Windows 11 • Release: 6 Benchmark Date: 05 Jan 2026
CAT II V-253289 WN11-00-000175
The Secondary Logon service must be disabled on Windows 11.
Discussion
The Secondary Logon service provides a means for entering alternate credentials, typically used to run commands with elevated privileges. Using privileged credentials in a standard user session can expose those credentials to theft.
Check Procedure
Run "Services.msc". Locate the "Secondary Logon" service. If the "Startup Type" is not "Disabled" or the "Status" is "Running", this is a finding.
Fix Action
Configure the "Secondary Logon" service "Startup Type" to "Disabled".