4719 Security log · Policy Change high severity low volume

Windows Event ID 4719 — System audit policy was changed

System audit policy modified. SubcategoryGuid and SubcategoryName indicate what changed. AuditPolicyChanges shows the new setting.

Why event 4719 matters

Disabling audit policies blinds the SIEM (T1562.002). Disabling logon, process creation, or privilege use auditing directly reduces detection capability. Attackers do this immediately after gaining admin access.

How to detect it

Alert: any change that sets auditing to 'No Auditing'. Alert: changes outside business hours or by non-IT accounts. Baseline expected audit policy — any deviation warrants investigation.

Log source
Security
Advanced Audit Policy — enable the 'Policy Change' subcategory (Success and/or Failure).
Fields to pivot on
SubjectUserNameTargetUserNameLogonTypeIpAddressWorkstationName

MITRE ATT&CK mapping

Tactic Technique
Defense Evasion Disable Windows Event Logging (T1562.002)

Detection queries

Starting points — adapt the log source, projected fields and thresholds for your environment.

Sigma rule
title: Audit Policy Disabled
status: stable
description: Audit policy change disabling auditing
author: theadminstack.com
date: 2026/05/16
logsource:
    product: windows
    service: security
detection:
    selection:
        EventID: 4719
        AuditPolicyChanges|contains: 'No Auditing'
    condition: selection
falsepositives:
    - Legitimate GPO updates
level: high
tags:
    - attack.defense_evasion
    - attack.t1562.002
Sentinel / Defender KQL
SecurityEvent
| where EventID == 4719   // System audit policy was changed
| project TimeGenerated, Computer, SubjectUserName, TargetUserName, LogonType, IpAddress, WorkstationName
| sort by TimeGenerated desc
Splunk SPL
index=* sourcetype="WinEventLog:Security" EventCode=4719
| stats count earliest(_time) as first_seen latest(_time) as last_seen by ComputerName
| sort - count   `# System audit policy was changed — add EventData fields: SubjectUserName, TargetUserName, LogonType, IpAddress`
Hunt event 4719 in Sentinel/Defender →
Build a KQL query for this event in the KQL Query Builder.
Search all event IDs →
Open the interactive Windows Event ID lookup.

Related Policy Change events

4698 A scheduled task was created 4699 A scheduled task was deleted 4700 A scheduled task was enabled 4701 A scheduled task was disabled 4702 A scheduled task was updated 4703 A token right was adjusted 4704 A user right was assigned 4705 A user right was removed 4706 A new trust was created to a domain 4707 A trust to a domain was removed 4713 Kerberos policy was changed 4714 Encrypted data recovery policy was changed

Frequently asked questions

What is Windows Event ID 4719?

System audit policy was changed. System audit policy modified. SubcategoryGuid and SubcategoryName indicate what changed. AuditPolicyChanges shows the new setting.

Which log records event 4719?

Event 4719 is written to the Security channel by Microsoft-Windows-Security-Auditing. Advanced Audit Policy — enable the 'Policy Change' subcategory (Success and/or Failure).

What MITRE ATT&CK techniques map to event 4719?

Event 4719 is associated with: Disable Windows Event Logging (T1562.002).

How do you detect activity around event 4719?

Alert: any change that sets auditing to 'No Auditing'. Alert: changes outside business hours or by non-IT accounts. Baseline expected audit policy — any deviation warrants investigation.