Unauthorized accounts will not be granted the "Act as part of the operating system" user right.

From Windows Server 2008 R2 Member Server Security Technical Implementation Guide

Part of User Right - Act as part of OS

Associated with IA controls: ECLP-1

SV-32287r1_rule Unauthorized accounts will not be granted the "Act as part of the operating system" user right.

Vulnerability discussion

Inappropriate granting of user rights can provide system, administrative, and other high level capabilities.This is a Category 1 finding as accounts with this right can bypass all security protective mechanisms that apply to all users, including administrators. Accounts with this right should have passwords with the maximum length and be kept in a locked container accessible only by the IAO and his designated backup. Some applications require this right to function. Any exception needs to be documented with the IAO.

Check content

Fix text

Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> User Rights Assignment -> "Act as part of the operating system" as defined in the Check section.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer