Configure User Rights Assignments for Domain Controllers
Target Scope
- Applicable Systems: Domain Controllers (DCs)
- Operating Systems: Windows Server 2016 and above
Implementation Details
- Priority: High
- GPO Path / Registry Location:
- GPO Path:
Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment - Registry Location: Stored inside local security database under privilege definitions.
- GPO Path:
Rationale
User Rights Assignments on Domain Controllers represent a primary defense boundary to secure Active Directory directory services (Tier 0). Restricting who can perform raw volume access, time adjustments, or credential delegations prevents local privilege hijacking.
This submodule contains individual requirement rules for each User Rights Assignment control enforced on Domain Controllers.
Legacy Impact & Compatibility
- Operational Impact: Restricting privileges on Domain Controllers impacts replication, system tasks, or third-party AD monitoring agents. Thoroughly validate service accounts before deploying constraints.
Enforced User Rights Assignments on Domain Controllers
The following individual URA rules must be configured:
- REQ-DC-104 - Configure User Rights: Access this computer from the network on Domain Controllers
- REQ-DC-105 - Configure User Rights: Act as part of the operating system on Domain Controllers
- REQ-DC-106 - Configure User Rights: Add workstations to domain on Domain Controllers
- REQ-DC-107 - Configure User Rights: Adjust memory quotas for a process on Domain Controllers
- REQ-DC-108 - Configure User Rights: Allow log on locally on Domain Controllers
- REQ-DC-109 - Configure User Rights: Allow log on through Remote Desktop Services on Domain Controllers
- REQ-DC-110 - Configure User Rights: Back up files and directories on Domain Controllers
- REQ-DC-111 - Configure User Rights: Bypass traverse checking on Domain Controllers
- REQ-DC-112 - Configure User Rights: Change the system time on Domain Controllers
- REQ-DC-113 - Configure User Rights: Create a pagefile on Domain Controllers
- REQ-DC-114 - Configure User Rights: Create a token object on Domain Controllers
- REQ-DC-115 - Configure User Rights: Create permanent shared objects on Domain Controllers
- REQ-DC-116 - Configure User Rights: Debug programs on Domain Controllers
- REQ-DC-117 - Configure User Rights: Deny access to this computer from the network on Domain Controllers
- REQ-DC-118 - Configure User Rights: Deny log on as a batch job on Domain Controllers
- REQ-DC-119 - Configure User Rights: Deny log on as a service on Domain Controllers
- REQ-DC-120 - Configure User Rights: Deny log on locally on Domain Controllers
- REQ-DC-121 - Configure User Rights: Deny log on through Remote Desktop Services on Domain Controllers
- REQ-DC-122 - Configure User Rights: Enable computer and user accounts to be trusted for delegation on Domain Controllers
- REQ-DC-123 - Configure User Rights: Force shutdown from a remote system on Domain Controllers
- REQ-DC-124 - Configure User Rights: Generate security audits on Domain Controllers
- REQ-DC-125 - Configure User Rights: Load and unload device drivers on Domain Controllers
- REQ-DC-126 - Configure User Rights: Lock pages in memory on Domain Controllers
- REQ-DC-127 - Configure User Rights: Log on as a batch job on Domain Controllers
- REQ-DC-128 - Configure User Rights: Log on as a service on Domain Controllers
- REQ-DC-129 - Configure User Rights: Manage auditing and security log on Domain Controllers
- REQ-DC-130 - Configure User Rights: Modify firmware environment values on Domain Controllers
- REQ-DC-131 - Configure User Rights: Profile single process on Domain Controllers
- REQ-DC-132 - Configure User Rights: Restore files and directories on Domain Controllers
- REQ-DC-133 - Configure User Rights: Shut down the system on Domain Controllers
- REQ-DC-134 - Configure User Rights: Synchronize directory service data on Domain Controllers
- REQ-DC-135 - Configure User Rights: Take ownership of files or other objects on Domain Controllers
Sources & Compliance References
- ANSSI Active Directory Hardening Guide: Protective controls baselines on Domain Controllers
- Microsoft Security Baseline: User Rights Configuration specifications