If you ran into an event in event log looks like this:
An operation was attempted on a privileged object.
Security ID: LOCAL SERVICE
Account Name: LOCAL SERVICE
Logon ID: 0x3b5
Object Type: -
Object Name: -
Process ID: 0x258
Process Name: C:WindowsSystem32lsass.exe
Event ID 4674 on a windows 2012 R2 server indicates that the login account had an interaction with one or more of the services on the computer.
To see the PID of the process, you can go to task manager < services and see the PID and name of the process. Operation you may check to make this event from occurring again: Get the audit configurations running the command line under CMD: auditpol.exe /get /category:* Check if audit policy is configured to audit Sensitive Privilege Use in your environment and disable.