Ravindra BagaleCourses & study guides Track your progress

Labs · Cyber Security

Lab: Separate Your Admin and Daily Accounts on Windows and Audit Failed Logons with Event ID 4625

Beginner35 minYour own Windows 10/11 laptop · Settings, Event Viewer, auditpol, PowerShell (as admin)

Course: Cyber Security · Chapter 38: Active Directory Attacks and Defence

Chapter 38 explains Active Directory attacks and defence; this lab practises the two core defences, separate admin accounts and logon auditing, on a single Windows PC.

Chala mitrano! In company networks, most Active Directory attacks succeed because people browse and read email while logged in as admins, and because nobody watches failed logons. We can practise both defences on our own Windows laptop: a separate daily account without admin rights, and an eye on Event ID 4625. Chala!

Suppose we are…

Suppose we are a Windows administrator at Cognizant. The security team's top two rules for staff laptops and servers are: do daily work as a standard user, use admin rights only when needed; and record failed logons so password guessing is noticed. A full Active Directory lab needs several heavy VMs, so we practise the same two controls on our own Windows laptop.

Goal of this lab

By the end you will have:

  • A standard (non-admin) daily account and a separate admin account.
  • UAC set to Always notify.
  • Logon auditing on, with test failures found in Event Viewer and PowerShell (Event ID 4625).

What you need (all free)

  • Your own Windows 10 or 11 laptop where you are an administrator. About 35 minutes.
  • Your password manager (Lab 22) for the new password.

Safety and ethics

Make these changes only on your own computer. Your current account stays an administrator until the new daily account works, so you cannot lock yourself out. Test failed logons only against your own accounts.

Steps

  1. Check who is an administrator now. Open Terminal (Admin) and run:

    net localgroup Administrators
    

    What you should see: your current account (and the built-in Administrator, usually disabled).

  2. Create a standard daily account: Settings → Accounts → Other users (Windows 10: Family & other users) → Add account → I don't have this person's sign-in information → Add a user without a Microsoft account. Name it daily-yourname, set a strong password from your password manager.

  3. Confirm it is Standard: in the same page click the new account → Change account type → Standard User → OK.
  4. Set UAC to the strongest level: Start → type UAC → Change User Account Control settings → move the slider to the top, Always notify → OK.
  5. Turn on logon auditing (English Windows; on other languages use Local Security Policy → Advanced Audit Policy → Logon/Logoff → Audit Logon):

    auditpol /set /subcategory:"Logon" /success:enable /failure:enable
    auditpol /get /subcategory:"Logon"
    

    What you should see: Logon Success and Failure.

  6. Create test failures: press Windows + L, choose daily-yourname, type a wrong password twice, then the right one. Look around, then sign out and sign back in to your admin account.

  7. Open Event Viewer → Windows Logs → Security → Filter Current Log… → in type 4625 → OK.

    What you should see: two events "An account failed to log on" with Account Name: daily-yourname, Failure Reason: Unknown user name or bad password, Logon Type: 2 (interactive, at the keyboard).

  8. Get the same in PowerShell (admin), the way a SOC script would:

    Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625} -MaxEvents 5 | Select-Object TimeCreated, @{n='Account';e={$_.Properties[5].Value}}, @{n='LogonType';e={$_.Properties[10].Value}}
    

    What you should see: your two failures with time, account daily-yourname and logon type 2.

  9. Find the successful logon (Event ID 4624) for the daily account right after the failures. Filter by 4624 and look for Account Name: daily-yourname with Logon Type: 2.

  10. From tomorrow, use daily-yourname for browsing, email and study. When Windows asks for admin rights, type the admin account's password in the UAC prompt.

Ravindra Bagale's Tip

In a company domain, the same idea becomes "tiered admin": a normal account for email, a separate admin account only for servers, and LAPS so every PC has a unique local admin password. And failed logons (4625) followed by a success (4624) is the Windows version of the pattern from Lab 31. Same story, different log!

Common mistakes

Mistake What happens Fix
Making the daily account an Administrator too Malware you open runs with admin rights Account type must be Standard User
Removing admin from your only account first You lose admin access Create and test the new account first
Running auditpol without admin "Access is denied" Use Terminal (Admin)
Filtering the Application log instead of Security No 4625 events found Windows Logs → Security
Leaving UAC at the default level Some admin actions happen silently Set Always notify

Self-check checklist

0 of 5 done

Try-at-home challenge

Make Windows lock an account after repeated wrong passwords. Which setting do you use, and how do you check it?

Check your answer

In Terminal (Admin): net accounts /lockoutthreshold:10 /lockoutwindow:15 /lockoutduration:15 (lock for 15 minutes after 10 failures in 15 minutes). Check with net accounts. Windows 11 ships with a similar default policy. A lockout produces Event ID 4740 on the machine, which a SOC watches together with 4625.

Samjla ka? Daily work without admin, failed logons recorded and reviewed. Aata pudhe jaauya: Chapter 39 checks suspicious files safely.