You can configure User Environment Manager to log the details of elevated application launches and, if desired, de-elevated child processes.
The default behavior of this setting is to log the details of the following events to the Windows event log.
- An application privilege is elevated.
- An elevated application launches a de-elevated child process.
- In the Group Policy Management Editor, double-click Privilege elevation logging to the Windows event log.
- Select Enabled.
- (Optional) If you do not want User Environment Manager to log de-elevated child processes, deselect Log de-elevated application launches.
- Click OK.