Configure User Rights Assignments

Target Scope

  • Applicable Systems: Member Servers, Tier 2 Clients (Windows 10/11)
  • Operating Systems: Windows Server 2016 (and above), Windows 10/11 Enterprise/Professional

Implementation Details

  • Priority: High
  • GPO Path / Registry Location:
    • GPO Path: Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment
    • Registry Location: Stored inside local security database under privilege definitions.

Rationale

User Rights Assignments (URAs) govern the specific actions that security principals (users, groups, and service accounts) can perform on a system. Insecure default URA mappings can be abused by attackers to elevate privileges, compromise credentials, or establish persistence.

This submodule contains individual requirement rules for each User Rights Assignment control enforced on standard workstations.


Legacy Impact & Compatibility

  • Operational Impact: Restricting privileges restricts custom services or applications that depend on local execution rights. Validate all applications in audit staging environments before implementing block rules.

Enforced User Rights Assignments

The following individual URA rules must be configured:

  1. REQ-END-096 - Configure User Rights: Access Credential Manager as a trusted caller
  2. REQ-END-097 - Configure User Rights: Access this computer from the network
  3. REQ-END-098 - Configure User Rights: Act as part of the operating system
  4. REQ-END-099 - Configure User Rights: Allow log on locally
  5. REQ-END-100 - Configure User Rights: Back up files and directories
  6. REQ-END-101 - Configure User Rights: Change the system time
  7. REQ-END-102 - Configure User Rights: Change the time zone
  8. REQ-END-103 - Configure User Rights: Create a pagefile
  9. REQ-END-104 - Configure User Rights: Create a token object
  10. REQ-END-105 - Configure User Rights: Create global objects
  11. REQ-END-106 - Configure User Rights: Create permanent shared objects
  12. REQ-END-107 - Configure User Rights: Create symbolic links
  13. REQ-END-108 - Configure User Rights: Debug programs
  14. REQ-END-109 - Configure User Rights: Enable computer and user accounts to be trusted for delegation
  15. REQ-END-110 - Configure User Rights: Force shutdown from a remote system
  16. REQ-END-111 - Configure User Rights: Impersonate a client after authentication
  17. REQ-END-112 - Configure User Rights: Increase scheduling priority
  18. REQ-END-113 - Configure User Rights: Load and unload device drivers
  19. REQ-END-114 - Configure User Rights: Lock pages in memory
  20. REQ-END-115 - Configure User Rights: Manage auditing and security log
  21. REQ-END-116 - Configure User Rights: Modify firmware environment values
  22. REQ-END-117 - Configure User Rights: Perform volume maintenance tasks
  23. REQ-END-118 - Configure User Rights: Profile single process
  24. REQ-END-119 - Configure User Rights: Profile system performance
  25. REQ-END-120 - Configure User Rights: Replace a process level token
  26. REQ-END-121 - Configure User Rights: Restore files and directories
  27. REQ-END-122 - Configure User Rights: Take ownership of files or other objects
  28. REQ-END-123 - Configure User Rights: Modify an object label
  29. REQ-END-124 - Configure User Rights: Deny access to this computer from the network
  30. REQ-END-125 - Configure User Rights: Deny log on through Remote Desktop Services

Sources & Compliance References

  • ANSSI Active Directory Hardening Guide: User Rights Assignment protective controls
  • Microsoft Security Baseline: User Rights Configuration specifications

results matching ""

    No results matching ""