Windows 11 • Release: 6 Benchmark Date: 05 Jan 2026

CAT II V-253289 WN11-00-000175

The Secondary Logon service must be disabled on Windows 11.

Documentable No
Rule ID SV-253289r958478_rule
CCI References
CCI-000381

The Secondary Logon service provides a means for entering alternate credentials, typically used to run commands with elevated privileges. Using privileged credentials in a standard user session can expose those credentials to theft.

Check Procedure

Run "Services.msc".

Locate the "Secondary Logon" service.

If the "Startup Type" is not "Disabled" or the "Status" is "Running", this is a finding.

Fix Action

Configure the "Secondary Logon" service "Startup Type" to "Disabled".