Event ID 4704: User right assigned
- Event ID
- 4704
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Policy changes
- Default logging
- Needs configuration
What event 4704 means
Event 4704 is written when a user right — a privilege such as SeDebugPrivilege, SeBackupPrivilege or SeImpersonatePrivilege — is assigned to a security principal in the computer's local security policy. TargetSid is who received it and PrivilegeList lists what was granted.
Rights usually arrive through Group Policy, in which case the subject is the computer account and the change is applied on every host in scope. A right granted by an interactive admin on a single host, outside a GPO refresh, deserves a closer look.
Logon rights such as SeRemoteInteractiveLogonRight are not privileges and are logged separately in 4717 and 4718.
When it is logged
Advanced Audit Policy Configuration > Policy Change > Audit Authorization Policy Change (Success).
Key fields
| Field | What it tells you |
|---|---|
| SubjectUserName | Account that made the change; the computer account (HOST$) when applied by Group Policy. |
| SubjectLogonId | Logon session of the subject; 0x3e7 for SYSTEM. |
| TargetSid | SID of the account or group that received the right. Resolve it; the name is not included. |
| PrivilegeList | One or more privileges assigned, e.g. SeDebugPrivilege, SeBackupPrivilege, SeLoadDriverPrivilege. |
Common benign sources
- Group Policy applying the User Rights Assignment settings defined for the host.
- Installation of server roles or software that grants rights to their service accounts.
What attackers do that produces it
- Granting a compromised or newly created account powerful privileges such as
SeDebugPrivilege,SeBackupPrivilegeorSeLoadDriverPrivilegefor later abuse. - A malicious GPO that adds rights to an attacker-controlled group across many hosts.
Investigation tips
- Resolve
TargetSidand check whether that principal should hold the listed privileges. - If the subject is a user rather than the computer account, find the tool used through 4688 in that session.
- For GPO-delivered changes, review recent 5136 edits of Group Policy objects on the domain controllers.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1098 Account Manipulation | Persistence, Privilege Escalation |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 1
- HighEnabled User Right in AD to Control User ObjectsRule by @neu5ron, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.