GPO tool

Group Policy made searchable

A free ADMX browser or comparison tool for IT administrators.Search policies, find registry keys, and see exactly what each setting writes to the Windows Registry. Or compare two GPO backups to see exactly what has changed between them.

Select a product
  • Select a category.

Enable Protected Event Logging

This policy setting lets you configure Protected Event Logging.

If you enable this policy setting, components that support it will use the certificate you supply to encrypt potentially sensitive event log data before writing it to the event log. Data will be encrypted using the Cryptographic Message Syntax (CMS) standard and the public key you provide. You can use the Unprotect-CmsMessage PowerShell cmdlet to decrypt these encrypted messages, provided that you have access to the private key corresponding to the public key that they were encrypted with.

If you disable or do not configure this policy setting, components will not encrypt event log messages before writing them to the event log.

Registry Information

VendorMicrosoft
ProductEvent Logging
CategoryEvent Logging
Applies toComputer Configuration
Supported onWindows 10 0
Registry Key[HKLM]SoftwarePoliciesMicrosoftWindowsEventLogProtectedEventLogging
Value NameEnableProtectedEventLogging
TypeREG_DWORD
Enabled value1
Disabled value0

Policy Settings

EncryptionCertificate

Registry Key[HKLM]SoftwarePoliciesMicrosoftWindowsEventLogProtectedEventLogging
Value NameEncryptionCertificate
TypeREG_MULTI_SZ