Submitting forms on the support site are temporary unavailable for schedule maintenance. If you need immediate assistance please contact technical support. We apologize for the inconvenience.
Multiple Event ID 4703 being logged in Security Event Log
설명
The Windows Security event log is filling with Event ID 4703 on servers running the Change Auditor agent. The Change Auditor agent, NPSrvHost.exe, is the Process name.
원인
Microsoft captures Successes and Failures of EventID 4073 "A user right token has been adjusted" and is turned on by default in the Local Auditing Policy.
해결 방안
Either ignore the event or disable the Success Auditing of that event in the Local Auditing Policy: