4897: Role separation enabled
On this page
This event is logged whenever CS starts and whenever role separation is actually changed. Role separation is a form of "separation of duty" control that you can optionally enable on your Certification Authority to ensures that the compromise of a user's account - or a user going "rogue" - does not compromise the entire CA administered by the user
Role separation enabled: %1
Your entire Windows Event Collection environment on a single pane of glass.
Free.
Role separation enabled: No
Example of enabled
The certificate manager settings for Certificate Services changed.
Enable: Yes
Allow ACME-FR\Certificate Managers BUILTIN\Users Allow ACME-FR\Certificate Managers BUILTIN\Users Allow ACME-FR\Domain Admins Everyone Allow ACME-FR\Enterprise Admins Everyone Allow BUILTIN\Administrators Everyone
Top 10 Windows Security Events to Monitor
Free Tool for Windows Event Collection
Go To Event ID: Must be a 1-5 digit number No such event ID
Security Log Quick Reference Chart Download now!