17.5.5 Ensure 'Audit Special Logon' is set to 'Success'

Information

This subcategory reports when a special logon is used.

A special logon is a logon that has administrator-equivalent privileges and can be used to elevate a process to a higher level.

Events for this subcategory include: - 4964 : Special groups have been assigned to a new logon.

The recommended state for this setting is: 'Success'.

Solution

To establish the recommended configuration via GP, set the following UI path to 'Success':

Computer Configuration\Policies\Windows Settings\Security Settings\Advanced Audit Policy Configuration\Audit Policies\Logon/Logoff\Audit Special Logon

See Also

https://workbench.cisecurity.org/files/1941