Windows Security Log Event ID 857

Operating Systems Windows 2003 and XP
CategoryPolicy Change
Type Success
Corresponding events
in Windows 2008
and Vista
 

857: The Windows Firewall setting to allow remote administration, allowing port TCP 135 and DCOM/RPC, has changed

On this page

Windows logs this event when an administrator changes the local policy of the Windows Firewall or a group policy refresh results in setting the Windows Firewall setting to allow or disable remote administration.

Free Security Log Resources by Randy

Description Fields in 857

  • Policy origin: Group Policy or Local Policy
  • Profile changed: Standard or Domain

New Settings:

  • Allow remote administration: Enabled or Disabled

Old Settings:

  • Allow remote administration: Enabled or Disabled

 

Supercharger Free Edition


Your entire Windows Event Collection environment on a single pane of glass.

Free.

 

Examples of 857

The Windows Firewall setting to allow remote administration, allowing port TCP 135 and DCOM/RPC, has changed.
 
Policy origin: Group Policy
Profile changed: Standard
New Setting:
     Allow remote administration: Enabled
Old Setting:
     Allow remote administration: Disabled

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection

 

Upcoming Webinars
    Additional Resources

      Go To Event ID:

      Security Log
      Quick Reference
      Chart
      Download now!