Skip to content
Security

Event ID 4717: Logon right granted

System security access was granted to an accountSecurity event 4717 logs a logon right (e.g. SeRemoteInteractiveLogonRight, SeServiceLogonRight) being granted to an account or group in local security policy.
4717
Event ID
4717
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Policy changes
Default logging
Logged by default

What event 4717 means

Event 4717 is written when a logon right is granted to a security principal: the rights that control how an account may log on, such as SeInteractiveLogonRight, SeNetworkLogonRight, SeRemoteInteractiveLogonRight, SeBatchLogonRight and SeServiceLogonRight, and their SeDeny... counterparts. Privileges such as SeDebugPrivilege are logged in 4704 instead.

TargetSid is the principal and AccessGranted the right. Most records are Group Policy applying User Rights Assignment, with the computer account or SYSTEM as subject. A grant outside a GPO refresh, or to an unexpected account, is worth checking.

Granting RDP logon to a new account, or service logon to an account that runs attacker tooling, is a common way to prepare access on a host.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Policy Change > Audit Authentication Policy Change (Success). Enabled for Success in the default Windows audit policy.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that made the change; the computer account or SYSTEM when applied by Group Policy.
SubjectLogonIdLogon session of the subject; 0x3e7 for SYSTEM.
TargetSidSID of the account or group that received the right.
AccessGrantedLogon right granted.
ValueMeaning
SeInteractiveLogonRightAllow log on locally.
SeNetworkLogonRightAccess this computer from the network.
SeRemoteInteractiveLogonRightAllow log on through Remote Desktop Services.
SeBatchLogonRightLog on as a batch job (scheduled tasks).
SeServiceLogonRightLog on as a service.
SeDenyInteractiveLogonRightDeny log on locally.
SeDenyNetworkLogonRightDeny access to this computer from the network.
SeDenyRemoteInteractiveLogonRightDeny log on through Remote Desktop Services.
SeDenyBatchLogonRightDeny log on as a batch job.
SeDenyServiceLogonRightDeny log on as a service.

Common benign sources

  • Group Policy applying the User Rights Assignment defined for the host.
  • Service installation granting SeServiceLogonRight to the service account (e.g. through services.msc).
  • Administrators granting RDP access to support staff.

What attackers do that produces it

  • Granting SeRemoteInteractiveLogonRight to a newly created or compromised account to enable RDP access.
  • Granting SeServiceLogonRight or SeBatchLogonRight to an account used for malicious services or tasks.

Investigation tips

  • Resolve TargetSid and check whether that principal should hold the right on this host.
  • If the subject is not the computer account, pivot SubjectLogonId to 4688 to see how the change was made.
  • Look for follow-on logons by the principal (4624 with the matching logon type) after the grant.

MITRE ATT&CK techniques

TechniqueTactics
T1098 Account ManipulationPersistence, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading