You can configure User Environment Manager to log the details of elevated application launches and, if desired, de-elevated child processes.

The default behavior of this setting is to log the details of the following events to the Windows event log.
  • An application privilege is elevated.
  • An elevated application launches a de-elevated child process.

Procedure

  1. In the Group Policy Management Editor, double-click Privilege elevation logging to the Windows event log.
  2. Select Enabled.
  3. (Optional) If you do not want User Environment Manager to log de-elevated child processes, deselect Log de-elevated application launches.
  4. Click OK.