Do one of the following.
How to audit windows 10.
Step 2 your computer will boot automatically and you will be logged in to audit mode.
Select and hold or right click the file or folder that you want to audit select properties and then select the security tab.
In the advanced security settings dialog box select the auditing tab and then select continue.
The computer will reboot automatically and log into audit mode.
With this we can force windows to record as much information as possible to the local windows 10 system.
By enabling various auditing event categories you can implement an auditing policy that suits the security needs of your organization.
Oobe or out of box experience is the default mode that allows the consumers to set up windows on a new machine or when they choose to reset windows 10.
You will see a prompt asking about system preparation tool.
A prompt will appear asking you.
If an installation or setting change requires a restart select the system cleanup action enter system audit mode and shutdown option restart.
If you are using a laptop press the fn key.
Double click on audit system events and select success and failure before pressing ok.
This will save the settings and restart the machine back to audit mode.
A basic audit policy specifies categories of security related events that you want to audit.
Advanced security audit policies.