Event ID 4672

Special privileges assigned to new logon

Special privileges assigned to new logon.

Subject:
    Security ID:        %1
    Account Name:       %2
    Account Domain:     %3
    Logon ID:           %4

Privileges:             %5


This event is generated for new account logons whenever one of the following sensitive privileges is assigned to the logon session. For a complete list of privileges see the insertion string below.

PrivilegeDescription
SeTcbPrivilegeAct as part of the operating system
SeBackupPrivilegeBack up files and directories
SeCreateTokenPrivilegeCreate a token object
SeDebugPrivilegeDebug programs
SeEnableDelegationPrivilegeEnable computer and user accounts to be trusted for delegation
SeAuditPrivilegeGenerate security audits
SeImpersonatePrivilegeImpersonate a client after authentication
SeLoadDriverPrivilegeLoad and unload device drivers
SeSecurityPrivilegeManage auditing and security log
SeSystemEnvironmentPrivilegeModify firmware environment values
SeAssignPrimaryTokenPrivilegeReplace a process-level token
SeRestorePrivilegeRestore files and directories
SeTakeOwnershipPrivilegeTake ownership of files or other objects
Auditing:     Conditional

Enable auditing if you are utilizing the "Special Groups" windows feature.


Volume:     Low

When "Special Groups" are enabled, volume depends on the configuration and types of users logging on.


Every logon of the SYSTEM account triggers this event.

NIST 800-171: 3.1.7
NIST SP 800-53: AC-6(1), AC-6(2),
CMMC v2 L2: AC-L2-3.1.7


Microsoft Documentation

Event ID - 4672



NameFieldInsertion StringOSExample
Security IDSubjectUserSid%1Any THEDOMAIN\UserThree
Account NameSubjectUserName%2Any UserThree
Account DomainSubjectDomainName%3Any THEDOMAIN
Logon IDSubjectLogonId%4Any 0x345423
PrivilegesPrivilegeList%5Any View Codes


Lookup Audit Policy Configuration Settings

C:\> AuditPol.exe /get /subcategory:"Special Logon"



LEFT/RIGHT arrow keys for navigation

Back to List