Limit remote access to the Event Log Service
Jump to overview

Policy overview

Key metadata and intent for this policy.

Computer
Category
Windows Components > Event Log Service
Supported on
Windows 11 22H1

Supported OS tags: Windows11

This policy setting controls which remote users will be allowed to connect to the Event Log service on this machine. If you enable this policy, you can restrict which group remote users must be a member of in order to connect to the Event Log Service on this machine. You can require that remote users be a member of one of the following builtin groups: • Authenticated Users • EventLog Readers • Administrators If you disable or do not configure this policy, the default value will be Authenticated Users. For prior versions of Windows, only Authenticated Users was supported. To maintain backwards compatability, local connections to the service will always be allowed from Authenticated Users. This setting does not control access to individual logs. Once a remote connection is allowed, it will still need access to the specific resources it is attempting to use.

Internal name
RpcAccess_Remote
Policy ID
c58e9b742076
Elements
1

Registry values

How enabled and disabled states update the registry.

ScopeRegistry locationTypeEnabled valueDisabled valueCopy
Computer
Path
Software\Policies\Microsoft\Windows\EventLog
Value name
EnableRemoteRpcAccessRestrictions
REG_DWORD
HKLM
1
HKLM
0
Registry location
Type REG_DWORD · Computer
Path
Software\Policies\Microsoft\Windows\EventLog
Value name
EnableRemoteRpcAccessRestrictions
Hive
HKLM
Enabled value
1
Disabled value
0

Policy elements

Inputs and configuration options exposed by this policy.

ScopeElementTypeRegistry mappingConstraints & behaviorCopy
Computer
Pick one of the following settings:
ID RpcAccess_Remote_Setting
enum
Path
Software\Policies\Microsoft\Windows\EventLog
Value name
RpcAccess_Remote_Setting
Type
REG_DWORD
Options: Authenticated Users (0), Event Log Readers (1), Administrators (2)
Pick one of the following settings:
Computer · Type enum
Registry mapping
Path
Software\Policies\Microsoft\Windows\EventLog
Value name
RpcAccess_Remote_Setting
Type
REG_DWORD
Details
Options: Authenticated Users (0), Event Log Readers (1), Administrators (2)