Skip to content

Security

Franck SALLET edited this page Sep 5, 2026 · 1 revision

Security

Local/domain audit policy inspection.

1 function(s) in Public/security/.

Functions

  • Get-AuditPolicy — Report advanced audit policy subcategory settings from auditpol.exe

Reference

Get-AuditPolicy

Report advanced audit policy subcategory settings from auditpol.exe.

Parses the advanced audit policy returned by 'auditpol.exe /get /category:* /r' (CSV) into one object per subcategory, reporting Success and Failure auditing state. It is a base building block for CIS/ANSSI compliance auditing and supports local and remote targets via Invoke-RemoteOrLocal, with optional filtering to a single category. Each Subcategory GUID is mapped to its parent Category using a static, well-known GUID map since 'auditpol /r' does not expose Category as a column.

Syntax

Get-AuditPolicy [-ComputerName <string[]>] [-Credential <System.Management.Automation.PSCredential>] [-Category <string>]

Examples

Get-AuditPolicy

Returns advanced audit policy subcategory settings for the local machine.

Get-AuditPolicy -Category 'Logon/Logoff'

Returns only the subcategories belonging to the 'Logon/Logoff' category on the local machine.

Get-AuditPolicy -ComputerName SRV01 -Credential (Get-Credential)

Returns advanced audit policy subcategory settings from SRV01 via WinRM, using the supplied credential.

'SRV01','SRV02' | Get-AuditPolicy

Returns advanced audit policy subcategory settings for SRV01 and SRV02 via pipeline.

Output: PSWinOps.AuditPolicy

One object per audit subcategory, with Category, Subcategory, SubcategoryGuid, AuditSuccess, AuditFailure and the derived Setting string.


PSWinOps Wiki

Home

Domains

Clone this wiki locally