Configure User Rights Assignments for PAWs

Target Scope

  • Applicable Systems: Privileged Access Workstations (PAWs) used for Tier 0 directory administration.
  • Operating Systems: Windows 10 Enterprise (1607+) and Windows 11 Enterprise.

Implementation Details

  • Priority: High
  • GPO Path / Registry Location:
    • GPO Path: Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment
    • Registry Location: Stored inside local security database under privilege definitions.

Rationale

Enforcing strict User Rights Assignments (URAs) on PAWs limits the execution footprint of administrative helper binaries, service accounts, and logon permissions to minimize the privilege footprint and prevent administrative impersonation.

This submodule contains individual requirement rules for each User Rights Assignment control enforced on PAWs.


Legacy Impact & Compatibility

  • Maximum Console Isolation: Standard domain users and non-administrative services have no permission assignments on PAW consoles. Operational impact should be non-existent because PAWs are restricted to pure administrative functions.

Enforced User Rights Assignments on PAWs

The following individual URA rules must be configured:

  1. REQ-PAW-092 - Configure User Rights: Access Credential Manager as a trusted caller for PAWs
  2. REQ-PAW-093 - Configure User Rights: Access this computer from the network for PAWs
  3. REQ-PAW-094 - Configure User Rights: Act as part of the operating system for PAWs
  4. REQ-PAW-095 - Configure User Rights: Allow log on locally for PAWs
  5. REQ-PAW-096 - Configure User Rights: Back up files and directories for PAWs
  6. REQ-PAW-097 - Configure User Rights: Create a pagefile for PAWs
  7. REQ-PAW-098 - Configure User Rights: Create a token object for PAWs
  8. REQ-PAW-099 - Configure User Rights: Create global objects for PAWs
  9. REQ-PAW-100 - Configure User Rights: Create permanent shared objects for PAWs
  10. REQ-PAW-101 - Configure User Rights: Debug programs for PAWs
  11. REQ-PAW-102 - Configure User Rights: Enable computer and user accounts to be trusted for delegation for PAWs
  12. REQ-PAW-103 - Configure User Rights: Force shutdown from a remote system for PAWs
  13. REQ-PAW-104 - Configure User Rights: Impersonate a client after authentication for PAWs
  14. REQ-PAW-105 - Configure User Rights: Load and unload device drivers for PAWs
  15. REQ-PAW-106 - Configure User Rights: Lock pages in memory for PAWs
  16. REQ-PAW-107 - Configure User Rights: Manage auditing and security log for PAWs
  17. REQ-PAW-108 - Configure User Rights: Modify firmware environment values for PAWs
  18. REQ-PAW-109 - Configure User Rights: Perform volume maintenance tasks for PAWs
  19. REQ-PAW-110 - Configure User Rights: Profile single process for PAWs
  20. REQ-PAW-111 - Configure User Rights: Restore files and directories for PAWs
  21. REQ-PAW-112 - Configure User Rights: Take ownership of files or other objects for PAWs
  22. REQ-PAW-113 - Configure User Rights: Deny access to this computer from the network for PAWs
  23. REQ-PAW-114 - Configure User Rights: Deny log on through Remote Desktop Services for PAWs

Sources & Compliance References

  • ANSSI Active Directory Hardening Guide: Protective controls baselines on Privileged Access Workstations
  • Microsoft Security Baseline: User Rights Configuration specifications

results matching ""

    No results matching ""