Ensure ‘Adjust memory quotas for a process’ is set to ‘Administrators, LOCAL SERVICE, NETWORK SERVICE’ Details This policy setting allows a user to adjust the maximum amount of memory that is available to a process....
Ensure ‘Allow log on locally’ is set to ‘Administrators, Users’ Details This policy setting determines which users can interactively log on to computers in your environment. Logons that are initiated...
Ensure ‘Allow log on through Remote Desktop Services’ is set to ‘Administrators, Remote Desktop Users’ Details This policy setting determines which users or groups have the right to log on as a Remote Desktop Services...
Ensure ‘Back up files and directories’ is set to ‘Administrators’ Details This policy setting allows users to circumvent file and directory permissions to back up the system. This user right...
Ensure ‘Change the system time’ is set to ‘Administrators, LOCAL SERVICE’ Details This policy setting determines which users and groups can change the time and date on the internal clock of...
Ensure ‘Change the time zone’ is set to ‘Administrators, LOCAL SERVICE, Users’ Details This setting determines which users can change the time zone of the computer. This ability holds no great danger...
Ensure ‘Create a pagefile’ is set to ‘Administrators’ Details This policy setting allows users to change the size of the pagefile. By making the pagefile extremely large or...
Ensure ‘Create a token object’ is set to ‘No One’ Details This policy setting allows a process to create an access token, which may provide elevated rights to access sensitive...
Ensure ‘Create global objects’ is set to ‘Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE’ Details This policy setting determines whether users can create global objects that are available to all sessions. Users can still...
Ensure ‘Create permanent shared objects’ is set to ‘No One’ Details This user right is useful to kernel-mode components that extend the object namespace. However, components that run in kernel...