Event 4673 is logged after "Audit Sensitive Privilege Use" is set to failure in Windows 8.1 or Windows Server 2012 R2


Event 4673 is logged in the event view two times every minute. For more information about the "Audit Sensitive Privilege Use" Group Policy Object (GPO), go to the "More Information" section.


To fix this issue, you can install the hotfix that's described in hotfix 3078584


Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section.


See the terminology that Microsoft uses to describe software updates.

More Information

Here's how to set the option of the "Audit Sensitive Privilege Use" GPO to failure:
  • Open Local Group Policy Editor.
  • In the navigation pane, select Computer Configuration > Windows Settings > Security Settings > Advanced Audit Policy Configuration > System Audit Policies - Local Group Policy Object > Privilege Use.
  • Press and hold (or right-click) Audit Sensitive Privilege Use, and then select Properties.
  • Under the Policy tab, select Configure the following audit events > Failure.

File Information

The English (United States) version of this software update installs files that have the attributes that are listed in the following tables. The dates and times for these files are listed in Coordinated Universal Time (UTC). Be aware that dates and times for these files on your local computer are displayed in your local time and with your current daylight saving time bias. The dates and times may also change when you perform certain operations on the files.
Additional file information

Article ID: 3084395 - Last Review: Sep 14, 2015 - Revision: 1