(L1) Ensure ‘Debug programs’ is set to ‘Administrators’ Details This policy setting determines which user accounts will have the right to attach a debugger to any process or...
(L1) Ensure ‘Deny access to this computer from the network’ to include ‘Guests, Local account’ Details This policy setting prohibits users from connecting to a computer from across the network, which would allow users to...
(L1) Ensure ‘Deny log on as a batch job’ to include ‘Guests’ Details This policy setting determines which accounts will not be able to log on to the computer as a batch...
(L1) Ensure ‘Deny log on as a service’ to include ‘Guests’ Details This security setting determines which service accounts are prevented from registering a process as a service. This user right...
(L1) Ensure ‘Deny log on locally’ to include ‘Guests’ Details This security setting determines which users are prevented from logging on at the computer. This policy setting supersedes the...
(L1) Ensure ‘Deny log on through Remote Desktop Services’ to include ‘Guests, Local account’ Details This policy setting determines whether users can log on as Remote Desktop clients. After the baseline workstation is joined...
(L1) Ensure ‘Enable computer and user accounts to be trusted for delegation’ is set to ‘No One’ Details This policy setting allows users to change the Trusted for Delegation setting on a computer object in Active Directory....
(L1) Ensure ‘Increase scheduling priority’ is set to ‘Administrators, Window ManagerWindow Manager Group’ Details This policy setting determines whether users can increase the base priority class of a process. (It is not a...
(L1) Ensure ‘Load and unload device drivers’ is set to ‘Administrators’ Details This policy setting allows users to dynamically load a new device driver on a system. An attacker could potentially...
(L1) Ensure ‘Lock pages in memory’ is set to ‘No One’ Details This policy setting allows a process to keep data in physical memory, which prevents the system from paging the...