Windows 11 OS install clean, about 2 months ago. Fully updated as of this posting. This issue did not occur on Windows 10 or previous versions of Windows on same hardware. This is not a hardware issue. This issue has now happened on multiple instances of Windows 11 either upgraded from Windows 10 or new installation of Windows 11.
Providing the correct AD or local security policy is set, the family of 4800 Event IDs should be published to the security event log. This includes 4800 (lock workstation), 4801 (unlock workstation), and 4802 (invoke screen saver) and 4803 (dismiss screen saver).
With Windows 11 deployments, we are not seeing 4802 or 4803 events generated at all as expected, but we are seeing the expected 4800 and 4801 events. So we per the published Microsoft documentation, believe the correct local security policy settings are, enabled, and configured correctly. So please to not suggest that we validate or enable a local security policy as a quick fix, if 'Audit Other Logon and Logoff Events' was not set, the 4800 and 4801 EventIDs would be missing as well as the 4802 and 4803 EventIDs.
This a simple question, is there a known bug with Windows 11 applicable to this behavior? Or a design change that has removed 4802 and 4803 EventIDs? Would not be the first time Microsoft has removed or changed EventIDs without explicit warning or robust communication.
We are getting feed back from our client base, that monitoring of 4802 and 4803 EventIDs is disappearing from respective environments as Windows 11 is being deployed. This is a real issue, in that monitoring the screen saver state, is a key issue for specific environments, for various reasons, that will not be discussed here, but are relevant and significant to secured and controlled environments.
The hope is that others are seeing the same issue, and being a new issue, it has yet to be significantly communicated? Trying to get some perspective on if this is a major or common issue?
If you don't know how to use GPEDIT.msc or what local security policies are, don't try to respond to this question please. You are not dealing with an IT beginner posting this query. A 40 year career as IT professional, having designed Microsoft OS based security solutions, cloud/global virtual enterprise level solutions, for over 25 years. So please don't suggest the typical call center/scripted cookie cutter foolishness that 90% of questions in this forum get as quasi assistance. This is a serious query, and would greatly appreciate serious knowledgeable responses.