Skip to content
Security

Event ID 4704: User right assigned

A user right was assignedSecurity event 4704 logs a user right (privilege) being assigned to an account or group in local security policy, such as SeDebugPrivilege or SeBackupPrivilege.
4704
Event ID
4704
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Policy changes
Default logging
Needs configuration

What event 4704 means

Event 4704 is written when a user right — a privilege such as SeDebugPrivilege, SeBackupPrivilege or SeImpersonatePrivilege — is assigned to a security principal in the computer's local security policy. TargetSid is who received it and PrivilegeList lists what was granted.

Rights usually arrive through Group Policy, in which case the subject is the computer account and the change is applied on every host in scope. A right granted by an interactive admin on a single host, outside a GPO refresh, deserves a closer look.

Logon rights such as SeRemoteInteractiveLogonRight are not privileges and are logged separately in 4717 and 4718.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Policy Change > Audit Authorization Policy Change (Success).

Key fields

FieldWhat it tells you
SubjectUserNameAccount that made the change; the computer account (HOST$) when applied by Group Policy.
SubjectLogonIdLogon session of the subject; 0x3e7 for SYSTEM.
TargetSidSID of the account or group that received the right. Resolve it; the name is not included.
PrivilegeListOne or more privileges assigned, e.g. SeDebugPrivilege, SeBackupPrivilege, SeLoadDriverPrivilege.

Common benign sources

  • Group Policy applying the User Rights Assignment settings defined for the host.
  • Installation of server roles or software that grants rights to their service accounts.

What attackers do that produces it

  • Granting a compromised or newly created account powerful privileges such as SeDebugPrivilege, SeBackupPrivilege or SeLoadDriverPrivilege for later abuse.
  • A malicious GPO that adds rights to an attacker-controlled group across many hosts.

Investigation tips

  • Resolve TargetSid and check whether that principal should hold the listed privileges.
  • If the subject is a user rather than the computer account, find the tool used through 4688 in that session.
  • For GPO-delivered changes, review recent 5136 edits of Group Policy objects on the domain controllers.

MITRE ATT&CK techniques

TechniqueTactics
T1098 Account ManipulationPersistence, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading