Skip to content
Security

Event ID 4718: Logon right removed

System security access was removed from an accountSecurity event 4718 logs a logon right (such as a Deny logon right or RDP logon right) being removed from an account or group in local security policy.
4718
Event ID
4718
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Policy changes
Default logging
Logged by default

What event 4718 means

Event 4718 is the counterpart of 4717: a logon right was removed from a security principal. TargetSid is the principal and AccessRemoved the right, for example SeRemoteInteractiveLogonRight or SeDenyNetworkLogonRight.

Removing an allow right restricts access; removing a deny right widens it. Deny rights like SeDenyNetworkLogonRight and SeDenyRemoteInteractiveLogonRight are commonly used to keep privileged or local accounts from logging on remotely, so their removal outside a GPO change is significant.

As with 4717, most records come from Group Policy with the computer account or SYSTEM as subject.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Policy Change > Audit Authentication Policy Change (Success). Enabled for Success in the default Windows audit policy.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that made the change; the computer account or SYSTEM for Group Policy.
SubjectLogonIdLogon session of the subject.
TargetSidSID of the account or group that lost the right.
AccessRemovedLogon right removed, using the same names as 4717 (e.g. SeNetworkLogonRight, SeDenyRemoteInteractiveLogonRight, SeServiceLogonRight).

Common benign sources

  • Group Policy re-applying User Rights Assignment and removing rights granted locally.
  • Decommissioning of service accounts or removal of support staff access.

What attackers do that produces it

  • Removing a SeDeny...LogonRight that blocked local or privileged accounts from network or RDP logons, to open a lateral movement path.
  • Removing a right granted earlier (4717) after use, to clean up.

Investigation tips

  • Pay most attention to removed deny rights; check which principal is now allowed to log on.
  • Look for a matching 4717 and a GPO refresh around the same time to decide if the change is policy-driven.
  • Correlate with subsequent 4624 logons by the affected principal.

MITRE ATT&CK techniques

TechniqueTactics
T1098 Account ManipulationPersistence, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading