By configuring Windows for monitoring user activities, we can increase the security of the administration and can also punish the victim users by observing their records in case of an offense. In this article, we’ll tell you the way to track user activities in Windows 11/10/8.1/8/7 using Audit Policy. Here is how:
Track User Activity using Audit Policy in WorkGroup Mode
Press Windows Key + R combination, type put secpol.msc in Run dialog box and hit Enter to open the Local Security Policy.
In the Local Security Policy window, expand Security Settings > Local Policies > Audit Policy. Now you should get your window resembled with this one:
In the right pane, you can see 9 Audit…[] policies have No auditing as pre-defined security setting. Click one by one all the policies and make the selection to Success and Failure, click Apply followed by OK for each policy.
In this way, we will have configured Windows to track down user activity. Follow these steps to get the traced records:
Trace User Activity Using Event Viewer
Press Windows Key + R combination, type put eventvwr in Run dialog box and hit Enter to open the Event Viewer.
Now, in the Event Viewer window, from the left pane, select Windows Logs > Security. Here Windows keeps a record of every event concerning security.
From the center pane, click any event to get its info:
Now, here is the list of the event IDs which covers the user activities for the accounts in the workgroup mode:
- Create User: Below are the Event IDs that get logged when the user is created.
Event ID: 4728 | Type: Audit Success | Category: Security Group Management | Description: A member was added to a Security-enabled global group.
Event ID: 4720 | Type: Audit Success | Category: User Account Management | Description: A User account was created.
Event ID: 4722 | Type: Audit Success | Category: User Account Management | Description: A User account was enabled.
Event ID: 4738 | Type: Success Audit | Category: User Account Management | Description: A User account was changed.
Event ID: 4732 | Type: Success Audit | Category: Security Group Management | Description: A member was added to a Security-enabled local group.
- Delete User: Below are the Event IDs that get logged when the user is deleted.
Event ID: 4733 | Type: Success Audit | Category: Security Group Management | Description: A member was removed from a Security-enabled local group.
Event ID: 4729 | Type: Success Audit | Category: Security Group Management | Description: A member was added to a Security-enabled global group.
Event ID: 4726 | Type: Success Audit | Category: User Account Management | Description: A User account was deleted.
- User Account Disabled: Below are the Event IDs that get logged when the user is disabled.
Event ID: 4725 | Type: Success Audit | Category: User Account Management | Description: A User account was disabled.
Event ID: 4738 | Type: Success Audit | Category: User Account Management | Description: A User account was changed.
- User Account Enabled: Below are the Event IDs that get logged when the user is enabled.
Event ID: 4722 | Type: Success Audit | Category: User Account Management | Description: A User account was enabled.
Event ID: 4738 | Type: Success Audit | Category: User Account Management | Description: A User account was changed.
- User Account Password Reset: Below are the Event IDs that get logged when the User Account Password gets reset.
Event ID: 4738 | Type: Success Audit | Category: User Account Management | Description: A User account was changed.
Event ID: 4724 | Type: Success Audit | Category: User Account Management | Description: An attempt was made to reset an account’s password.
- User Account Profile Path Set: Below is the Event ID that gets logged when Profile Path gets set for a user account.
Event ID: 4738 | Type: Success Audit | Category: User Account Management | Description: A User account was changed.
- User Account Rename: Below are the Event IDs that get logged when the User Account is renamed.
Event ID: 4781 | Type: Success Audit | Category: User Account Management | Description: The name of an account was changed.
Event ID: 4738 | Type: Success Audit | Category: User Account Management | Description: A User Account was changed.
- Create Local Group: Below are the Event IDs that get logged when the Local Group is created.
Event ID: 4731 | Type: Success Audit | Category: Security Group Management | Description: A Security-enabled local group was created
Event ID: 4735 | Type: Success Audit | Category: Security Group Management | Description: A Security-enabled local group was changed
- Add User to Local Group: Below is the Event ID that gets logged when the user gets added to the Local group.
Event ID: 4732 | Type: Success Audit | Category: Security Group Management | Description: A member was added to a Security-enabled local group
- Remove User from Local Group: Below is the Event ID that gets logged when the user is removed from the Local group.
Event ID: 4733 | Type: Success Audit | Category: Security Group Management | Description: A member was removed from a Security-enabled local group
- Delete Local Group: Below is the Event ID that gets logged when the Local Group is deleted.
Event ID: 4734 | Type: Success Audit | Category: Security Group Management | Description: A Security-enabled local group was deleted
- Rename Local Group: Below are the Event IDs that get logged when the Local Group is renamed.
Event ID: 4781 | Type: Success Audit | Category: User Account Management | Description: A name of an account was changed
Event ID: 4735 | Type: Success Audit | Category: Security Group Management | Description: A Security-enabled local group was changed
In this way, you can trace users with their activities. This article is applicable for Windows 11/10/8.1 in Workgroup Mode. For Active Directory Domain, the procedure will be different.