System events for software restriction policies

Applies To: Windows Server 2003, Windows Server 2003 R2, Windows Server 2003 with SP1, Windows Server 2003 with SP2

System events for software restriction policies

When users try to run software that has been disallowed by software restriction policies or by software restriction policies rules, events are generated and stored in the application log, as indicated in the following table. You can view these events with the Event Viewer. For more information about Event Viewer, see Event Viewer.

Event ID What it means

865

A user attempted to run software that is disallowed by the default security level.

866

A user attempted to run software that is disallowed by a path rule.

867

A user attempted to run software that is disallowed by a certificate rule.

868

A user attempted to run software that is disallowed by an Internet zone rule or a hash rule.

For more information about the event log, see Settings for Event Logs. For more information about software restriction policies, see Software Restriction Policies.