Event ID 4705: User right removed
- Event ID
- 4705
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Policy changes
- Default logging
- Needs configuration
What event 4705 means
Event 4705 is written when a privilege is removed from a security principal in the computer's local security policy. It has the same shape as 4704: TargetSid is the principal and PrivilegeList the rights taken away.
Most records come from Group Policy re-applying the defined User Rights Assignment, which removes rights that were granted outside the policy. A 4704 followed shortly by a 4705 for the same SID is often exactly that: a manual grant being reverted at the next GPO refresh — or an attacker cleaning up after using the right.
Removal of rights from security tooling or administrators can also be a way to impair defenses or operations.
When it is logged
Advanced Audit Policy Configuration > Policy Change > Audit Authorization Policy Change (Success).
Key fields
| Field | What it tells you |
|---|---|
| SubjectUserName | Account that made the change; the computer account when applied by Group Policy. |
| SubjectLogonId | Logon session of the subject. |
| TargetSid | SID of the account or group that lost the right. |
| PrivilegeList | Privileges removed, e.g. SeBackupPrivilege, SeSecurityPrivilege. |
Common benign sources
- Group Policy refresh removing rights that are not part of the defined policy.
- Uninstallation of software that had granted rights to its service account.
What attackers do that produces it
- Removing a right granted earlier (4704) after it was used, to reduce traces.
- Stripping
SeSecurityPrivilegeor other rights from security or admin groups to disrupt auditing and response.
Investigation tips
- Look for a matching 4704 for the same
TargetSidand privilege; the window between them is when the right was usable. - Check whether the subject is the computer account (GPO) or a user performing a manual change.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1098 Account Manipulation | Persistence, Privilege Escalation |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.