The Secondary Logon service must be disabled on Windows 10.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-220732
WN10-00-000175
SV-220732r958478_rule
Medium
Description
The Secondary Logon service provides a means for entering alternate credentials, typically used to run commands with elevated privileges. Using privileged credentials in a standard user session can expose those credentials to theft.