Article ID: 272460 - Last Review: March 1, 2007 - Revision: 3.2 Information About Event 617 in the Security Event LogThis article was previously published under Q272460 SUMMARY
When the "Audit policy change" policy is enabled for either success or failure in the Default Domain Policy or Default Domain Controllers Policy Group Policy objects (GPO), a success event, event 617, is logged in the Windows 2000 Security log regardless of whether or not a policy change occurred.
MORE INFORMATION
The following list describes when a Security policy is propagated by default:
Date: 8/28/2000 Source: Security
Time: 4:10:18 PM Category: Policy Change
Type: Success Event ID: 617
User: NT AUTHORITY\SYSTEM
Computer: MALABO
Description:
"Kerberos Policy Changed:
Changed By:
User Name: MALABO$
Domain Name: INSULAR
Logon ID: (0x0,0x3E7)
Changes made:
('--' means no changes, otherwise each change is shown as:
<ParameterName>: <new value> (<old value>))
--
Date: 6/25/2000 Source: Security
Time: 5:56:48 PM Category: Policy Change
Type: Success Event ID: 617
User: NT AUTHORITY\SYSTEM
Computer: MALABO
Description:
"Kerberos Policy Changed:
Changed By:
User Name: MALABO$
Domain Name: INSULAR
Logon ID: (0x0,0x3E7)
Changes made:
('--' means no changes, otherwise each change is shown as:
<ParameterName>: <new value> (<old value>))
KerLogoff: 0x7683cd1a01a9f8b0 (0x7683cd1a01b5f8b0);
| Article Translations
|
Back to the top
