---
title: CIS Windows 11 User Rights Assignment: 38 Checks | Wartiva
description: Wartiva's 38 checks for section 2.2, User Rights Assignment, of the CIS Microsoft Windows 11 Stand-alone Benchmark, with rationale and remediation.
url: https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html
updated: 2026-10-07
---

CIS Microsoft Windows 11 Stand-alone Benchmark · Section 2.2

# Windows 11 User Rights Assignment: 38 Checks

Wartiva runs 38 checks for section 2.2, User Rights Assignment, of the CIS Microsoft Windows 11 Stand-alone Benchmark. Each one lists what it finds, why it matters, and how to fix it.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. [How Wartiva works →](https://wartiva.com/platform.html)

## [Ensure 'Access Credential Manager as a trusted caller' Is Set To No One](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#access-credential-manager-as-a-trusted-caller-is-set-to-no-one)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Access Credential Manager as a trusted caller' is assigned to one or more accounts.

Checks which accounts hold the right used by Credential Manager during backup and restore.

This rule fails when `seTrustedCredManAccessPrivilege` is assigned to any account.

**Rationale:** Only Winlogon needs this right; granting it lets an account retrieve another user's saved credentials.

**Impact:** None; no account requires this right by default.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Access Credential Manager as a trusted caller'** to **No One**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Insecure Use of Secrets

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

## [Ensure 'Access this computer from the network' Is Set To 'Administrators, Remote Desktop Users'](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#access-this-computer-from-the-network-is-set-to-administrators-remote-desktop-us)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Access this computer from the network' is not restricted to Administrators, Remote Desktop Users.

Checks which accounts may connect to this computer over the network.

This rule fails when the accounts assigned to `seNetworkLogonRight` are not exactly Administrators, Remote Desktop Users.

**Rationale:** Accounts able to reach the machine over the network can access resources they are permitted to; the set should be limited to administrators and remote desktop users.

**Impact:** Only the listed groups can access the computer across the network.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Access this computer from the network'** to **Administrators, Remote Desktop Users**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Unprotected Principal

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## [Ensure 'Act as part of the operating system' Is Set To No One](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#act-as-part-of-the-operating-system-is-set-to-no-one)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Act as part of the operating system' is assigned to one or more accounts.

Checks which accounts may act as part of the operating system.

This rule fails when `seTcbPrivilege` is assigned to any account.

**Rationale:** This right lets a process assume any user identity and take complete control of the computer.

**Impact:** None; the right is rarely required by any legitimate account.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Act as part of the operating system'** to **No One**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Unprotected Principal

MITRE ATT&CK tactic

Privilege Escalation ([TA0004](https://attack.mitre.org/tactics/TA0004/))

## [Ensure 'Adjust memory quotas for a process' Is Set To 'Administrators, LOCAL SERVICE, NETWORK SERVICE'](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#adjust-memory-quotas-for-a-process-is-set-to-administrators-local-service-networ)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Adjust memory quotas for a process' is not restricted to Administrators, LOCAL SERVICE, NETWORK SERVICE.

Checks which accounts may adjust the memory quota available to a process.

This rule fails when the accounts assigned to `seIncreaseQuotaPrivilege` are not exactly Administrators, LOCAL SERVICE, NETWORK SERVICE.

**Rationale:** An account with this right can starve processes of memory and disrupt business-critical applications.

**Impact:** Only the listed principals can adjust process memory quotas.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Adjust memory quotas for a process'** to **Administrators, LOCAL SERVICE, NETWORK SERVICE**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Reliability Impact

MITRE ATT&CK tactic

Impact ([TA0040](https://attack.mitre.org/tactics/TA0040/))

## [Ensure 'Allow log on locally' Is Set To 'Administrators, Users'](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#allow-log-on-locally-is-set-to-administrators-users)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Allow log on locally' is not restricted to Administrators, Users.

Checks which accounts may log on interactively at the console.

This rule fails when the accounts assigned to `seInteractiveLogonRight` are not exactly Administrators, Users.

