Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

To log command lines when Windows creates a process, enable two device policies: Audit Process Creation with Success auditing, and Include command line in process creation events. The first generates Security event 4688; the second adds the command line to that event. The command line is recorded in plain text, so plan access, collection, and retention before deploying broadly.

How the two policies work together

Windows Security event 4688, “A new process has been created,” is generated when a new process starts. Its Process Command Line field is empty by default. Audit Process Creation enables the event; Include command line in process creation events adds the command-line detail. Enabling only one does not provide the complete result.

Policy Purpose Configuration identifier Value or format
Audit Process Creation Generates process-creation audit events. ./Device/Vendor/MSFT/Policy/Config/Audit/DetailedTracking_AuditProcessCreation Set to 1 for Success auditing. The CSP also defines 0 (Off/None), 2 (Failure), and 3 (Success+Failure). Microsoft documents the CSP values and support details.
Include command line in process creation events Adds command-line text to process-creation events. ./Device/Vendor/MSFT/Policy/Config/ADMX_AuditSettings/IncludeCmdLine Enable the ADMX-backed, device-scoped setting using the CSP’s string/character SyncML format. It requires Audit Process Creation to be enabled. See Microsoft’s ADMX_AuditSettings CSP documentation.

Microsoft’s Windows audit guidance recommends Success auditing for process starts; the subcategory has no Failure events in that guidance. Read the Audit Process Creation guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Configure the policies through Intune

Intune’s Settings Catalog is a general way to configure settings exposed through Windows CSPs and create assignable device configuration profiles. The available documentation does not establish whether both named settings appear in every tenant’s current catalog, nor does it confirm a current exact portal sequence for combining them. Treat catalog availability and portal labels as tenant-dependent rather than assuming a fixed click path.

#1 Best Overall
  1. Check device eligibility. Confirm that the Windows edition and build support both CSP settings. Their applicability differs; review the support details in the linked Audit CSP and ADMX_AuditSettings CSP entries.
  2. Create a device configuration profile. In Intune, use a supported profile mechanism for the device-scoped settings. Microsoft describes the general Settings Catalog profile and assignment process in its Settings Catalog documentation; it does not confirm the current availability of these specific controls in every tenant.
  3. Set Audit Process Creation to Success. Use the CSP identifier ./Device/Vendor/MSFT/Policy/Config/Audit/DetailedTracking_AuditProcessCreation and value 1.
  4. Enable IncludeCmdLine. Configure ./Device/Vendor/MSFT/Policy/Config/ADMX_AuditSettings/IncludeCmdLine. If using a custom CSP payload, follow its required string/character SyncML format. The exact Intune payload serialization and portal steps are not established here, so do not copy an unverified XML example.
  5. Assign to a test device group. Validate the effective policy and inspect newly created Security event 4688 records on a test device before expanding deployment.
  6. Expand only after operational checks. Confirm command-line visibility, log access controls, event collection, and retention for your workload.

Verify command-line logging on a test device

After the profile applies, inspect newly generated Security log events with ID 4688. Check that the Process Command Line field is populated for a process created after the setting took effect. Existing events are not retroactively filled in. Microsoft describes the event and field behavior in its Event 4688 documentation.

If the field remains empty, check that both policies are enabled and that the profile reached the device. Also check whether another management source or audit configuration is changing the effective policy. Microsoft warns that Advanced Audit Policy Configuration can be overridden by basic audit policy settings; verify effective settings across the device’s management sources rather than assuming an Intune assignment alone resolved a conflict. The same Microsoft guidance discusses the audit-policy interaction and the force-subcategory setting in Group Policy.

Rank #2
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
  • 256 GB SSD of storage.
  • Multitasking is easy with 16GB of RAM
  • Equipped with a blazing fast Core i5 2.00 GHz processor.

Check Windows edition and build support

The two settings have separate applicability requirements, so a device must meet both. The Audit Process Creation CSP lists Windows 10 Pro, Enterprise, Education, and IoT Enterprise, with support beginning at Windows 10 version 1803 subject to specified servicing updates; it also lists Windows 10 version 2004 and later. The IncludeCmdLine CSP lists Windows 10 version 2004, 20H2, and 21H1 with KB5005101 and later, and Windows 11 version 21H2 and later. Both CSP entries list Pro, Enterprise, Education, and IoT Enterprise editions. Check the live Microsoft entries for current build applicability before deployment, since these support details may change.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Protect the command-line data

Command lines are stored as plain text in Security events. Microsoft cautions that anyone who can read the security events can read the arguments for successfully created processes; arguments may contain passwords or user data. Treat the logs and any forwarded copies as sensitive data.

Rank #3
HP OmniBook 3 17.3 inch Laptop PC, FHD Display, AMD Ryzen 3 30, 8 GB RAM, 512 GB SSD, AMD Radeon 610M Graphics, Windows 11 Home, Mica Silver, 17-dp0199nr
  • FULL HD IPS DISPLAY - Enjoy vibrant, crystal-clear images with 178-degree wide-viewing angles
  • AMD RYZEN 3 30 PROCESSOR - Everyday performance you can count on; Multitask, stream, game casually, and edit photos smoothly with responsive power and vibrant HDR visuals
  • ENJOY UP TO 14 HOURS AND 15 MINUTES OF BATTERY LIFE - HP Fast Charge restores battery from 0 to 50% in approximately 45 minutes
  • AMD RADEON 610M GRAPHICS - Experience smooth entertainment; Built for streaming and multitasking, enjoy realistic visuals and efficient performance for work and play
  • STORAGE AND MEMORY - 512 GB PCIe NVMe M.2 SSD offers fast speed and efficient storage; and 8 GB LPDDR5 RAM memory boosts performance with higher bandwidth
  • Limit who can read Security logs and downstream event-collection destinations.
  • Review whether applications or scripts put credentials, personal information, or other secrets in command-line arguments.
  • Set collection and retention according to your security needs and applicable data-handling requirements. Microsoft does not prescribe a universal retention period for this setting.

Process-creation event volume depends on activity and Microsoft characterizes it as medium to high depending on how the machine is used. There is no universal event count; measure the workload on representative devices and account for log capacity and collection volume before broad rollout. See Microsoft’s Audit Process Creation guidance.

Quick Recap

Bestseller No. 1
HP 14' HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
HP 14" HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
$245.99
Bestseller No. 2
Dell Latitude 5420 14' FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
256 GB SSD of storage.; Multitasking is easy with 16GB of RAM; Equipped with a blazing fast Core i5 2.00 GHz processor.
$285.00
Bestseller No. 4
HP 14' HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Blue (Renewed)
HP 14" HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Blue (Renewed)
14” Diagonal HD BrightView WLED-Backlit (1366 x 768), Intel Graphics,; Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD
$247.99
Rank #4
HP 14" HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Blue (Renewed)
  • 14” Diagonal HD BrightView WLED-Backlit (1366 x 768), Intel Graphics,
  • Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD
  • 3x USB Type A,1x SD Card Reader, 1x Headphone/Microphone
  • 802.11a/b/g/n/ac (2x2) Wi-Fi and Bluetooth, HP Webcam with Integrated Digital Microphone
  • Windows 11 OS, Dale Blue

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.