When an update to the Security tab of a protected Certificate Template is made in Certificate Templates Console but fails due to protection, a "pKICertificateTemplate nTSecurityDescriptor changed" event with "Protected" result may not be recorded in Change Auditor. This is the expected result when applied to the ntSecurityDescriptor attribute of the pKICertificateTemplate class. The "Protected" event is correctly captured for this attribute.
This is due to the ntSecurityDescriptor attribute and its interaction with other attributes.
Understanding this interaction is crucial for correctly configuring protection templates in the pKICertificateTemplate class. If protection is added to any of the following attributes within the same or another protection template, the "Protected" event for the ntSecurityDescriptor attribute will not be received. Instead, a "Protected" event will be triggered for the msPKI-Template-Minor-Revision attribute: