Download Security Update 17 User`s Guide for Windows

Transcript
80 Modules
Account Integrity
Delegation is used by multi-tier client/server applications. An account with this
user right may be able to conduct sophisticated attacks to gain access to network
resources.
You can use the name lists in the check to exclude or include users or security
groups that are not already excluded or included by the Users to check option.
The check returns the following message:
Message name
Title
Type
Class
ENABLE_TRUSTED_
DELEGATION
Enable computer and user accounts to be
trusted for delegation
C
1
For steps to demonstrate the check, see “To demonstrate user rights checks” on
page 69.
To protect your computers
◆
Use the Correct feature to revoke this right from unauthorized users. This
right should be granted only to users and security groups that require it for
normal business functions.
Force shutdown from a remote system
This security check reports accounts with rights to shut down a computer that is
running Windows from a remote location on the network.
This standard right is given by default to Administrators on workstations and
servers and to Power Users on workstations.
You can use the name lists in the check to exclude or include users or security
groups that are not already excluded or included by the Users to check option.
The check returns the following message:
Message name
Title
Type
FORCE_REMOTE_ SHUTDOWN
Force shutdown from a remote C
system
Class
1
For steps to demonstrate the check, see “To demonstrate user rights checks” on
page 69.
To protect your computers
◆
Use the Correct feature to revoke this right from unauthorized users. The
right should not be granted to any user.