Event ID 4717: Logon right granted
- Event ID
- 4717
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Policy changes
- Default logging
- Logged by default
What event 4717 means
Event 4717 is written when a logon right is granted to a security principal: the rights that control how an account may log on, such as SeInteractiveLogonRight, SeNetworkLogonRight, SeRemoteInteractiveLogonRight, SeBatchLogonRight and SeServiceLogonRight, and their SeDeny... counterparts. Privileges such as SeDebugPrivilege are logged in 4704 instead.
TargetSid is the principal and AccessGranted the right. Most records are Group Policy applying User Rights Assignment, with the computer account or SYSTEM as subject. A grant outside a GPO refresh, or to an unexpected account, is worth checking.
Granting RDP logon to a new account, or service logon to an account that runs attacker tooling, is a common way to prepare access on a host.
When it is logged
Advanced Audit Policy Configuration > Policy Change > Audit Authentication Policy Change (Success). Enabled for Success in the default Windows audit policy.
Key fields
| Field | What it tells you | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| SubjectUserName | Account that made the change; the computer account or SYSTEM when applied by Group Policy. | ||||||||||||||||||||||
| SubjectLogonId | Logon session of the subject; 0x3e7 for SYSTEM. | ||||||||||||||||||||||
| TargetSid | SID of the account or group that received the right. | ||||||||||||||||||||||
| AccessGranted | Logon right granted.
|
Common benign sources
- Group Policy applying the User Rights Assignment defined for the host.
- Service installation granting
SeServiceLogonRightto the service account (e.g. throughservices.msc). - Administrators granting RDP access to support staff.
What attackers do that produces it
- Granting
SeRemoteInteractiveLogonRightto a newly created or compromised account to enable RDP access. - Granting
SeServiceLogonRightorSeBatchLogonRightto an account used for malicious services or tasks.
Investigation tips
- Resolve
TargetSidand check whether that principal should hold the right on this host. - If the subject is not the computer account, pivot
SubjectLogonIdto 4688 to see how the change was made. - Look for follow-on logons by the principal (4624 with the matching logon type) after the grant.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1098 Account Manipulation | Persistence, Privilege Escalation |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.