Configure User Rights Assignments for PAWs
Target Scope
- Applicable Systems: Privileged Access Workstations (PAWs) used for Tier 0 directory administration.
- Operating Systems: Windows 10 Enterprise (1607+) and Windows 11 Enterprise.
Implementation Details
- Priority: High
- GPO Path / Registry Location:
- GPO Path:
Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment - Registry Location: Stored inside local security database under privilege definitions.
- GPO Path:
Rationale
Enforcing strict User Rights Assignments (URAs) on PAWs limits the execution footprint of administrative helper binaries, service accounts, and logon permissions to minimize the privilege footprint and prevent administrative impersonation.
This submodule contains individual requirement rules for each User Rights Assignment control enforced on PAWs.
Legacy Impact & Compatibility
- Maximum Console Isolation: Standard domain users and non-administrative services have no permission assignments on PAW consoles. Operational impact should be non-existent because PAWs are restricted to pure administrative functions.
Enforced User Rights Assignments on PAWs
The following individual URA rules must be configured:
- REQ-PAW-092 - Configure User Rights: Access Credential Manager as a trusted caller for PAWs
- REQ-PAW-093 - Configure User Rights: Access this computer from the network for PAWs
- REQ-PAW-094 - Configure User Rights: Act as part of the operating system for PAWs
- REQ-PAW-095 - Configure User Rights: Allow log on locally for PAWs
- REQ-PAW-096 - Configure User Rights: Back up files and directories for PAWs
- REQ-PAW-097 - Configure User Rights: Create a pagefile for PAWs
- REQ-PAW-098 - Configure User Rights: Create a token object for PAWs
- REQ-PAW-099 - Configure User Rights: Create global objects for PAWs
- REQ-PAW-100 - Configure User Rights: Create permanent shared objects for PAWs
- REQ-PAW-101 - Configure User Rights: Debug programs for PAWs
- REQ-PAW-102 - Configure User Rights: Enable computer and user accounts to be trusted for delegation for PAWs
- REQ-PAW-103 - Configure User Rights: Force shutdown from a remote system for PAWs
- REQ-PAW-104 - Configure User Rights: Impersonate a client after authentication for PAWs
- REQ-PAW-105 - Configure User Rights: Load and unload device drivers for PAWs
- REQ-PAW-106 - Configure User Rights: Lock pages in memory for PAWs
- REQ-PAW-107 - Configure User Rights: Manage auditing and security log for PAWs
- REQ-PAW-108 - Configure User Rights: Modify firmware environment values for PAWs
- REQ-PAW-109 - Configure User Rights: Perform volume maintenance tasks for PAWs
- REQ-PAW-110 - Configure User Rights: Profile single process for PAWs
- REQ-PAW-111 - Configure User Rights: Restore files and directories for PAWs
- REQ-PAW-112 - Configure User Rights: Take ownership of files or other objects for PAWs
- REQ-PAW-113 - Configure User Rights: Deny access to this computer from the network for PAWs
- REQ-PAW-114 - Configure User Rights: Deny log on through Remote Desktop Services for PAWs
Sources & Compliance References
- ANSSI Active Directory Hardening Guide: Protective controls baselines on Privileged Access Workstations
- Microsoft Security Baseline: User Rights Configuration specifications