**Rationale:** Restricting local logon prevents unauthorized users from signing in at the machine's console.

**Impact:** Only administrators and standard users can log on locally.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Allow log on locally'** to **Administrators, Users**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Unprotected Principal

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## [Ensure 'Allow log on through Remote Desktop Services' Is Set To 'Administrators, Remote Desktop Users'](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#allow-log-on-through-remote-desktop-services-is-set-to-administrators-remote-des)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Allow log on through Remote Desktop Services' is not restricted to Administrators, Remote Desktop Users.

Checks which accounts may log on through Remote Desktop Services.

This rule fails when the accounts assigned to `seRemoteInteractiveLogonRight` are not exactly Administrators, Remote Desktop Users.

**Rationale:** Limiting RDP logon to administrators and remote desktop users reduces the remote attack surface.

**Impact:** Only the listed groups can sign in over Remote Desktop.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Allow log on through Remote Desktop Services'** to **Administrators, Remote Desktop Users**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

External Exposure

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## [Ensure 'Back up files and directories' Is Set To 'Administrators'](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#back-up-files-and-directories-is-set-to-administrators)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Back up files and directories' is not restricted to Administrators.

Checks which accounts may bypass file and directory permissions to perform backups.

This rule fails when the accounts assigned to `seBackupPrivilege` are not exactly Administrators.

**Rationale:** This right bypasses ACLs; a non-administrator could copy protected data off the system.

**Impact:** Only administrators can back up files and directories.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Back up files and directories'** to **Administrators**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Unprotected Data

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

## [Ensure 'Change the system time' Is Set To 'Administrators, LOCAL SERVICE'](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#change-the-system-time-is-set-to-administrators-local-service)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Change the system time' is not restricted to Administrators, LOCAL SERVICE.

Checks which accounts may change the system clock.

This rule fails when the accounts assigned to `seSystemtimePrivilege` are not exactly Administrators, LOCAL SERVICE.

**Rationale:** Altering the clock can invalidate event-log and file timestamps and disrupt time-based authentication.

**Impact:** Only administrators and LOCAL SERVICE can change the system time.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Change the system time'** to **Administrators, LOCAL SERVICE**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Reliability Impact

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

## [Ensure 'Create a pagefile' Is Set To 'Administrators'](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#create-a-pagefile-is-set-to-administrators)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Create a pagefile' is not restricted to Administrators.

Checks which accounts may create or resize the pagefile.

This rule fails when the accounts assigned to `seCreatePagefilePrivilege` are not exactly Administrators.

**Rationale:** Mis-sizing or relocating the pagefile can degrade system performance.

**Impact:** Only administrators can create a pagefile.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Create a pagefile'** to **Administrators**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Reliability Impact

MITRE ATT&CK tactic

Impact ([TA0040](https://attack.mitre.org/tactics/TA0040/))

## [Ensure 'Create a token object' Is Set To No One](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#create-a-token-object-is-set-to-no-one)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Create a token object' is assigned to one or more accounts.

Checks which accounts may create access tokens.

This rule fails when `seCreateTokenPrivilege` is assigned to any account.

**Rationale:** An account with this right can craft tokens granting itself elevated access and fully compromise the host.

**Impact:** None; no account requires this right by default.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Create a token object'** to **No One**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Unprotected Principal

MITRE ATT&CK tactic

Privilege Escalation ([TA0004](https://attack.mitre.org/tactics/TA0004/))

## [Ensure 'Create global objects' Is Set To 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE'](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#create-global-objects-is-set-to-administrators-local-service-network-service-ser)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Create global objects' is not restricted to Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE.

Checks which accounts may create global objects available to all sessions.

This rule fails when the accounts assigned to `seCreateGlobalPrivilege` are not exactly Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE.

**Rationale:** Global objects can interfere with services and processes running under other accounts.

**Impact:** Only the listed principals can create global objects.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Create global objects'** to **Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Unprotected Principal

MITRE ATT&CK tactic

Privilege Escalation ([TA0004](https://attack.mitre.org/tactics/TA0004/))

## [Ensure 'Create permanent shared objects' Is Set To No One](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#create-permanent-shared-objects-is-set-to-no-one)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Create permanent shared objects' is assigned to one or more accounts.

Checks which accounts may create permanent shared objects.

This rule fails when `seCreatePermanentPrivilege` is assigned to any account.

