Labs · Cyber Security
Lab: Separate Your Admin and Daily Accounts on Windows and Audit Failed Logons with Event ID 4625
Course: Cyber Security · Chapter 38: Active Directory Attacks and Defence
Chapter 38 explains Active Directory attacks and defence; this lab practises the two core defences, separate admin accounts and logon auditing, on a single Windows PC.
Chala mitrano! In company networks, most Active Directory attacks succeed because people browse and read email while logged in as admins, and because nobody watches failed logons. We can practise both defences on our own Windows laptop: a separate daily account without admin rights, and an eye on Event ID 4625. Chala!
चला मित्रांनो! Company networks मध्ये बहुतेक Active Directory attacks यशस्वी होतात कारण लोक admin म्हणून login असताना browsing आणि email करतात, आणि failed logons कोणी बघत नाही. आपण दोन्ही defences आपल्या Windows laptop वर practise करू शकतो: admin rights नसलेलं वेगळं daily account, आणि Event ID 4625 वर नजर. चला!
चलो दोस्तों! Company networks में ज़्यादातर Active Directory attacks इसलिए सफल होते हैं क्योंकि लोग admin बनकर login रहते हुए browsing और email करते हैं, और failed logons कोई नहीं देखता। हम दोनों defences अपने Windows laptop पर practise कर सकते हैं: बिना admin rights वाला अलग daily account, और Event ID 4625 पर नज़र। चलो!
Suppose we are…
Suppose we are a Windows administrator at Cognizant. The security team's top two rules for staff laptops and servers are: do daily work as a standard user, use admin rights only when needed; and record failed logons so password guessing is noticed. A full Active Directory lab needs several heavy VMs, so we practise the same two controls on our own Windows laptop.
Goal of this lab
By the end you will have:
- A standard (non-admin) daily account and a separate admin account.
- UAC set to Always notify.
- Logon auditing on, with test failures found in Event Viewer and PowerShell (Event ID 4625).
What you need (all free)
- Your own Windows 10 or 11 laptop where you are an administrator. About 35 minutes.
- Your password manager (Lab 22) for the new password.
Safety and ethics
Make these changes only on your own computer. Your current account stays an administrator until the new daily account works, so you cannot lock yourself out. Test failed logons only against your own accounts.
Steps
-
Check who is an administrator now. Open Terminal (Admin) and run:
net localgroup AdministratorsWhat you should see: your current account (and the built-in
Administrator, usually disabled). -
Create a standard daily account: Settings → Accounts → Other users (Windows 10: Family & other users) → Add account → I don't have this person's sign-in information → Add a user without a Microsoft account. Name it
daily-yourname, set a strong password from your password manager. - Confirm it is Standard: in the same page click the new account → Change account type → Standard User → OK.
- Set UAC to the strongest level: Start → type
UAC→ Change User Account Control settings → move the slider to the top, Always notify → OK. -
Turn on logon auditing (English Windows; on other languages use Local Security Policy → Advanced Audit Policy → Logon/Logoff → Audit Logon):
auditpol /set /subcategory:"Logon" /success:enable /failure:enable auditpol /get /subcategory:"Logon"What you should see:
Logon Success and Failure. -
Create test failures: press Windows + L, choose
daily-yourname, type a wrong password twice, then the right one. Look around, then sign out and sign back in to your admin account. -
Open Event Viewer → Windows Logs → Security → Filter Current Log… → in
type 4625→ OK.What you should see: two events "An account failed to log on" with Account Name:
daily-yourname, Failure Reason: Unknown user name or bad password, Logon Type: 2 (interactive, at the keyboard). -
Get the same in PowerShell (admin), the way a SOC script would:
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625} -MaxEvents 5 | Select-Object TimeCreated, @{n='Account';e={$_.Properties[5].Value}}, @{n='LogonType';e={$_.Properties[10].Value}}What you should see: your two failures with time, account
daily-yournameand logon type2. -
Find the successful logon (Event ID 4624) for the daily account right after the failures. Filter by
4624and look for Account Name:daily-yournamewith Logon Type: 2. - From tomorrow, use
daily-yournamefor browsing, email and study. When Windows asks for admin rights, type the admin account's password in the UAC prompt.
Ravindra Bagale's Tip
In a company domain, the same idea becomes "tiered admin": a normal account for email, a separate admin account only for servers, and LAPS so every PC has a unique local admin password. And failed logons (4625) followed by a success (4624) is the Windows version of the pattern from Lab 31. Same story, different log!
Ravindra Bagale's Tip – मराठी
Company domain मध्ये हीच कल्पना "tiered admin" बनते: email साठी साधं account, फक्त servers साठी वेगळं admin account, आणि LAPS म्हणजे प्रत्येक PC चा unique local admin password. आणि failed logons (4625) नंतर success (4624) हा Lab 31 च्या pattern चा Windows version आहे. तीच गोष्ट, वेगळा log!
Ravindra Bagale's Tip – हिंदी
Company domain में यही idea "tiered admin" बनता है: email के लिए साधारण account, सिर्फ servers के लिए अलग admin account, और LAPS ताकि हर PC का unique local admin password हो। और failed logons (4625) के बाद success (4624) Lab 31 वाले pattern का Windows version है। वही कहानी, अलग log!
Common mistakes
| Mistake | What happens | Fix |
|---|---|---|
| Making the daily account an Administrator too | Malware you open runs with admin rights | Account type must be Standard User |
| Removing admin from your only account first | You lose admin access | Create and test the new account first |
| Running auditpol without admin | "Access is denied" | Use Terminal (Admin) |
| Filtering the Application log instead of Security | No 4625 events found | Windows Logs → Security |
| Leaving UAC at the default level | Some admin actions happen silently | Set Always notify |
Self-check checklist
0 of 5 done
Try-at-home challenge
Make Windows lock an account after repeated wrong passwords. Which setting do you use, and how do you check it?
Check your answer
In Terminal (Admin): net accounts /lockoutthreshold:10 /lockoutwindow:15 /lockoutduration:15 (lock for 15 minutes after 10 failures in 15 minutes). Check with net accounts. Windows 11 ships with a similar default policy. A lockout produces Event ID 4740 on the machine, which a SOC watches together with 4625.
Samjla ka? Daily work without admin, failed logons recorded and reviewed. Aata pudhe jaauya: Chapter 39 checks suspicious files safely.