Security Compliance

Windows 10 hosts continuously send Event ID 4703 to SEM

The SEM console is being flooded by Event ID 4703 events being sent from Windows 10 agents.

First published date

10/17/2018 10:28 PM

Last published date

10/17/2018 10:28 PM

Overview

The Security Event Manager (formerly Log & Event Manager) console is being flooded by Event ID 4703 events being sent from Windows 10 agents.

Product section

Security Event Manager

Cause

This is a new, relentless event type being sent from Windows 10-based hosts.

Resolution

You can prevent the events from being generated on the hosts themselves by disabling a specific subcategory in its audit policy.

Change the Authorization Policy Change subcategory to No Auditing either through the local policy or a group policy. See Audit Policies and Best Practices for SEM for more information on adjusting audit policies.
Learn more about event 4703 here (© 2020 Microsoft, available athttps://www.microsoft.com/en-us/, obtained on 29 January, 2020).