Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-45589 | WINGE-000200 | SV-58415r2_rule | Low |
Description |
---|
Several user rights on domain systems require that local administrator accounts be assigned to them. This is separate from the built-in Administrators group, which also contains domain administrative accounts/groups. Defining a consistent group name allows compliance to be more easily determined. |
STIG | Date |
---|---|
Windows Vista Security Technical Implementation Guide | 2016-10-28 |
Check Text ( None ) |
---|
None |
Fix Text (F-62391r1_fix) |
---|
This requirement is NA for non domain-joined systems. Create a local group with the name "DenyNetworkAccess" or "DeniedNetworkAccess" on the system. Include all local administrator accounts as members of the group, including the built-in Administrator account. Do not include domain administrative accounts or groups. |