Event Details
Operating System->Microsoft Windows->Built-in logs->Windows 2000-2003->Security Log->Policy Change->EventID 622 - System Security Access Removed [Win 2003 / XP]
EventID 622 - System Security Access Removed [Win 2003 / XP]
This event record indicates that logon rights (such as "Access this computer from the network" or "Logon as a service") were removed from a user account.

Find more information about this event on ultimatewindowssecurity.com.

Corresponding events on other OS versions:
Windows 2008
Related events:
This event and EventID 621 log assignments of logon rights only, such as "Access this computer from the network" or "Logon as a service" - not other rights such as "Change the system time" or "Take ownership of files and other objects". For other rights assignments/removals see the following events:
     Sample:
    Event Type:     Success Audit
    Event Source:   Security
    Event Category: Policy Change
    Event ID:       622
    Date:           10/26/2009
    Time:           07:41:24
    User:           RESEARCH\ALebovsky
    Computer:       DC1
    Description:    
    System Security Access Removed:
    	Access Removed:	SeServiceLogonRight
    	Account Modified:	%{S-1-5-21-184992632-1607737289-1287950321-1185}
    	Removed By:
    	  User Name:	Alebovsky
    	  Domain:		RESEARCH
    	  Logon ID:	(0x0,0x59DF36)
    
    Log Type: Windows Event Log
     Uniquely Identified By:
    Log Name: Security
    Filtering Field Equals to Value
    OSVersion Windows 2003
    Windows XP
    Category Policy Change
    Source Security
    EventId 622
    Field Matching
    FieldDescriptionStored inSample Value
    DateTime Date/Time of event origination in GMT format. DateTime 10.10.2000 19:00:00
    Source Name of an Application or System Service originating the event. Source Security
    Type Warning, Information, Error, Success, Failure, etc. Type Success
    User Domain\Account name of user/service/computer initiating event. User RESEARCH\Alebovsky
    Computer Name of server workstation where event was logged. Computer DC1
    EventID Numerical ID of event. Unique within one Event Source. EventId 576
    Description The entire unparsed event message. Description Special privileges assigned to new logon.
    Log Name The name of the event log (e.g. Application, Security, System, etc.) LogName Security
    Category A name for a subclass of events within the same Event Source. Category Logon/Logoff
    Access Removed System name of the logon right revoked. Please see logon right descriptions here. InsertionString4
    Account Modified The user or group from who the right was revoked, prefixed by domain name InsertionString5 %{S-1-5-21-184992632-1607737289-1287950321-1185}
    User Name The user who removed the right. Normally the computer name where the right was removed. InsertionString1 Alebovsky
    Domain Domain of the user who removed the right InsertionString2 RESEARCH
    Logon ID ID of the logon session of the user who removed the right. Useful for tracking other user activity during the same logon session. InsertionString3 (0x0,0x59DF36)
    Comments
    You must be logged in to comment