy on your site

What to embed
Theme

Adds one script line: the theme follows your site’s appearance and the height fits the content. If your site blocks scripts, the embed follows the visitor’s system theme.

Preview