Policy-ChangeWindows Event ID 4670: Permissions on an object were changedJuly 3, 2026Windows Event ID 4703: A user right (token privilege) was adjustedJuly 3, 2026Windows Event ID 4704: A user right was assignedJuly 3, 2026Windows Event ID 4705: A user right was removedJuly 3, 2026Windows Event ID 4706: A new trust was created to a domainJuly 3, 2026Windows Event ID 4707: A trust to a domain was removedJuly 3, 2026Windows Event ID 4713: Kerberos policy was changedJuly 3, 2026Windows Event ID 4714: Encrypted data recovery policy was changedJuly 3, 2026Windows Event ID 4715: The audit policy (SACL) on an object was changedJuly 3, 2026Windows Event ID 4716: Trusted domain information was modifiedJuly 3, 2026Windows Event ID 4717: System security access was granted to an accountJuly 3, 2026Windows Event ID 4718: System security access was removed from an accountJuly 3, 2026Windows Event ID 4719: System audit policy was changedJuly 3, 2026Windows Event ID 4739: Domain Policy was changedJuly 3, 2026Windows Event ID 4817: Auditing settings on object were changed (Global Object Access)July 3, 2026Windows Event ID 4819: Central Access Policies on the machine have been changedJuly 3, 2026Windows Event ID 4826: Boot Configuration Data loadedJuly 3, 2026Windows Event ID 4864: A namespace collision was detectedJuly 3, 2026Windows Event ID 4865: A trusted forest information entry was addedJuly 3, 2026Windows Event ID 4866: A trusted forest information entry was removedJuly 3, 2026Windows Event ID 4867: A trusted forest information entry was modifiedJuly 3, 2026Windows Event ID 4902: The Per-user audit policy table was createdJuly 3, 2026Windows Event ID 4904: An attempt was made to register a security event sourceJuly 3, 2026Windows Event ID 4905: An attempt was made to unregister a security event sourceJuly 3, 2026Windows Event ID 4906: The CrashOnAuditFail value has changedJuly 3, 2026Windows Event ID 4907: Auditing settings on object were changedJuly 3, 2026Windows Event ID 4908: Special Groups Logon table modifiedJuly 3, 2026Windows Event ID 4909: The local policy settings for the TBS were changedJuly 3, 2026Windows Event ID 4910: The group policy settings for the TBS were changedJuly 3, 2026Windows Event ID 4911: Resource attributes of the object were changedJuly 3, 2026Windows Event ID 4912: Per User Audit Policy was changedJuly 3, 2026Windows Event ID 4913: Central Access Policy on the object was changedJuly 3, 2026Windows Event ID 5063: A cryptographic provider operation was attemptedJuly 3, 2026Windows Event ID 5064: A cryptographic context operation was attemptedJuly 3, 2026Windows Event ID 5065: A cryptographic context modification was attemptedJuly 3, 2026Windows Event ID 5066: A cryptographic function operation was attemptedJuly 3, 2026Windows Event ID 5067: A cryptographic function modification was attemptedJuly 3, 2026Windows Event ID 5068: A cryptographic function provider operation was attemptedJuly 3, 2026Windows Event ID 5069: A cryptographic function property operation was attemptedJuly 3, 2026Windows Event ID 5070: A cryptographic function property modification was attemptedJuly 3, 2026Windows Event ID 5447: A Windows Filtering Platform filter has been changedJuly 3, 2026Windows Event ID 6144: Security policy in the Group Policy objects has been applied successfullyJuly 3, 2026Windows Event ID 6145: One or more errors occurred while processing security policy in the Group Policy objectsJuly 3, 2026