Microsoft-Windows-Security-Auditing › Event 4882

Event ID 4882 — The security permissions for Certificate Services changed.

Provider
Microsoft-Windows-Security-Auditing
Channel
Security
Audit Policy
Object Access → Certification Services
Collection Priority
Recommended (NSA, others)
Opcode
Info

Description

The security permissions for Certificate Services changed.

Message #

The security permissions for Certificate Services changed.
	
%1

Fields #

NameDescription
SecuritySettings UnicodeString
SubjectUserSid SID
SubjectUserName UnicodeString
SubjectDomainName UnicodeString
SubjectLogonId HexInt64

Community Notes #

Records changes to a CA ACL, may indicate privilege escalation via addition of rogue accounts. Critical for detecting AD CS abuse.

References #