**Rationale:** This right could be used to create shared objects that expose sensitive data on the network.

**Impact:** None; kernel-mode components already hold this right inherently.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Create permanent shared objects'** to **No One**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Unprotected Principal

MITRE ATT&CK tactic

Privilege Escalation ([TA0004](https://attack.mitre.org/tactics/TA0004/))

## [Ensure 'Create symbolic links' Is Set To 'Administrators'](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#create-symbolic-links-is-set-to-administrators)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Create symbolic links' is not restricted to Administrators.

Checks which accounts may create symbolic links.

This rule fails when the accounts assigned to `seCreateSymbolicLinkPrivilege` are not exactly Administrators.

**Rationale:** Symbolic-link creation can be abused for link-following attacks that redirect operations to other targets.

**Impact:** Only administrators can create symbolic links.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Create symbolic links'** to **Administrators**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Unprotected Principal

MITRE ATT&CK tactic

Privilege Escalation ([TA0004](https://attack.mitre.org/tactics/TA0004/))

## [Ensure 'Debug programs' Is Set To 'Administrators'](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#debug-programs-is-set-to-administrators)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Debug programs' is not restricted to Administrators.

Checks which accounts may attach a debugger to any process or the kernel.

This rule fails when the accounts assigned to `seDebugPrivilege` are not exactly Administrators.

**Rationale:** Debug rights grant full access to process and kernel memory and are used to extract credentials and code.

**Impact:** Only administrators can debug programs.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Debug programs'** to **Administrators**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Insecure Use of Secrets

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

## [Ensure 'Deny access to this computer from the network' Is Set To Include Guests](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#deny-access-to-this-computer-from-the-network-is-set-to-include-guests)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Deny access to this computer from the network' does not include the Guests group.

Checks that network logon is denied to the Guests group.

This rule fails when `seDenyNetworkLogonRight` does not include the `Guests` group.

**Rationale:** Blocking guest network logon prevents anonymous enumeration and access to shared resources.

**Impact:** Guests can no longer access the computer over the network.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Deny access to this computer from the network'** to **Guests**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

External Exposure

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## [Ensure 'Deny log on as a batch job' Is Set To Include Guests](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#deny-log-on-as-a-batch-job-is-set-to-include-guests)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Deny log on as a batch job' does not include the Guests group.

Checks that batch-job logon is denied to the Guests group.

This rule fails when `seDenyBatchLogonRight` does not include the `Guests` group.

**Rationale:** Guests with batch logon could schedule resource-consuming or malicious jobs.

**Impact:** Guests can no longer log on as a batch job.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Deny log on as a batch job'** to **Guests**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Unprotected Principal

MITRE ATT&CK tactic

Privilege Escalation ([TA0004](https://attack.mitre.org/tactics/TA0004/))

## [Ensure 'Deny log on as a service' Is Set To Include Guests](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#deny-log-on-as-a-service-is-set-to-include-guests)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Deny log on as a service' does not include the Guests group.

Checks that service logon is denied to the Guests group.

This rule fails when `seDenyServiceLogonRight` does not include the `Guests` group.

**Rationale:** Guests able to log on as a service could register unauthorized or malicious services.

**Impact:** Guests can no longer log on as a service.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Deny log on as a service'** to **Guests**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Unprotected Principal

MITRE ATT&CK tactic

Privilege Escalation ([TA0004](https://attack.mitre.org/tactics/TA0004/))

## [Ensure 'Deny log on locally' Is Set To Include Guests](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#deny-log-on-locally-is-set-to-include-guests)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Deny log on locally' does not include the Guests group.

Checks that local logon is denied to the Guests group.

This rule fails when `seDenyInteractiveLogonRight` does not include the `Guests` group.

**Rationale:** Guests able to log on locally could access the console and installed data.

**Impact:** Guests can no longer log on at the console.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Deny log on locally'** to **Guests**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Unprotected Principal

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## [Ensure 'Deny log on through Remote Desktop Services' Is Set To Include Guests](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#deny-log-on-through-remote-desktop-services-is-set-to-include-guests)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Deny log on through Remote Desktop Services' does not include the Guests group.

Checks that Remote Desktop logon is denied to the Guests group.

This rule fails when `seDenyRemoteInteractiveLogonRight` does not include the `Guests` group.

