Skip to content
Security

Event ID 4705: User right removed

A user right was removedSecurity event 4705 logs a user right (privilege) being removed from an account or group in local security policy. Mirror of event 4704.
4705
Event ID
4705
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Policy changes
Default logging
Needs configuration

What event 4705 means

Event 4705 is written when a privilege is removed from a security principal in the computer's local security policy. It has the same shape as 4704: TargetSid is the principal and PrivilegeList the rights taken away.

Most records come from Group Policy re-applying the defined User Rights Assignment, which removes rights that were granted outside the policy. A 4704 followed shortly by a 4705 for the same SID is often exactly that: a manual grant being reverted at the next GPO refresh — or an attacker cleaning up after using the right.

Removal of rights from security tooling or administrators can also be a way to impair defenses or operations.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Policy Change > Audit Authorization Policy Change (Success).

Key fields

FieldWhat it tells you
SubjectUserNameAccount that made the change; the computer account when applied by Group Policy.
SubjectLogonIdLogon session of the subject.
TargetSidSID of the account or group that lost the right.
PrivilegeListPrivileges removed, e.g. SeBackupPrivilege, SeSecurityPrivilege.

Common benign sources

  • Group Policy refresh removing rights that are not part of the defined policy.
  • Uninstallation of software that had granted rights to its service account.

What attackers do that produces it

  • Removing a right granted earlier (4704) after it was used, to reduce traces.
  • Stripping SeSecurityPrivilege or other rights from security or admin groups to disrupt auditing and response.

Investigation tips

  • Look for a matching 4704 for the same TargetSid and privilege; the window between them is when the right was usable.
  • Check whether the subject is the computer account (GPO) or a user performing a manual change.

MITRE ATT&CK techniques

TechniqueTactics
T1098 Account ManipulationPersistence, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading