Windows Security Log Event ID 4902

Operating Systems Windows 2008 R2 and 7
Windows 2012 R2 and 8.1
Windows 2016 and 10
Windows Server 2019 and 2022
Category
 • Subcategory
Policy Change
 • Audit Policy Change
Type Success
Corresponding events
in Windows 2003
and before
 

4902: The Per-user audit policy table was created

On this page

This is a routine event logged at system startup and can be regarded as noise.

To learn more about per-user selective auditing see See Roger Grimes' article at www.windowsitpro.com for an excellent introduction to per user selective auditing.  But don't get your hopes up; it isn't a very practical feature; basically it's just there for Common Criteria compliance.

Free Security Log Resources by Randy

Description Fields in 4902

  • Number of Elements:
  • Policy ID:

Supercharger Free Edition


Your entire Windows Event Collection environment on a single pane of glass.

Free.

 

Examples of 4902

The Per-user audit policy table was created. 

   Number of Elements: 0
   Policy ID: 0x8d36

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection

 

Upcoming Webinars
    Additional Resources

      Go To Event ID:

      Security Log
      Quick Reference
      Chart
      Download now!