If you ran into an event in event log looks like this:

An operation was attempted on a privileged object.

Subject:
Security ID:  LOCAL SERVICE
Account Name:  LOCAL SERVICE
Account Domain:

NT AUTHORITY
Logon ID:  0x3b5
Object:
Object Server:LSA
Object Type:  -
Object Name:  -
Object Handle:

0x0
Process Information:
Process ID:  0x258
Process Name:  C:WindowsSystem32lsass.exe
Requested Operation:
Desired Access:1677745
Privileges:  SeSecurityPrivilege.

Event ID 4674 on a windows 2012 R2 server indicates that the login account had an interaction with one or more of the services on the computer.

To see the PID of the process, you can go to task manager < services and see the PID and name of the process. Operation you may check to make this event from occurring again: Get the audit configurations running the command line under CMD: auditpol.exe /get /category:* Check if audit policy is configured to audit Sensitive Privilege Use in your environment and disable.