1. Home
  2. Security Hardening
  3. CIS Microsoft Windows 10 Enterprise Release 1909 V1.8.1 L1 Bl Ng
  4. Ensure ‘Access Credential Manager as a trusted caller’ is set to ‘No One’

Ensure ‘Access Credential Manager as a trusted caller’ is set to ‘No One’

Details

This security setting is used by Credential Manager during Backup and Restore. No accounts should have this user right, as it is only assigned to Winlogon. Users’ saved credentials might be compromised if this user right is assigned to other entities.

The recommended state for this setting is: No One.

Rationale:

If an account is given this right the user of the account may create an application that calls into Credential Manager and is returned the credentials for another user.

Solution

To establish the recommended configuration via GP, set the following UI path to No One:

Computer ConfigurationPoliciesWindows SettingsSecurity SettingsLocal PoliciesUser Rights AssignmentAccess Credential Manager as a trusted caller

Impact:

None – this is the default behavior.

Default Value:

No one.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Access Control.This control applies to the following type of system Windows.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles