The Secondary Logon service must be disabled on Windows 10.
Severity | Group ID | Group Title | Version | Rule ID | Date | STIG Version |
---|---|---|---|---|---|---|
medium | V-220732 | SRG-OS-000095-GPOS-00049 | WN10-00-000175 | SV-220732r958478_rule | 2025-02-25 | 3 |
Description |
---|
The Secondary Logon service provides a means for entering alternate credentials, typically used to run commands with elevated privileges. Using privileged credentials in a standard user session can expose those credentials to theft. |
ℹ️ Check |
---|
Run "Services.msc". Locate the "Secondary Logon" service. If the "Startup Type" is not "Disabled" or the "Status" is "Running", this is a finding. |
✔️ Fix |
---|
Configure the "Secondary Logon" service "Startup Type" to "Disabled". |