To audit NTFS permission changes, enable Audit File System on the file server and add a targeted auditing entry (SACL) to the files or folders you need to monitor. The key event is 4670, “Permissions on an object were changed.” For that event to be generated for a file-system object, its SACL must audit Change Permissions and/or Take Ownership for the relevant accounts. Enabling the policy alone is not enough.
Understand what is being audited
A file or folder has two different access-control lists that matter here:
- DACL (discretionary access control list): determines which users and groups are granted or denied access.
- SACL (system access control list): specifies which access operations Windows should audit, and for which users or groups.
Audit policy enables a category of logging on the server; the object’s SACL selects the activity and principals that produce file-system audit events. Both must be configured to match the change you want to detect. Microsoft cautions against enabling file-system auditing before planning how collected events will be analyzed: Audit File System.
Configure auditing for NTFS permission changes
- Choose the scope and outcomes. Identify the folders or files, accounts or groups, and operations that matter. Decide whether you need successful changes, failed attempts, or both. Prefer specific paths and principals over auditing everything.
- Enable Audit File System on the server. In Group Policy, go to Computer Configuration > Policies > Windows Settings > Security Settings > Advanced Audit Policy Configuration > System Audit Policies > Object Access > Audit File System. Enable Success, Failure, or both according to your monitoring objective. The policy’s location and behavior are documented in Microsoft’s Audit Policy CSP.
- Add an auditing entry to the target object. On the file or folder, open Properties > Security > Advanced > Auditing, add the required user or group, and select the access types and success/failure outcomes to audit. If descendants are in scope, account for inheritance so that the intended child objects receive the audit entry. See Microsoft’s basic file or folder audit-policy procedure.
- Include the rights relevant to Event 4670. For a file-system object’s permission-change event, Microsoft specifies that the object’s SACL must include Change Permissions and/or Take Ownership. Ensure the audit entry covers the principals and objects you actually intend to monitor. See Event 4670.
- Apply policy and verify in a controlled context. Refresh Group Policy as appropriate, then perform an authorized test change on a test object or during a maintenance window. On the resource server, inspect Event Viewer > Windows Logs > Security for the expected event and object path. Microsoft’s central-audit demonstration shows policy application and Security-log verification: Deploy Security Auditing with Central Audit Policies.
- Tune collection. Confirm log sizing, retention, forwarding, review filters, and SACL inheritance. Remove entries that are excessive or do not serve the monitoring objective, then verify that the resulting event stream is useful.
Which events matter?
| Event | What it tells you | Important qualification |
|---|---|---|
| 4670 | “Permissions on an object were changed.” This is the primary signal for a permission change. | For a file-system object, the SACL needs Change Permissions and/or Take Ownership. The event can also concern registry or security-token objects, so check the object type and path. It is not generated when the object’s SACL itself changes. Microsoft event reference. |
| 4663 | “An attempt was made to access an object.” It indicates that an access right was used. | It is not a permission-change record. It requires a matching SACL audit entry. Microsoft event reference. |
| 4656 | A handle to an object was requested. | A handle request alone does not prove that the requested access was successfully used. Microsoft lists it among events associated with Audit File System. Audit File System. |
| 5145 | A detailed network-share access check was performed. | This is share auditing, not a substitute for NTFS permission-change auditing. A failure event indicates denial at the share level; Microsoft says one is not generated for an NTFS-level denial. Microsoft event reference. |
| 5140 | A network share was accessed. | This is broader share-access telemetry, distinct from per-object file-system auditing. Advanced Audit Policy Configuration settings. |
When reviewing an event, check the subject or account, object path, time, and the access or permission details recorded in its fields. A handle identifier or related access event can provide correlation context when available, but do not assume that every change will have a complete matching event pair.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
- Spacious Design: Measuring 21.1" wide and 14.1" deep, our lap desk comfortably fits most laptops up to 15.6". Extra room for accessories ensures convenience.
- Enhanced Functionality: Packed with handy features, including a 5x9" precision tracking mouse pad and a built-in phone slot for seamless work or video calls. Plus, enjoy ergonomic support with the integrated cushioned wrist rest.
- Cool Comfort: Enjoy a stable surface with our lap desk's dual bolster cushion, designed for comfort and airflow, keeping your lap cool during extended use.
- Durable Surface: Work with confidence on our lap desk's solid surface, featuring a sleek black carbon color, ensuring optimal air circulation to prevent your laptop from overheating.
- On-the-Go Convenience: With an integrated handle and lightweight design (2.8 lbs), our lap desk is portable for travel or moving around the house, offering flexibility in any space.
Why Event 4670 may be missing
- The policy is not enabled on the resource server. Confirm Audit File System is enabled for the server that hosts the object, with the success or failure setting relevant to your objective.
- The object’s SACL does not match. Check that an audit entry covers the account, object, outcome, and relevant access types. For 4670, include Change Permissions and/or Take Ownership as applicable.
- The audit entry did not reach the object. Review the Auditing tab and inheritance on the target folder and descendants.
- You are checking the wrong signal or system. File-system events are in the Security log on the resource server. Share events such as 5145 answer a different question.
- The change was to the SACL itself. Event 4670 does not generate when the auditing ACL changes, so its absence does not establish that no SACL change occurred.
- Collection or retention obscures the event. Check Security-log capacity, forwarding, retention, and filters as part of verification.
NTFS auditing and SMB share auditing answer different questions
Use Audit File System with scoped object SACLs when you need to monitor particular NTFS files or folders. Use Audit File Share or Audit Detailed File Share for network-share access activity. Share auditing has no share SACL selector: Microsoft says these policies audit access to all shares on the system, and detailed share auditing can generate high event volume. File-system event volume also depends on SACL configuration. See Microsoft’s Advanced Audit Policy Configuration guidance and Audit File System guidance.
SMB access is evaluated against both share permissions and NTFS permissions; a denial at one layer is not equivalent to a denial at the other. In particular, the absence of a 5145 failure does not prove that NTFS allowed an operation: that failure event is generated only for a share-level denial. Also, enabling Audit File Share does not generate events for share creation, deletion, or changes to share permissions. Choose the audit layer according to whether you need evidence about NTFS permission changes, file-system access, or share-level access checks.
Rank #2
- 5-in-1 Connectivity: Equipped with a 4K HDMI port, a 5 Gbps USB-C data port, two 5 Gbps USB-A ports, and a USB C 100W PD-IN port. Note: The USB C 100W PD-IN port supports only charging and does not support data transfer devices such as headphones or speakers.
- Powerful Pass-Through Charging: Supports up to 85W pass-through charging so you can power up your laptop while you use the hub. Note: Pass-through charging requires a charger (not included). Note: To achieve full power for iPad, we recommend using a 45W wall charger.
- Transfer Files in Seconds: Move files to and from your laptop at speeds of up to 5 Gbps via the USB-C and USB-A data ports. Note: The USB C 5Gbps Data port does not support video output.
- HD Display: Connect to the HDMI port to stream or mirror content to an external monitor in resolutions of up to 4K@30Hz. Note: The USB-C ports do not support video output.
- What You Get: Anker 332 USB-C Hub (5-in-1), welcome guide, our worry-free 18-month warranty, and friendly customer service.
Control event volume before expanding scope
Broad SACLs and detailed share auditing can produce large volumes of events. Microsoft warns that excessive or ineffective SACL entries can overload the log; detailed share auditing may also be high volume, including on file servers or domain controllers with SYSVOL activity. Start with paths, principals, and outcomes tied to a defined monitoring purpose, then validate the volume and usefulness before broadening collection.
Quick Recap
Best Value
- Spacious Design: Measuring 21.1" wide and 12" deep, our lap desk comfortably fits most laptops up to 15.6". Extra room for accessories ensures convenience.
- Enhanced Functionality: Packed with handy features, including a 5x9" precision tracking mouse pad and a built-in phone slot for seamless work or video calls. Plus, enjoy laptop support with the integrated device ledge.
- Cool Comfort: Enjoy a stable surface with our lap desk's dual bolster cushion, designed for comfort and airflow, keeping your lap cool during extended use.
- Durable Surface: Work with confidence on our lap desk's solid surface, featuring a blush pink color, ensuring optimal air circulation to prevent your laptop from overheating.
- On-the-Go Convenience: With an integrated handle and lightweight design (2.14 lbs), our lap desk is portable for travel or moving around the house, offering flexibility in any space.
Rank #4
- Anti-Slip Surface - Transform your laptop into a mobile workstation with the AboveTEK portable laptop lap desk. The anti-slip surface provides a strong grip for laptops up to 15.6 inches(Diagonal), while the double rubber strip on the bottom ensures a stable display or typing experience on your lap, couch, or bed.
- Retractable Mouse Pad - Retractable laptop mouse pad extends on both directions for the left/right handed with elevation along the edges for stopping mouse from falling off. The size of laptop tray is 14" X 9.7" and the size of mouse pad is 7.4" X 6.1".
- Effective Heat Shield - The effective heat shield made of sturdy and thick material protects your laptop from overheating. Prioritizes your comfort and safety, an ideal lap pad or board for working anywhere.
- EASY to Carry and Store - With an ergonomic and simplistic design, the lap desk is portable to store in a backpack. Only 15" in size, 2.2 lb of weight and with slim 0.6 inch thickness, it is ready to be easily carried around.
- Widely Applicable - The smooth platform accommodates laptops and tablets up to 15.6 inches(Diagonal), making it a versatile accessory and one of the best gifts for mom, dad, students and professionals. Perfect for use as a laptop bed tray or tablet holder anywhere at home, library, or park.
Rank #3
- Note: Not suitable for MacBooks released after 2023 or devices with a protruding front camera; Not applicable to full-screen or notch-style tempered glass screen protectors; Do not use on the rear camera of the phone.
- 💻 Why Do You Need a Webcam Cover Slide? — Safeguard your privacy by covering your webcam with our reliable webcam cover when not in use. Don't let anyone secretly watch you. Stay protected!
- ✅ Thin & Stylish — Enhance your laptop's functionality and aesthetics with our 0.027" ultra-thin webcam covers. Seamlessly close your laptop while adding a touch of sophistication.
- ✅ Fits Most Devices — Compatible with laptops, phones, tablets, desktops! Keep your privacy intact on Ap/ple, Mac/Book, iPh/one, iP/ad, H/P, L/novo, De/ll, Ac/er, As/us, Sa/msung devices.
- ✅ 365 Days Protection — Our upgraded 3.0 adhesive ensures a strong hold that won't damage your equipment. Experience reliable, long-term privacy protection day in and day out.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

