What am I missing here? I'm trying to enable file auditing so I can see who deleted a file via security logs in event viewer. I created the below group policy Computer Configuration > Windows Settings > Local Policies/Audit Policy > Audit Object Access. Enabled for success and failure. The enabled checkbox is checked for the policy. In the delegation tab the computer account I'm trying to set this up for has read and apply policy selected. as well as authenticated users.
On the folder itself I've enabled auditing for "Everyone" for "Delete subfolders and files" as well as "Delete" Success and failure are setup for these. gpresult shows the policy is applied not sure if it matters but gpedit shows the policy is not applied.
Where else should this be set?