**Rationale:** Guests able to log on over Remote Desktop could reach the remote console of the machine.

**Impact:** Guests can no longer sign in over Remote Desktop.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Deny log on through Remote Desktop Services'** to **Guests**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

External Exposure

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## [Ensure 'Enable computer and user accounts to be trusted for delegation' Is Set To No One](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#enable-computer-and-user-accounts-to-be-trusted-for-delegation-is-set-to-no-one)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Enable computer and user accounts to be trusted for delegation' is assigned to one or more accounts.

Checks which accounts may mark computer and user accounts as trusted for delegation.

This rule fails when `seEnableDelegationPrivilege` is assigned to any account.

**Rationale:** Misuse allows impersonation of other users and access to network resources under their identity.

**Impact:** None; this right is not required on a standalone workstation.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Enable computer and user accounts to be trusted for delegation'** to **No One**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Unprotected Principal

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## [Ensure 'Force shutdown from a remote system' Is Set To 'Administrators'](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#force-shutdown-from-a-remote-system-is-set-to-administrators)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Force shutdown from a remote system' is not restricted to Administrators.

Checks which accounts may shut the computer down remotely.

This rule fails when the accounts assigned to `seRemoteShutdownPrivilege` are not exactly Administrators.

**Rationale:** Anyone with this right could trigger a denial of service by shutting the machine down.

**Impact:** Only administrators can force a remote shutdown.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Force shutdown from a remote system'** to **Administrators**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Reliability Impact

MITRE ATT&CK tactic

Impact ([TA0040](https://attack.mitre.org/tactics/TA0040/))

## [Ensure 'Generate security audits' Is Set To 'LOCAL SERVICE, NETWORK SERVICE, RESTRICTED SERVICES\PrintSpoolerService'](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#generate-security-audits-is-set-to-local-service-network-service-restricted-serv)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Generate security audits' is not restricted to LOCAL SERVICE, NETWORK SERVICE, RESTRICTED SERVICES\PrintSpoolerService.

Checks which accounts may write records to the Security event log.

This rule fails when the accounts assigned to `seAuditPrivilege` are not exactly LOCAL SERVICE, NETWORK SERVICE, RESTRICTED SERVICES\PrintSpoolerService.

**Rationale:** An account with this right could flood the Security log to hide malicious activity.

**Impact:** Only the listed service principals can generate security audit events.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Generate security audits'** to **LOCAL SERVICE, NETWORK SERVICE, RESTRICTED SERVICES\PrintSpoolerService**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Unprotected Principal

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

## [Ensure 'Impersonate a client after authentication' Is Set To 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE, RESTRICTED SERVICES\PrintSpoolerService'](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#impersonate-a-client-after-authentication-is-set-to-administrators-local-service)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Impersonate a client after authentication' is not restricted to Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE, RESTRICTED SERVICES\PrintSpoolerService.

Checks which accounts may impersonate a client after authentication.

This rule fails when the accounts assigned to `seImpersonatePrivilege` are not exactly Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE, RESTRICTED SERVICES\PrintSpoolerService.

**Rationale:** An account with this right could trick a client into connecting and then impersonate it.

**Impact:** Only the listed principals can impersonate an authenticated client.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Impersonate a client after authentication'** to **Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE, RESTRICTED SERVICES\PrintSpoolerService**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Unprotected Principal

MITRE ATT&CK tactic

Privilege Escalation ([TA0004](https://attack.mitre.org/tactics/TA0004/))

## [Ensure 'Increase scheduling priority' Is Set To 'Administrators, Window Manager\Window Manager Group'](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#increase-scheduling-priority-is-set-to-administrators-window-manager-window-mana)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Increase scheduling priority' is not restricted to Administrators, Window Manager\Window Manager Group.

Checks which accounts may raise the scheduling priority of a process.

This rule fails when the accounts assigned to `seIncreaseBasePriorityPrivilege` are not exactly Administrators, Window Manager\Window Manager Group.

