Hardware Dev Center

SeAuditingFileOrGlobalEvents routine

The SeAuditingFileOrGlobalEvents routine determines whether file or global events are currently being audited.

Syntax


BOOLEAN SeAuditingFileOrGlobalEvents(
  _In_ BOOLEAN                   AccessGranted,
  _In_ PSECURITY_DESCRIPTOR      SecurityDescriptor,
  _In_ PSECURITY_SUBJECT_CONTEXT SubjectSecurityContext
);

Parameters

AccessGranted [in]

Set to TRUE if the access attempt was successful, FALSE otherwise.

SecurityDescriptor [in]

Pointer to the security descriptor protecting the object being accessed.

SubjectSecurityContext [in]

Pointer to the subject's captured security context.

Return value

SeAuditingFileOrGlobalEvents returns TRUE if file or global events are currently being audited, FALSE otherwise.

Remarks

For more information about security and access control, see the documentation on these topics in the Microsoft Windows SDK.

Requirements

Target platform

Universal

Header

Ntifs.h (include Ntifs.h)

Library

NtosKrnl.lib

DLL

NtosKrnl.exe

IRQL

PASSIVE_LEVEL

See also

SeAuditingFileEvents
SECURITY_DESCRIPTOR
SECURITY_SUBJECT_CONTEXT
SeDeleteObjectAuditAlarm
SeOpenObjectAuditAlarm
SeOpenObjectForDeleteAuditAlarm

 

 

Send comments about this topic to Microsoft

Show:
© 2015 Microsoft