STIG ID: WN10-00-000175 | SRG: SRG-OS-000095-GPOS-00049 | Severity: medium | CCI: | Vulnerability Id: V-220732
The Secondary Logon service provides a means for entering alternate credentials, typically used to run commands with elevated privileges. Using privileged credentials in a standard user session can expose those credentials to theft.
Configure the "Secondary Logon" service "Startup Type" to "Disabled".
Run "Services.msc".
Locate the "Secondary Logon" service.
If the "Startup Type" is not "Disabled" or the "Status" is "Running", this is a finding.