19.06.2014 Views

Windows Server 2003 Recommended Baseline Security

Windows Server 2003 Recommended Baseline Security

Windows Server 2003 Recommended Baseline Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Unclassified ITSG for <strong>Windows</strong> <strong>Server</strong> <strong>2003</strong><br />

4.4.2.2 Act as part of the operating system<br />

setcbprivilege =<br />

The ‘setcbprivilege’ grants an account the ability to act as part of the operating system.<br />

According to Microsoft, there is no reason why an account would require this privilege.<br />

4.4.2.3 Add workstations to domain<br />

semachineaccountprivilege =<br />

The ‘semachineaccountprivilege’ grants the right to add workstations to a domain. This policy<br />

grants no privilege. Restricting this privilege helps maintain Domain integrity.<br />

4.4.2.4 Adjust memory quotas for a process<br />

seincreasequotaprivilege = *S-1-5-32-544,*S-1-5-19,*S-1-5-20<br />

The ‘seincreasequotaprivilege’ grants the ability to adjust memory quotas for a process. This<br />

policy grants privileges to Administrators, LOCAL SERVICE and NETWORK SERVICE<br />

accounts. If misused, DoS attacks are possible.<br />

4.4.2.5 Allow log on locally<br />

seinteractivelogonright = *S-1-5-32-551,*S-1-5-32-544<br />

The ‘seinteractivelogonright’ grants logon privilege to the local console. These privileges are<br />

given to Administrators and Backup operators. Local access is restricted to accounts that have<br />

legitimate reason for access. By restricting this privilege, system exposure is reduced.<br />

4.4.2.6 Allow log on through Terminal Services<br />

seremoteinteractivelogonright = *S-1-5-32-544<br />

The ‘seremoteinteractivelogonright’ grants the right to logon remotely through Terminal<br />

Services. This policy grants rights to Administrators. There is no requirement to allow users this<br />

form of access.<br />

4.4.2.7 Backup files and directories<br />

sebackupprivilege = *S-1-5-32-551,*S-1-5-32-544<br />

The ‘sebackupprivilege’ grants the right to backup files and directories. Rights are given to<br />

Administrators and Backup Operators. If your policy does not allow administrators to backup<br />

then omit the Administrators group. The allocation of this privilege must be tightly controlled.<br />

50 March 2004 <strong>Server</strong> Policy Files

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!