Intune Insights: Enable process auditing for App Metering

App Metering relies on the process start and stop events that Windows records in the Security event log. Windows records these events only when Process Creation and Process Termination auditing are enabled on the device. This article describes how to enable both on your target devices by using either an Intune settings catalog policy or Group Policy, and how to verify that the events are being recorded.

Enable auditing on your target devices before you enable App Metering. For an overview of the feature and how to enable it, see Intune Insights: Enable and configure App Metering.

The following audit subcategories generate the events that App Metering needs:

Subcategory

Event ID

What it records

Audit Process Creation

4688 - A new process has been created

The process name, parent process, user, token elevation type, and command line (if command-line capture is enabled).

Audit Process Termination

4689 - A process has exited

When a process ended, and its exit status.

Important

Use only one of the methods in this article, based on your environment. Adapt the steps to suit your internal processes, and make sure your policy administration team agrees with the approach before you implement it.

Enable auditing with an Intune settings catalog policy

The settings catalog is the recommended method. It replaces custom OMA-URI settings for these configurations. You create a single configuration profile that enables both audit subcategories, turns on command-line capture, and protects the settings from legacy audit policy.

To create the profile:
  1. Sign in to the Microsoft Intune admin center.

  2. Navigate to Devices > Configuration, select Create, and then select New policy.

  3. For Platform, select Windows 10 and later. For Profile type, select Settings catalog, and then select Create.

  4. Enter a traceable name for the profile, for example WIN - Security - Process Auditing (4688/4689), and then select Next.

To add the audit subcategories:
  1. Select Add settings.

  2. Search for Detailed Tracking, and then expand the Audit category.

  3. Select Detailed Tracking Audit Process Creation and Detailed Tracking Audit Process Termination.

  4. Set both settings to Success. Don't select Success+Failure, because there are no failure events to collect.

To add command-line capture:
  1. Select Add settings.

  2. Search for Include command line in process creation events.

  3. Expand Administrative Templates > System > Audit Process Creation, select the setting, and then set it to Enabled.

To protect the settings from legacy audit policy:
  1. Select Add settings.

  2. Search for Force audit policy subcategory settings.

  3. Expand Local Policies Security Options, select Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings, and then set it to Enabled.

    This setting stops legacy audit policy category settings from overriding the subcategory settings you configured.

To assign and deploy the profile:
  1. Select Next to move through Scope tags.

  2. On the Assignments page, assign the profile to your pilot device group first. Assign the profile to devices, not users.

  3. Select Next, and then on the Review + create page, select Create.

  4. Allow for the normal Intune sync. To speed up the sync on a test device, on the device navigate to Settings > Accounts > Access work or school, select the connected account, select Info, and then select Sync.

  5. In the Intune admin center, navigate to Devices > Configuration, select your profile, and check that Device status shows Succeeded.

Enable auditing with Group Policy

Use this method for devices managed by Group Policy. You create and link a GPO that enables both audit subcategories, turns on command-line capture, protects the settings from legacy audit policy, and sets a Security log size large enough to hold the events.

To create and link the GPO:
  1. On a domain controller or management workstation, open Group Policy Management.

  2. Right-click the target OU, and then select Create a GPO in this domain, and Link it here.

  3. Enter a name for the GPO, for example WIN - Security - Process Auditing.

  4. Right-click the new GPO, and then select Edit.

To enable the audit subcategories:
  1. Navigate to Computer Configuration > Policies > Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Detailed Tracking.

  2. Open Audit Process Creation. Select the Configure the following audit events check box, select the Success check box, and leave Failure cleared. Then select OK.

  3. Open Audit Process Termination. Select the Configure the following audit events check box, select the Success check box, and leave Failure cleared. Then select OK.

To enable command-line capture:
  1. Navigate to Computer Configuration > Policies > Administrative Templates > System > Audit Process Creation.

  2. Open Include command line in process creation events, select Enabled, and then select OK.

To protect the settings from legacy audit policy:
  1. Navigate to Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options.

  2. Open Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings. Select the Define this policy setting check box, select Enabled, and then select OK.

To size the Security log:
  1. Navigate to Computer Configuration > Policies > Administrative Templates > Windows Components > Event Log Service > Security.

  2. Open Specify the maximum log file size (KB), select Enabled, set the maximum log file size to 196608 or higher, and then select OK.

To apply the policy:
  1. Close the Group Policy Management Editor.

  2. On a test machine, run the following command:

    gpupdate /force
  3. For machines that you don't force-update, allow up to two refresh cycles (about 90 to 120 minutes) for the policy to apply.

Verify that auditing is working

Run the following commands on a target device, in an elevated command prompt.

  1. Confirm the effective audit policy. Process Creation and Process Termination should both show Success.

    auditpol /get /category:"Detailed Tracking"
  2. Confirm that command-line capture is on. The value should be 0x1.

    reg query "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Audit" /v ProcessCreationIncludeCmdLine_Enabled
  3. Open Notepad, and then read the newest 4688 event. It should show a New Process Name and a populated Process Command Line field.

    wevtutil qe Security /q:"*[System[(EventID=4688)]]" /c:1 /rd:true /f:text
  4. Close Notepad, and then confirm that 4689 events are being recorded.

    wevtutil qe Security /q:"*[System[(EventID=4689)]]" /c:1 /rd:true /f:text

Troubleshooting

  • No 4688 events at all. Legacy audit policy might be overwriting your settings. Look for Event ID 4719 (System audit policy was changed) in the Security log, and confirm that the Audit: Force audit policy subcategory settings option is enabled.

  • 4688 events appear, but the Process Command Line field is blank. The Administrative Templates setting hasn't applied. Verify the registry value described in Verify that auditing is working. Command-line capture affects only events generated after the setting applies; it isn't retroactive.

  • Events stop after a few hours. The Security log is wrapping. Increase the maximum log size, or forward events to a collector or SIEM.

  • The Intune profile shows Error 65000 or a conflict. Another profile, a security baseline, or an on-premises GPO is setting the same audit subcategory. On hybrid-joined devices, Group Policy and Intune both writing audit policy is a common conflict. Choose one authority for each setting.

  • The settings apply, but nothing changes on a Cloud PC or session host. Confirm that the policy is assigned to a device group that contains the Cloud PC or session host objects, not to the users.

Need help?

Raise a support ticket for this item.

Was this article helpful?

0 out of 0 found this helpful
Have more questions? Submit a request

Comments (0 comments)

Article is closed for comments.