Configure User Rights Assignments
Target Scope
- Applicable Systems: Member Servers, Tier 2 Clients (Windows 10/11)
- Operating Systems: Windows Server 2016 (and above), Windows 10/11 Enterprise/Professional
Implementation Details
- Priority: High
- GPO Path / Registry Location:
- GPO Path:
Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment - Registry Location: Stored inside local security database under privilege definitions.
- GPO Path:
Rationale
User Rights Assignments (URAs) govern the specific actions that security principals (users, groups, and service accounts) can perform on a system. Insecure default URA mappings can be abused by attackers to elevate privileges, compromise credentials, or establish persistence.
This submodule contains individual requirement rules for each User Rights Assignment control enforced on standard workstations.
Legacy Impact & Compatibility
- Operational Impact: Restricting privileges restricts custom services or applications that depend on local execution rights. Validate all applications in audit staging environments before implementing block rules.
Enforced User Rights Assignments
The following individual URA rules must be configured:
- REQ-END-096 - Configure User Rights: Access Credential Manager as a trusted caller
- REQ-END-097 - Configure User Rights: Access this computer from the network
- REQ-END-098 - Configure User Rights: Act as part of the operating system
- REQ-END-099 - Configure User Rights: Allow log on locally
- REQ-END-100 - Configure User Rights: Back up files and directories
- REQ-END-101 - Configure User Rights: Change the system time
- REQ-END-102 - Configure User Rights: Change the time zone
- REQ-END-103 - Configure User Rights: Create a pagefile
- REQ-END-104 - Configure User Rights: Create a token object
- REQ-END-105 - Configure User Rights: Create global objects
- REQ-END-106 - Configure User Rights: Create permanent shared objects
- REQ-END-107 - Configure User Rights: Create symbolic links
- REQ-END-108 - Configure User Rights: Debug programs
- REQ-END-109 - Configure User Rights: Enable computer and user accounts to be trusted for delegation
- REQ-END-110 - Configure User Rights: Force shutdown from a remote system
- REQ-END-111 - Configure User Rights: Impersonate a client after authentication
- REQ-END-112 - Configure User Rights: Increase scheduling priority
- REQ-END-113 - Configure User Rights: Load and unload device drivers
- REQ-END-114 - Configure User Rights: Lock pages in memory
- REQ-END-115 - Configure User Rights: Manage auditing and security log
- REQ-END-116 - Configure User Rights: Modify firmware environment values
- REQ-END-117 - Configure User Rights: Perform volume maintenance tasks
- REQ-END-118 - Configure User Rights: Profile single process
- REQ-END-119 - Configure User Rights: Profile system performance
- REQ-END-120 - Configure User Rights: Replace a process level token
- REQ-END-121 - Configure User Rights: Restore files and directories
- REQ-END-122 - Configure User Rights: Take ownership of files or other objects
- REQ-END-123 - Configure User Rights: Modify an object label
- REQ-END-124 - Configure User Rights: Deny access to this computer from the network
- REQ-END-125 - Configure User Rights: Deny log on through Remote Desktop Services
Sources & Compliance References
- ANSSI Active Directory Hardening Guide: User Rights Assignment protective controls
- Microsoft Security Baseline: User Rights Configuration specifications