title: DN_0066_4704_user_right_was_assigned description: > This event generates every time local user right policy is changed and user right was assigned to an account. You will see unique event for every user loggingpolicy: - LP_0105_windows_audit_authorization_policy_change references: - https://github.com/MicrosoftDocs/windows-itpro-docs/blob/master/windows/security/threat-protection/auditing/event-4704.md category: OS Logs platform: Windows type: Windows Log channel: Security provider: Microsoft-Windows-Security-Auditing fields: - EventID - Computer - Hostname # redundant - SubjectUserSid - SubjectUserName - SubjectDomainName - SubjectLogonId - TargetSid - PrivilegeList sample: | - - 4704 0 0 13570 0 0x8020000000000000 1049866 Security DC01.contoso.local - S-1-5-18 DC01$ CONTOSO 0x3e7 S-1-5-21-3457937927-2839227994-823803824-1104 SeAuditPrivilege SeIncreaseWorkingSetPrivilege