Microsoft-Windows-SoftwareRestrictionPolicies

6 events across 1 channel

Event ID 50 — Access to %1 is monitored by policy rule %2.

Provider
Microsoft-Windows-SoftwareRestrictionPolicies
Channel
Application

Message

Access to %1 is monitored by policy rule %2.

Fields

NameDescription
AttemptedPath
SrpRuleGuid

Event ID 865 — Access to %1 has been restricted by your Administrator by the default software restriction policy level.

Provider
Microsoft-Windows-SoftwareRestrictionPolicies
Channel
Application

Message

Access to %1 has been restricted by your Administrator by the default software restriction policy level.

Fields

NameDescription
AttemptedPath

Sigma Rules

Event ID 866 — Access to %1 has been restricted by your Administrator by location with policy rule %2 placed on path %3.

Provider
Microsoft-Windows-SoftwareRestrictionPolicies
Channel
Application

Message

Access to %1 has been restricted by your Administrator by location with policy rule %2 placed on path %3.

Fields

NameDescription
AttemptedPath
SrpRuleGuid
RulePath

Sigma Rules

Event ID 867 — Access to %1 has been restricted by your Administrator by software publisher policy.

Provider
Microsoft-Windows-SoftwareRestrictionPolicies
Channel
Application

Message

Access to %1 has been restricted by your Administrator by software publisher policy.

Fields

NameDescription
AttemptedPath

Sigma Rules

Event ID 868 — Access to %1 has been restricted by your Administrator by policy rule %2.

Provider
Microsoft-Windows-SoftwareRestrictionPolicies
Channel
Application

Message

Access to %1 has been restricted by your Administrator by policy rule %2.

Fields

NameDescription
AttemptedPath
SrpRuleGuid

Sigma Rules

Event ID 882 — Access to %1 has been restricted by your Administrator by policy rule %2.

Provider
Microsoft-Windows-SoftwareRestrictionPolicies
Channel
Application

Message

Access to %1 has been restricted by your Administrator by policy rule %2.

Fields

NameDescription
AttemptedPath
SrpRuleGuid

Sigma Rules