Home / Security Commands / auditpol

auditpol

Audit Policy Manager

What Does It Do?

The auditpol command displays information about and performs functions to manipulate audit policies in Windows. It allows administrators to configure what security events are logged in the Windows Security Event Log.

Think of it like setting up security cameras in your building. You decide what activities to monitor (logons, file access, policy changes) and auditpol configures Windows to track those events for security analysis and compliance.

Advertisement

[ Insert Google AdSense Banner Code Here ]

When Should I Use It?

Security Monitoring

Track user logons, file access, and security policy changes.

Compliance Requirements

Meet PCI-DSS, HIPAA, and other regulatory audit requirements.

Incident Investigation

Collect evidence after security breaches or suspicious activity.

Policy Backup & Restore

Save and restore audit configurations across systems.

Common Commands

auditpol /get /category:*

Display all current audit policy settings for all categories.

auditpol /list /category

List all available audit policy categories.

auditpol /list /subcategory

List all available audit subcategories.

auditpol /set /subcategory:"Logon" /success:enable

Enable success auditing for logon events.

auditpol /backup /file:C:\audit.csv

Backup current audit policy to a file.

Administrator Privileges Required

All auditpol commands require Administrator privileges to view or configure audit policies.

To run commands as Administrator in the simulator:

1.
runas /user:administrator cmd

Request administrator privileges

2.
admin123

Enter the password when prompted

3.
auditpol /get /category:*

Now you can use auditpol commands

Real Windows: Right-click Command Prompt and select "Run as administrator" before running auditpol commands.

Try It Yourself

Practice auditpol commands in the interactive terminal below: