This table lists all Policy Management events and their unique subtypes specific to this release of App Control.

Note: New or changed events are identified with ** (double-asterisk) in the left column. This allows a search to quickly identify only the new or changed events.
Table 1. Policy Management Events and Subtypes
Subtype ID No. Severity Example Descriptions/Comments
AD rules loaded 605 Info Active Directory rules script with version $param1$ was loaded successfully.
Approval Request closed 646 Info

Approval Request Id $requestID$ was closed by user '$username$' as ‘$resolvedState$’ with ‘$comment$’.

Approval Request created 644 Info

Approval Request Id $requestID$ was created by user '$username$'.

Approval Request duplicate created 661 Info

Duplicate of Approval Request Id $requestID$ was created by user '$username$'.

Approval Request escalated 663 Info

Approval Request Id $requestID$ was escalated by user '$username$'.

Approval Request modified 662 Info

Approval Request Id $requestID$ was modified by user '$username$'.

Approval Request opened 645 Info

Approval Request Id $requestID$ was opened by user '$username$'.

Certificate approval created 651 Info Certificate $SubjectName$ was approved by ‘$username$’ for publisher $publisher$.
Certificate approval deleted 653 Info Approval of certificate $SubjectName$ was deleted by '$username$' for publisher $publisher$.
Certificate approval modified 652 Info Approval of certificate '$param1$' was modified by '$username$' for publisher '$param3$'.
Certificate ban created 654 Info Certificate $SubjectName$ was banned by $username$ for publisher $publisher$.
Certificate ban deleted 656 Info Ban of certificate $SubjectName$ was deleted by '$username$' for publisher $publisher$.
Certificate ban modified 655 Info Ban of certificate '$subjectName$' was modified by '$username$' for publisher '$param3$'.
Custom Rule created 638 Info

Custom Rule '$ruleName$' was created by '$username$'.

Custom Rule '$ruleName$ (Unified)' was created by '$username$'.

‘$ruleName$’ was imported by ‘$username’.

Custom Rule deleted 640 Info

Custom Rule '$ruleName$' was deleted by '$username$'.

Custom Rule '$ruleName$ (Unified)' was deleted by '$username$'.

Custom Rule modified 639 Info

Custom Rule '$ruleName$' was modified by '$username$'.

Custom Rule '$ruleName$ (Unified)' was modified by '$username$'.

‘$ruleName$’ was imported by ‘$username’.

Device Rule created 641 Info

Device Rule for ‘$ruleName$’ with id ‘$ruleID$’ was created by '$username$'.

Device Rule deleted 642 Info

Rule for device '$deviceName$' with id ‘$ruleID$’ was removed by '$username$'.

Device Rule modified 643 Info

Device Rule ‘$ruleName$’ with id ‘$ruleID$’ was modified by '$username$'.

File approval created 627 Info

Approval '$ruleName$' for hash [$hash$] was created by '$username$'.

Approval ‘$ruleName (Unified)’ for hash [$hash$] was created by '$username$'.

File '$filepath$ ' with hash [$hash$] was approved based on Reputation.

$param1$ files were approved based on Reputation.

Notes: This event occurs when the rule is created on the server, not when a file instance is approved. In the last example, ‘$param1$ files’ links to a list of files approved by reputation in this event.

File approval deleted 629 Info

Approval '$ruleName$' for hash [$hash$] was deleted by '$username$'.

Approval ‘$ruleName (Unified)’ for hash [$hash$] was deleted by '$username$'.

Approval of file '$filePathAndName$' with hash [$hash$] was removed based on Reputation.

Approval of $param1$ files were removed based on Reputation.

Notes: This event occurs when the approval rule is deleted on the server, not when approval of a file instance is removed. For the last example, ‘$param1$ files’ is a link to the Files on Computers page where the files whose approvals were removed will be listed if they still exist in their respective locations.

File approval modified 628 Info

Approval '$ruleName$' for hash [$hash$] was modified by '$username$'.

Approval ‘$ruleName (Unified)’ for hash [$hash$] was modified by '$username$'.

File approved (certificate) 660 Info File '$filePathAndName$' was approved by certificate '$param1$'.
File ban created 635 Info

Ban '$name$' for [$hash$] was created by '$username$'.

Ban ‘$name$ (Unified)’ for [$hash$] was created by '$username$'.

Note: $name$ is either the name of the banned file or a user-created name (usually for multi-file bans).

File ban deleted 637 Info

Ban '$name$' for [$hash$] was deleted by '$username$'.

Ban ‘$name$ (Unified)’ for [$hash$] was deleted by '$username$'.

Note: $name$ is the name of the banned file or a user-created name (usually for multi-file bans).

File ban modified 636 Info

Ban '$name$' for [$hash$] was modified by '$username$'.

Ban ‘$name$ (Unified)’ for [$hash$] was modified by '$username$'.

Note: $name$ is the name of the banned file or a user-created name (usually for multi-file bans).

File local approval 623 Info File '$filePathAndName$' [$hash$] was locally approved on computer $computer$ by '$userName$'.
File properties modified 611 Info

There are multiple possible descriptions for this subtype. Examples:

File [$hash$] was approved by '$username$'.

File [$hash$] was marked as an installer by '$username$'.

Reputation was disabled for file [$hash$] by '$username$’.

