> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/logon-assigned-right.md).

# XDM\_CONST.LOGON\_ASSIGNED\_RIGHT

User rights that are assigned in this logon. See <https://docs.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/user-rights-assignment>.

| Original                                  | Mapped                                                                                 | Description                                                         |
| ----------------------------------------- | -------------------------------------------------------------------------------------- | ------------------------------------------------------------------- |
| SeTrustedCredManAccessPrivilege           | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_TRUSTED\_CRED\_MAN\_ACCESS\_PRIVILEGE           | Access Credential Manager as a trusted caller.                      |
| SeNetworkLogonRight                       | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_NETWORK\_LOGON\_RIGHT                           | Access this computer from the network.                              |
| SeTcbPrivilege                            | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_TCB\_PRIVILEGE                                  | Act as part of the operating system.                                |
| SeMachineAccountPrivilege                 | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_MACHINE\_ACCOUNT\_PRIVILEGE                     | Add workstations to domain.                                         |
| SeIncreaseQuotaPrivilege                  | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_INCREASE\_QUOTA\_PRIVILEGE                      | Adjust memory quotas for a process.                                 |
| SeInteractiveLogonRight                   | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_INTERACTIVE\_LOGON\_RIGHT                       | Allow log on locally.                                               |
| SeRemoteInteractiveLogonRight             | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_REMOTE\_INTERACTIVE\_LOGON\_RIGHT               | Allow log on through Remote Desktop Services.                       |
| SeBackupPrivilege                         | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_BACKUP\_PRIVILEGE                               | Back up files and directories.                                      |
| SeChangeNotifyPrivilege                   | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_CHANGE\_NOTIFY\_PRIVILEGE                       | Bypass traverse checking.                                           |
| SeSystemtimePrivilege                     | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_SYSTEMTIME\_PRIVILEGE                           | Change the system time.                                             |
| SeTimeZonePrivilege                       | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_TIME\_ZONE\_PRIVILEGE                           | Change the time zone.                                               |
| SeCreatePagefilePrivilege                 | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_CREATE\_PAGEFILE\_PRIVILEGE                     | Create a pagefile.                                                  |
| SeCreateTokenPrivilege                    | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_CREATE\_TOKEN\_PRIVILEGE                        | Create a token object.                                              |
| SeCreateGlobalPrivilege                   | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_CREATE\_GLOBAL\_PRIVILEGE                       | Create global objects.                                              |
| SeCreatePermanentPrivilege                | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_CREATE\_PERMANENT\_PRIVILEGE                    | Create permanent shared objects.                                    |
| SeCreateSymbolicLinkPrivilege             | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_CREATE\_SYMBOLIC\_LINK\_PRIVILEGE               | Create symbolic links.                                              |
| SeDebugPrivilege                          | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_DEBUG\_PRIVILEGE                                | Debug programs.                                                     |
| SeDenyNetworkLogonRight                   | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_DENY\_NETWORK\_LOGON\_RIGHT                     | Deny access to this computer from the network.                      |
| SeDenyBatchLogonRight                     | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_DENY\_BATCH\_LOGON\_RIGHT                       | Deny log on as a batch job.                                         |
| SeDenyServiceLogonRight                   | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_DENY\_SERVICE\_LOGON\_RIGHT                     | Deny log on as a service.                                           |
| SeDenyInteractiveLogonRight               | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_DENY\_INTERACTIVE\_LOGON\_RIGHT                 | Deny log on locally.                                                |
| SeDenyRemoteInteractiveLogonRight         | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_DENY\_REMOTE\_INTERACTIVE\_LOGON\_RIGHT         | Deny log on through Remote Desktop Services.                        |
| SeEnableDelegationPrivilege               | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_ENABLE\_DELEGATION\_PRIVILEGE                   | Enable computer and user accounts to be trusted for delegation.     |
| SeRemoteShutdownPrivilege                 | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_REMOTE\_SHUTDOWN\_PRIVILEGE                     | Force shutdown from a remote system.                                |
| SeAuditPrivilege                          | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_AUDIT\_PRIVILEGE                                | Generate security audits.                                           |
| SeImpersonatePrivilege                    | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_IMPERSONATE\_PRIVILEGE                          | Impersonate a client after authentication.                          |
| SeIncreaseWorkingSetPrivilege             | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_INCREASE\_WORKING\_SET\_PRIVILEGE               | Increase a process working set.                                     |
| SeIncreaseBasePriorityPrivilege           | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_INCREASE\_BASE\_PRIORITY\_PRIVILEGE             | Increase scheduling priority.                                       |
| SeLoadDriverPrivilege                     | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_LOAD\_DRIVER\_PRIVILEGE                         | Load and unload device drivers.                                     |
| SeLockMemoryPrivilege                     | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_LOCK\_MEMORY\_PRIVILEGE                         | Lock pages in memory.                                               |
| SeBatchLogonRight                         | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_BATCH\_LOGON\_RIGHT                             | Log on as a batch job.                                              |
| SeServiceLogonRight                       | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_SERVICE\_LOGON\_RIGHT                           | Log on as a service.                                                |
| SeSecurityPrivilege                       | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_SECURITY\_PRIVILEGE                             | Manage auditing and security log.                                   |
| SeRelabelPrivilege                        | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_RELABEL\_PRIVILEGE                              | Modify an object label.                                             |
| SeSystemEnvironmentPrivilege              | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_SYSTEM\_ENVIRONMENT\_PRIVILEGE                  | Modify firmware environment values.                                 |
| SeDelegateSessionUserImpersonatePrivilege | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_DELEGATE\_SESSION\_USER\_IMPERSONATE\_PRIVILEGE | Obtain an impersonation token for another user in the same session. |
| SeManageVolumePrivilege                   | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_MANAGE\_VOLUME\_PRIVILEGE                       | Perform volume maintenance tasks.                                   |
| SeProfileSingleProcessPrivilege           | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_PROFILE\_SINGLE\_PROCESS\_PRIVILEGE             | Profile single process.                                             |
| SeSystemProfilePrivilege                  | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_SYSTEM\_PROFILE\_PRIVILEGE                      | Profile system performance.                                         |
| SeUndockPrivilege                         | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_UNDOCK\_PRIVILEGE                               | Remove computer from docking station.                               |
| SeAssignPrimaryTokenPrivilege             | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_ASSIGN\_PRIMARY\_TOKEN\_PRIVILEGE               | Replace a process level token.                                      |
| SeRestorePrivilege                        | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_RESTORE\_PRIVILEGE                              | Restore files and directories.                                      |
| SeShutdownPrivilege                       | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_SHUTDOWN\_PRIVILEGE                             | Shut down the system                                                |
| SeSyncAgentPrivilege                      | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_SYNC\_AGENT\_PRIVILEGE                          | Synchronize directory service data.                                 |
| SeTakeOwnershipPrivilege                  | XDM\_CONST.LOGON\_ASSIGNED\_RIGHT\_SE\_TAKE\_OWNERSHIP\_PRIVILEGE                      | Take ownership of files or other objects.                           |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/xsiam-data-model-schema/consts/logon-assigned-right.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
