Endpoint configuration · GraphQL type

LocalAuditPolicy type

Defines local audit behavior and system response when audit logging fails. These settings control how Windows handles audit policy configuration and logging integrity on the local computer.

Fields

Field Name Description
sCENoApplyLegacyAuditPolicy - Boolean

Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings.

When enabled, this setting allows fine-grained audit policy management using subcategories, ensuring that Group Policy does not override them with broader category-level settings.

crashOnAuditFail - Boolean Shut down system immediately if unable to log security audits. When enabled, the system will force a shutdown if it cannot write audit events to the Security log (for example, if the log is full). This helps prevent operation without sufficient security audit coverage.

Used by

Example

Example

{"sCENoApplyLegacyAuditPolicy": false, "crashOnAuditFail": true}