File remove local approval 625 Info File '$filePathAndName$' [$hash$] was changed to unapproved on computer $computer$ by '$userName$'.
Install package creation scheduled 603 Notice

An $param1$ install package $policyName$.msi was scheduled for creation by '$username$'.

Note: Param1 is either empty or “automatic” for packages that allow automatic AD Policy assignment.

Justification created 650 Info

Justification Id $param2$ was created by user '$username$'.

Justification duplicate created 664 Info Duplicate of Justification Id $param2$ was created by user '$username$'.
Memory Rule created 129 Info

Memory Rule '$ruleName$' created by '$username$'.

Memory Rule '$ruleName$ (Unified)' created by '$username$'.

‘$ruleName$’ was imported by ‘$username’.

Memory Rule deleted 131 Info

Memory Rule '$ruleName$' deleted by '$username$'.

Memory Rule '$ruleName$ (Unified)' deleted by '$username$'.

Memory Rule modified 130 Info

Memory Rule '$ruleName$' modified by '$username$'.

Memory Rule '$ruleName$ (Unified)' modified by '$username$'.

‘$ruleName$’ was imported by ‘$username’.

Notifier created 153 Info Notifier ‘$notifierName$’ was created by '$username$'
Notifier deleted 154 Info Notifier ‘$notifierName$’ was deleted by '$username$'
Notifier modified 155 Info Notifier ‘$notifierName$’ was modified by '$username$'
Policy AD rules changed 604 Notice

'$username$' created an AD rule for mapping $param1$ to the Policy $policyName$.

Policy created 600 Info Policy '$policyName$' was created by '$username$'.
Policy deleted 601 Info Policy '$policyName$' was deleted by '$username$'.
Policy file tracking disabled 606 Notice File tracking has been disabled for Policy '$policyName$' by '$userName$'.
Policy file tracking enabled 607 Notice File tracking has been enabled for Policy '$policyName$' by '$userName$'.
Policy modified 602 Info Policy '$policyName$' was modified by '$username$'.
Process demoted 1006 Notice Process $filePathAndName$ was demoted on the computer '$computer$'. New files written by this process will be unapproved.
Publisher approval created 618 Info Publisher '$publisherName$' was approved by '$username$'.
Publisher approval removed 619 Info Publisher '$publisherName$' approval was removed by '$username$'.
Publisher ban created 657 Info Publisher $publisherName$ was banned by $username$.
Publisher ban deleted 659 Info Publisher $publisherName$ ban was removed by '$username$'.
Publisher modified 630 Info Publisher '$publisherName$' was edited by '$username$'.
Registry Rule created 132 Info

Registry Rule '$ruleName$' created by '$username$'.

Registry Rule '$ruleName$ (Unified)' created by '$username$'.

‘$ruleName$’ was imported by ‘$username’.

Registry Rule deleted 134 Info

Registry Rule '$ruleName$' deleted by '$username$'.

Registry Rule '$ruleName$ (Unified)' deleted by '$username$'.

Registry Rule modified 133 Info

Registry Rule '$ruleName$' modified by '$username$'.

Registry Rule '$ruleName$ (Unified)' modified by '$username$'.

‘$ruleName$’ was imported by ‘$username’.

Reputation settings modified 144 Info

Reputation was enabled by '$username$'.

Reputation was disabled by '$username$'.

Reputation settings were modified by '$username$'.

Rules exported 200 Info

Custom Rules were exported by '$username$'.

Memory Rules were exported by '$username$'.

Registry Rules were exported by '$username$'.

Script Rule created 647 Info

Script Rule '$ruleName$' was created by '$username$'.

Script Rule deleted 648 Info

Script Rule '$ruleName$' was deleted by '$username$'.

Script Rule modified 649 Info

Script Rule '$ruleName$' was modified by '$username$'.

Trusted Directory check 608 Info

Trusted Directory '$pathName$' on computer '$computer$' is '$param2$'.

Trusted Directory created 613 Info

Trusted directory '$pathname$' added by '$username$'.

Trusted Directory deleted 615 Info

Trusted directory '$pathname$' deleted by '$username$'.

Trusted Directory import 626

Info,

Warning,

Error

Trusted package '$param1$' from '$source$' has been processed.

Notes: Source may be a computer name or a manifest name. Severity is Info for status imports; Warning for improperly signed or misidentified manifests; Error for all other cases.

Trusted Directory modified 614 Info

Trusted directory '$filePathAndName$' modified by '$username$'.

Trusted Directory scan 609 Info

Pre-approval scan started for '$filePathAndName$'. Approval ID: $param1$. Job ID: $param2$.

Trusted User added 616 Info Trusted User '$name$' was added by '$username$'.
Trusted User deleted 617 Info Trusted User '$name$' was deleted by '$username$'.
Unified rule overridden 665 Info

Unified rule '$param1$' was overridden by '$username$'

Updater disabled 621 Info Updater '$updaterName$' was disabled by '$username$'.
Updater enabled 620 Info Updater '$updaterName$' was enabled by '$username$'.
Yara rule created 220 Info Yara Rule '$param1$' created by '$username$'.
Yara rule deleted 222 Info Yara Rule '$param1$' deleted by '$username$'.
Yara rule modified 221 Info Yara Rule '$param1$' modified by '$username$'.