UCF STIG Viewer Logo

Active Directory data files must have proper access control permissions.


Overview

Finding ID Version Rule ID IA Controls Severity
V-8316 DS00.0120_2008_R2 SV-38994r2_rule High
Description
Improper access permissions for directory data related files could allow unauthorized users to read, modify, or delete directory data or audit trails.
STIG Date
Windows Server 2008 R2 Domain Controller Security Technical Implementation Guide 2016-07-22

Details

Check Text ( None )
None
Fix Text (F-45040r1_fix)
Ensure the permissions on NTDS database and log files are maintained as follows.
NT AUTHORITY\SYSTEM:(I)(F)
BUILTIN\Administrators:(I)(F)

(I) - permission inherited from parent container
(F) - full access