Logon Rights and User Privileges

Andrei Miroshnikov · 2018

This chapter details about monitoring logon rights and user privileges policy changes, user privileges use, and use of backup and restore privileges. It also illustrates an example of an unsuccessful service call event in the Unsuccessful Call of a Privileged Service.evtx file in the download material. All logon session privileges in the session's token are disabled by default after the session is created. After a privilege or privileges are enabled, it is up to the application to disable them after they're used. When a privilege is enabled in the session token it does not mean it will be used. Depending on the operation performed, privilege use actions are divided into two categories: privileged service called, and operation performed on a privileged object. The backup (SeBackupPrivilege) and restore (SeRestorePrivilege) privilege audit has a dedicated group policy setting to configure in case to track use of these privileges.

Read the paper · More papers on PaperTik