Multiple Event ID 4703 being logged in Security Event Log
说明
The Windows Security event log is filling with Event ID 4703 on servers running the Change Auditor agent. The Change Auditor agent, NPSrvHost.exe, is the Process name.
原因
Microsoft captures Successes and Failures of EventID 4073 "A user right token has been adjusted" and is turned on by default in the Local Auditing Policy.
解决办法
Either ignore the event or disable the Success Auditing of that event in the Local Auditing Policy: