Previous Topic: Audit Only Mode

Next Topic: Warning Mode


Set Up Audit Only Mode

Audit Only mode records all intercepted events without checking or enforcing access rules. Use this mode to collect data for compliance requirements or regulations.

To set up Audit Only mode, set the SeOSD\GeneralInterceptionMode CA Access Control registry entry to 1.

Important! If you use Audit Only mode, make sure that you have enough disk space for the audit logs and that the size limit of the audit log is large enough. You should also consider options for audit log backup.