Defines local audit behavior and system response when audit logging fails. These settings control how Windows handles audit policy configuration and logging integrity on the local computer.
Fields
| Field Name | Description |
|---|---|
sCENoApplyLegacyAuditPolicy - Boolean
|
Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings. When enabled, this setting allows fine-grained audit policy management using subcategories, ensuring that Group Policy does not override them with broader category-level settings. |
crashOnAuditFail - Boolean
|
Shut down system immediately if unable to log security audits. When enabled, the system will force a shutdown if it cannot write audit events to the Security log (for example, if the log is full). This helps prevent operation without sufficient security audit coverage. |
Used by
LocalPoliciesWindowstype: Windows-specific local security and system policies.
Example
Example
{"sCENoApplyLegacyAuditPolicy": false, "crashOnAuditFail": true}