The Secondary Logon service must be disabled on Windows 10.

Severity
Group ID
Group Title
Version
Rule ID
Date
STIG Version
mediumV-220732SRG-OS-000095-GPOS-00049WN10-00-000175SV-220732r958478_rule2025-02-253
Description
The Secondary Logon service provides a means for entering alternate credentials, typically used to run commands with elevated privileges. Using privileged credentials in a standard user session can expose those credentials to theft.
ℹ️ Check
Run "Services.msc". Locate the "Secondary Logon" service. If the "Startup Type" is not "Disabled" or the "Status" is "Running", this is a finding.
✔️ Fix
Configure the "Secondary Logon" service "Startup Type" to "Disabled".