Audit Distribution Group Management

This security policy setting determines whether the operating system generates audit events for the following distribution group management tasks:

  • A distribution group is created, changed, or deleted.
  • A member is added to or removed from a distribution group.
  • This subcategory is logged only on domain controllers. (Note: Distribution groups cannot be used to manage access control permissions.)


Event volume: Low

If this policy setting is configured, the following events are generated. The events appear on computers running Windows Server 2008 R2 or Windows Server 2008.

  • 4744: A security-disabled local group was created.
  • 4745: A security-disabled local group was changed.
  • 4746: A member was added to a security-disabled local group.
  • 4747: A member was removed from a security-disabled local group.
  • 4748: A security-disabled local group was deleted.
  • 4749: A security-disabled global group was created.
  • 4750: A security-disabled global group was changed.
  • 4751: A member was added to a security-disabled global group.
  • 4752: A member was removed from a security-disabled global group.
  • 4753: A security-disabled global group was deleted.
  • 4759: A security-disabled universal group was created.
  • 4760: A security-disabled universal group was changed.
  • 4761: A member was added to a security-disabled universal group.
  • 4762: A member was removed from a security-disabled universal group.

Scope: 

Computer

Default: 

Not configured

Related content