Event ID 4718: Logon right removed
- Event ID
- 4718
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Policy changes
- Default logging
- Logged by default
What event 4718 means
Event 4718 is the counterpart of 4717: a logon right was removed from a security principal. TargetSid is the principal and AccessRemoved the right, for example SeRemoteInteractiveLogonRight or SeDenyNetworkLogonRight.
Removing an allow right restricts access; removing a deny right widens it. Deny rights like SeDenyNetworkLogonRight and SeDenyRemoteInteractiveLogonRight are commonly used to keep privileged or local accounts from logging on remotely, so their removal outside a GPO change is significant.
As with 4717, most records come from Group Policy with the computer account or SYSTEM as subject.
When it is logged
Advanced Audit Policy Configuration > Policy Change > Audit Authentication Policy Change (Success). Enabled for Success in the default Windows audit policy.
Key fields
| Field | What it tells you |
|---|---|
| SubjectUserName | Account that made the change; the computer account or SYSTEM for Group Policy. |
| SubjectLogonId | Logon session of the subject. |
| TargetSid | SID of the account or group that lost the right. |
| AccessRemoved | Logon right removed, using the same names as 4717 (e.g. SeNetworkLogonRight, SeDenyRemoteInteractiveLogonRight, SeServiceLogonRight). |
Common benign sources
- Group Policy re-applying User Rights Assignment and removing rights granted locally.
- Decommissioning of service accounts or removal of support staff access.
What attackers do that produces it
- Removing a
SeDeny...LogonRightthat blocked local or privileged accounts from network or RDP logons, to open a lateral movement path. - Removing a right granted earlier (4717) after use, to clean up.
Investigation tips
- Pay most attention to removed deny rights; check which principal is now allowed to log on.
- Look for a matching 4717 and a GPO refresh around the same time to decide if the change is policy-driven.
- Correlate with subsequent 4624 logons by the affected principal.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1098 Account Manipulation | Persistence, Privilege Escalation |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.