Skip to content
Intune Audit Security Group Management Policy

Intune Audit Security Group Management Policy

Written By Abhinav Rana
Last Updated July 24, 2026
Posted In Intune
SHARE

This article is written to take you through implementing the Intune Audit Security Group Management Policy. We’ll use Intune’s Settings Catalog to enforce this policy, emphasizing a practical, hands-on approach to make you understand the Audit Security Group Management Policy in action with Intune.

Audit Security Group Management Policy setting enables the auditing of events related to modifications in security groups, including the creation, alteration, or deletion of security groups, as well as the addition or removal of members from a security group and changes in the group type.

If configured, this policy setting triggers an audit event when an attempt is made to modify a security group. Successful attempts are recorded as Success audits, while unsuccessful attempts are recorded as Failure audits. In the absence of configuration for this policy setting, no audit event is generated when changes occur in a security group.

This particular subcategory provides a record for each occurrence of security group management events, encompassing instances when a security group undergoes creation, modification, or deletion, as well as when members are added to or removed from a security group.

Patch My PC

Enabling this Audit policy setting allows administrators to monitor these events, aiding in identifying potentially malicious, accidental, or authorized activities related to creating security group accounts. Events falling under this subcategory include:

  • 4727: A security-enabled global group was created.
  • 4728: A member was added to a security-enabled global group.
  • 4729: A member was removed from a security-enabled global group.
  • 4730: A security-enabled global group was deleted.
  • 4731: A security-enabled local group was created.
  • 4732: A member was added to a security-enabled local group.
  • 4733: A member was removed from a security-enabled local group.
  • 4734: A security-enabled local group was deleted.
  • 4735: A security-enabled local group was changed.
  • 4737: A security-enabled global group was changed.
  • 4754: A security-enabled universal group was created.
  • 4755: A security-enabled universal group was changed.
  • 4756: A member was added to a security-enabled universal group.
  • 4757: A member was removed from a security-enabled universal group.
  • 4758: A security-enabled universal group was deleted.
  • 4764: A group’s type was changed.
Intune Audit Security Group Management Policy Fig.1
Intune Audit Security Group Management Policy Fig.1

Audit Security Group Management Policy

To create a Audit Security Group Management Policy, follow the steps stated below:

  • Sign in to the Intune Admin Center portal https://intune.microsoft.com/.
  • Select Devices > Windows > Configuration profiles > Create a profile.

In Create Profile, I select Windows 10 and later in Platform, I choose the Profile Type as Settings catalog. Click on the Create button.

Intune Audit Security Group Management Policy Fig.2
Intune Audit Security Group Management Policy Fig.2

On the Basics tab pane, I provide a name for the policy as “Audit Security Group Management Policy.”

  • Optionally, if you want, you can enter a policy description and proceed by selecting “Next“.
Intune Audit Security Group Management Policy Fig.3
Intune Audit Security Group Management Policy Fig.3

Now, in Configuration Settings, Click Add Settings to browse or search the catalog for the settings I want to configure.

Intune Audit Security Group Management Policy Fig.4
Intune Audit Security Group Management Policy Fig.4

In the Settings Picker windows. I searched for the keyword Audit. I found the category Local Policies Security Options and selected this.

  • I see the sub-category Audit Security Group Management. After selecting that, click the cross mark at the right-hand corner, as shown below.
Intune Audit Security Group Management Policy Fig.5
Intune Audit Security Group Management Policy Fig.5

Here in Auditing, I have set the Audit Security Group Management to Success.

Intune Audit Security Group Management Policy Fig.6
Intune Audit Security Group Management Policy Fig.6

Using Scope tags, you can assign a tag to filter the profile to specific IT groups. One can add scope tags (if required). More details on Intune Scope Tags Implementation Guide.

  • Click Next to continue.

Now in Assignments, in Included Groups, you need to click on Add Groups and choose Select Groups to include one or more groups. Click Next to continue.

Intune Audit Security Group Management Policy Fig.7
Intune Audit Security Group Management Policy Fig.7

In the Review + Create tab, I review settings. After clicking on Create, changes are saved, and the profile is assigned.

Intune Audit Security Group Management Policy Fig.8
Intune Audit Security Group Management Policy Fig.8

After successfully creating the “Audit Security Group Management Policy,” a notification will appear in the top right-hand corner confirming the action. You can also verify the policy’s existence by navigating to the Configuration Profiles list, where it will be prominently displayed.

Your groups will receive your profile settings when the devices check in with the Intune service. The Policy applies to the device.

Intune Report for Audit Security Group Management Policy

From the Intune Portal, you can view the Intune settings catalog profile report, which provides an overview of device configuration policies and deployment status.

To track the assignment of the policy, you need to select the relevant policy from the Configuration Profiles list, which is the Audit Security Group Management Policy. Then, you can review the device and user check-in status to determine whether the policy has been successfully applied.

  • If you require more detailed information, you can click on “View Report” to access additional insights.
Intune Audit Security Group Management Policy Fig.9
Intune Audit Security Group Management Policy Fig.9

Registry Key Verification – Audit Security Group Management Policy

Now we will verify whether the policy was successfully deployed or not by accessing the registry settings that will hold the group policy configurations on a specific computer. To accomplish this, you can execute “REGEDIT.exe” on the target computer and navigate to the precise registry path mentioned below, where these settings are stored.

Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\providers\5B88AEF1-09E8-43BB-B144-7254ACBBDF3E\default\Device\Audit

When you navigate the above path in the Registry Editor, you will find the registry key named AccountManagement_AuditSecurityGroupManagement. Also, when I navigated to the above path, I saw that the Registry Key was created successfully.

Registry NameValue
AccountManagement_AuditSecurityGroupManagement1
Table 2 – Intune Audit Security Group Management Policy
Intune Audit Security Group Management Policy Fig.10
Intune Audit Security Group Management Policy Fig.10

Windows CSP Details AccountManagement_AuditSecurityGroupManagement

We will see Windows CSP Details for this Policy setting AccountManagement_AuditSecurityGroupManagement. In the absence of configured audit settings or if the audit settings are too permissive across the computers within your organization, the risk exists that security incidents may go undetected, or there may be insufficient evidence for network forensic analysis post-incident.

Conversely, excessively stringent audit settings may result in essential entries in the Security log being overshadowed by a multitude of irrelevant entries, potentially impacting computer performance and the available data storage significantly. Companies operating in specific regulated industries might have legal obligations to log certain events or activities.

CSP URI – ./Device/Vendor/MSFT/Policy/Config/Audit/AccountManagement_AuditSecurityGroupManagement

Deploy Intune Run all Administrators in Admin Approval Mode Policy Fig.10
Intune Audit Security Group Management Policy Fig.11

We are on WhatsApp. To get the latest step-by-step guides and news updates, Join our Channel. Click hereHTMD WhatsApp.

Author

Abhinav Rana is working as an SCCM and Intune Admin with several years of experience. He loves to help the community by sharing his knowledge. He is a B.Tech graduate in Information Technology.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Simplify Windows Devices to Run Only the Required Applications using Intune

Key Takeaways Hey, let’s learn about Simplify Windows Devices to Run Only the Required Applications using Intune. This policy lets administrators replace the default windows shell with a custom or lightweight shell. it improves performance by using system resources and is useful for devices that run a dedicated application. If the policy is disabled or […]

AC Anoop C Nair 8 min read
Intune

Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune

Key Takeaways In this post we are discussing about Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune. Microsoft has announced the general availability of Custom Compliance Settings for macOS in Microsoft Intune. The feature helps organizations strengthen security controls while supporting many types of macOS management scenarios. […]

AC Anoop C Nair 4 min read
Intune

Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune

Key Takeaways In this post we are discussing Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune. Microsoft Intune has received a new update that expands firmware management capabilities for Samsung Galaxy devices through Firmware Versionsintegration. This enhancement gives IT administrators more control over firmware and operating system updates, helping them […]

AC Anoop C Nair 4 min read
Intune

MS Intune Adds Windows Registry Data Collection to Device Inventory for Single Values All Key Values and Subkeys

Key Takeaways Microsoft Intune 2607 introduces Windows Registry Data collection in Device Inventory, allowing IT admins to verify actual device configurations without relying on custom discovery or remediation scripts. Using the Properties Catalog, admins can collect registry information through Single Value, All Values Under a Key (Non-Recursive), or Same Value Across Subkeys. MS Intune Adds […]

AC Anoop C Nair 5 min read