win_audit_policy_system module not changing the value

Hi,

Trying to use ansible on windows server 2016. winRM connection works and other modules run perfectly fine.

simple playbook and run win_audit_policy_system to change the values.

- name: “Ensure ‘Audit Application Group Management’ is set to ‘Success and Failure’”
win_audit_policy_system:
subcategory: Application Group Management
audit_type: success, failure

- name: “Ensure ‘Audit Computer Account Management’ is set to ‘Success and Failure’”
win_audit_policy_system:
subcategory: Computer Account Management
audit_type: success, failure

When I go to check on the Machine, the state of the policy does not change. I already restarted the machine and run the gpupdate /force. Any ideas?

Hello,

Hope anyone could help me!

(attachments)

Try running with more verbosity?

(attachments)

Hello Visser,

The values were changed in CLI but not changed in GUI.

There is one interesting things.The value was changed both GUI and CLI If I run with category options.

  • name: “Audit account management”
    win_audit_policy_system:
    category: Account management
    audit_type: success, failure

  • name: “Audit directory service access”
    win_audit_policy_system:
    category: DS Access
    audit_type: success, failure

If I run with subcategory options,the value was not changed in GUI.

  • name: “17.2.1,CCE-38329-9 | Ensure ‘Audit Application Group Management’ is set to ‘Success and Failure’”
    win_audit_policy_system:
    subcategory: Application Group Management
    audit_type: success, failure

  • name: “17.2.2,CCE-38004-8 | Ensure ‘Audit Computer Account Management’ is set to ‘Success and Failure’”
    win_audit_policy_system:
    subcategory: Computer Account Management
    audit_type: success, failure

(attachments)

Hello !

(attachments)