User Rights Assignment settings on a Windows Endpoint.
Fields
| Field Name | Description |
|---|---|
seTrustedCredManAccessPrivilege - [String!]
|
Access Credential Manager as a trusted caller. |
seNetworkLogonRight - [String!]
|
Access this computer from the network. |
seTcbPrivilege - [String!]
|
Act as part of the operating system. |
seMachineAccountPrivilege - [String!]
|
Add workstations to domain. |
seIncreaseQuotaPrivilege - [String!]
|
Adjust memory quotas for a process. |
seInteractiveLogonRight - [String!]
|
Allow log on locally. |
seRemoteInteractiveLogonRight - [String!]
|
Allow log on through Remote Desktop Services. |
seBackupPrivilege - [String!]
|
Back up files and directories. |
seChangeNotifyPrivilege - [String!]
|
Bypass traverse checking. |
seSystemtimePrivilege - [String!]
|
Change the system time. |
seTimeZonePrivilege - [String!]
|
Change the time zone. |
seCreatePagefilePrivilege - [String!]
|
Create a pagefile. |
seCreateTokenPrivilege - [String!]
|
Create a token object. |
seCreateGlobalPrivilege - [String!]
|
Create global objects. |
seCreatePermanentPrivilege - [String!]
|
Create permanent shared objects. |
seCreateSymbolicLinkPrivilege - [String!]
|
Create symbolic links. |
seDebugPrivilege - [String!]
|
Debug programs. |
seDenyNetworkLogonRight - [String!]
|
Deny access to this computer from the network. |
seDenyBatchLogonRight - [String!]
|
Deny log on as a batch job. |
seDenyServiceLogonRight - [String!]
|
Deny log on as a service. |
seDenyInteractiveLogonRight - [String!]
|
Deny log on locally. |
seDenyRemoteInteractiveLogonRight - [String!]
|
Deny log on through Remote Desktop Services. |
seEnableDelegationPrivilege - [String!]
|
Enable computer and user accounts to be trusted for delegation. |
seRemoteShutdownPrivilege - [String!]
|
Force shutdown from a remote system. |
seAuditPrivilege - [String!]
|
Generate security audits. |
seImpersonatePrivilege - [String!]
|
Impersonate a client after authentication. |
seIncreaseWorkingSetPrivilege - [String!]
|
Increase a process working set. |
seIncreaseBasePriorityPrivilege - [String!]
|
Increase scheduling priority. |
seLoadDriverPrivilege - [String!]
|
Load and unload device drivers. |
seLockMemoryPrivilege - [String!]
|
Lock pages in memory. |
seBatchLogonRight - [String!]
|
Log on as a batch job. |
seServiceLogonRight - [String!]
|
Log on as a service. |
seSecurityPrivilege - [String!]
|
Manage auditing and security log. |
seRelabelPrivilege - [String!]
|
Modify an object label. |
seSystemEnvironmentPrivilege - [String!]
|
Modify firmware environment values. |
seDelegateSessionUserImpersonatePrivilege - [String!]
|
Obtain an impersonation token for another user in the same session. |
seManageVolumePrivilege - [String!]
|
Perform volume maintenance tasks. |
seProfileSingleProcessPrivilege - [String!]
|
Profile single process. |
seSystemProfilePrivilege - [String!]
|
Profile system performance. |
seUndockPrivilege - [String!]
|
Remove computer from docking station. |
seAssignPrimaryTokenPrivilege - [String!]
|
Replace a process level token. |
seRestorePrivilege - [String!]
|
Restore files and directories. |
seShutdownPrivilege - [String!]
|
Shut down the system. |
seSyncAgentPrivilege - [String!]
|
Synchronize directory service data. |
seTakeOwnershipPrivilege - [String!]
|
Take ownership of files or other objects. |
Used by
LocalPoliciesWindowstype: Windows-specific local security and system policies.
Example
Example
{
"seTrustedCredManAccessPrivilege": [
"xyz789"
],
"seNetworkLogonRight": ["xyz789"],
"seTcbPrivilege": ["abc123"],
"seMachineAccountPrivilege": ["abc123"],
"seIncreaseQuotaPrivilege": ["abc123"],
"seInteractiveLogonRight": ["abc123"],
"seRemoteInteractiveLogonRight": [
"abc123"
],
"seBackupPrivilege": ["xyz789"],
"seChangeNotifyPrivilege": ["xyz789"],
"seSystemtimePrivilege": ["xyz789"],
"seTimeZonePrivilege": ["abc123"],
"seCreatePagefilePrivilege": ["xyz789"],
"seCreateTokenPrivilege": ["xyz789"],
"seCreateGlobalPrivilege": ["xyz789"],
"seCreatePermanentPrivilege": ["xyz789"],
"seCreateSymbolicLinkPrivilege": [
"xyz789"
],
"seDebugPrivilege": ["xyz789"],
"seDenyNetworkLogonRight": ["xyz789"],
"seDenyBatchLogonRight": ["xyz789"],
"seDenyServiceLogonRight": ["abc123"],
"seDenyInteractiveLogonRight": ["abc123"],
"seDenyRemoteInteractiveLogonRight": [
"xyz789"
],
"seEnableDelegationPrivilege": ["xyz789"],
"seRemoteShutdownPrivilege": ["xyz789"],
"seAuditPrivilege": ["xyz789"],
"seImpersonatePrivilege": ["xyz789"],
"seIncreaseWorkingSetPrivilege": [
"xyz789"
],
"seIncreaseBasePriorityPrivilege": [
"abc123"
],
"seLoadDriverPrivilege": ["xyz789"],
"seLockMemoryPrivilege": ["abc123"],
"seBatchLogonRight": ["abc123"],
"seServiceLogonRight": ["abc123"],
"seSecurityPrivilege": ["xyz789"],
"seRelabelPrivilege": ["xyz789"],
"seSystemEnvironmentPrivilege": [
"xyz789"
],
"seDelegateSessionUserImpersonatePrivilege": [
"abc123"
],
"seManageVolumePrivilege": ["xyz789"],
"seProfileSingleProcessPrivilege": [
"abc123"
],
"seSystemProfilePrivilege": ["xyz789"],
"seUndockPrivilege": ["abc123"],
"seAssignPrimaryTokenPrivilege": [
"abc123"
],
"seRestorePrivilege": ["abc123"],
"seShutdownPrivilege": ["abc123"],
"seSyncAgentPrivilege": ["abc123"],
"seTakeOwnershipPrivilege": ["xyz789"]
}