1, in the Win8.1 start screen or the traditional desktop, using the "windows+r" shortcut keys, open the WIN8 System Run dialog box, enter the "gpedit.msc" command and return, pop-up System Group Policy Edit dialog box, positioning the mouse to "Computer Configuration" → "Windows settings" → security settings → Local policies → audit policy node, double-click Audit Policy Changes Group Policy under the target node.
2, in the pop-up Edit dialog box to check the "success", "failure" option, and then press the "OK" button.
3, according to the same method of "audit process tracking" → "Audit login events" and other Group Policy, do the same set operation. In the future, the Win8.1 system will be able to monitor all the login behavior of the hidden accounts, and then open "Event Viewer" from the Computer Management window to get an accurate knowledge of the name of the system's hidden account and even the time to log on to the system.
After discovering this kind of hidden account, although cannot delete it directly, but can pass the "net user aaaa bbbb" command (in which "AAAA" is the hidden account name, "BBBB" for the new login password), adjusts the hidden account the login password, lets the hidden account not log in normally.