Hello,
Thank you for your question and for reaching out with your question today.
In order to achieve what you're looking for, you can enable UAC auditing (local GPO):
Computer Configuration – Windows Settings – Security Settings – Local Policies – Audit Policy
Enable the policies listed below:
Audit privilege use
Audit process tracking
As a result of this change, you can observe Event ID 4688 and 4689 at the below event location when you change UAC:
Event Viewer – Windows Logs – Security.
If the reply was helpful, please don’t forget to upvote or accept as answer.