During CPM (Credential Provider Manager) hardening, the locally created users that are granted Logon as a Service rights in the local group policy typically include PasswordManagerUser and CPMServiceAccount. These roles are crucial for managing the necessary operations and services that the CPM performs. PasswordManagerUser handles administrative tasks related to password management, while CPMServiceAccount is used by the CPM for performing its functions seamlessly.
In the Identity Administration Portal, you can review recent failed login events for all users. The Identity User Portal only allows individual users to view their own login activity, not that of all users.