**Rationale:** Raising a process to real-time priority can starve all other processes and cause a denial of service.

**Impact:** Only administrators and the Window Manager group can raise scheduling priority.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Increase scheduling priority'** to **Administrators, Window Manager\Window Manager Group**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Reliability Impact

MITRE ATT&CK tactic

Impact ([TA0040](https://attack.mitre.org/tactics/TA0040/))

## [Ensure 'Load and unload device drivers' Is Set To 'Administrators'](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#load-and-unload-device-drivers-is-set-to-administrators)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Load and unload device drivers' is not restricted to Administrators.

Checks which accounts may load and unload device drivers.

This rule fails when the accounts assigned to `seLoadDriverPrivilege` are not exactly Administrators.

**Rationale:** Drivers run as privileged kernel code; this right could be used to load malicious code into the kernel.

**Impact:** Only administrators can load and unload device drivers.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Load and unload device drivers'** to **Administrators**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Insecure Application

MITRE ATT&CK tactic

Privilege Escalation ([TA0004](https://attack.mitre.org/tactics/TA0004/))

## [Ensure 'Lock pages in memory' Is Set To No One](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#lock-pages-in-memory-is-set-to-no-one)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Lock pages in memory' is assigned to one or more accounts.

Checks which accounts may lock pages in physical memory.

This rule fails when `seLockMemoryPrivilege` is assigned to any account.

**Rationale:** Locking large amounts of memory can starve other processes and cause a denial of service.

**Impact:** None; no account requires this right by default.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Lock pages in memory'** to **No One**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Reliability Impact

MITRE ATT&CK tactic

Impact ([TA0040](https://attack.mitre.org/tactics/TA0040/))

## [Ensure 'Log on as a batch job' Is Set To 'Administrators'](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#log-on-as-a-batch-job-is-set-to-administrators)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Log on as a batch job' is not restricted to Administrators.

Checks which accounts may log on using the task scheduler service.

This rule fails when the accounts assigned to `seBatchLogonRight` are not exactly Administrators.

**Rationale:** Limiting batch logon reduces the ways scheduled tasks can be abused to run code.

**Impact:** Only administrators can log on as a batch job.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Log on as a batch job'** to **Administrators**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Unprotected Principal

MITRE ATT&CK tactic

Privilege Escalation ([TA0004](https://attack.mitre.org/tactics/TA0004/))

## [Ensure 'Log on as a service' Is Set To No One](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#log-on-as-a-service-is-set-to-no-one)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Log on as a service' is assigned to one or more accounts.

Checks which accounts may register a process as a service.

This rule fails when `seServiceLogonRight` is assigned to any account.

**Rationale:** Service logon lets code run continuously even when no one is signed in and should be tightly controlled.

**Impact:** None; assign the right only to specific service accounts if a component requires it.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Log on as a service'** to **No One**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Unprotected Principal

MITRE ATT&CK tactic

Persistence ([TA0003](https://attack.mitre.org/tactics/TA0003/))

## [Ensure 'Manage auditing and security log' Is Set To 'Administrators'](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#manage-auditing-and-security-log-is-set-to-administrators)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Manage auditing and security log' is not restricted to Administrators.

Checks which accounts may configure object auditing and clear the Security log.

This rule fails when the accounts assigned to `seSecurityPrivilege` are not exactly Administrators.

**Rationale:** This right allows clearing the Security log to erase evidence of an attack.

**Impact:** Only administrators can manage auditing and the Security log.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Manage auditing and security log'** to **Administrators**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Unprotected Principal

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

## [Ensure 'Modify an object label' Is Set To No One](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#modify-an-object-label-is-set-to-no-one)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Modify an object label' is assigned to one or more accounts.

Checks which accounts may change the integrity label of objects owned by others.

This rule fails when `seRelabelPrivilege` is assigned to any account.

**Rationale:** Changing an object's integrity label could cause code to run at a higher privilege than intended.

**Impact:** None; no account requires this right by default.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Modify an object label'** to **No One**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Unprotected Principal

MITRE ATT&CK tactic

Privilege Escalation ([TA0004](https://attack.mitre.org/tactics/TA0004/))

## [Ensure 'Modify firmware environment values' Is Set To 'Administrators'](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#modify-firmware-environment-values-is-set-to-administrators)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Modify firmware environment values' is not restricted to Administrators.

Checks which accounts may modify system firmware environment values.

This rule fails when the accounts assigned to `seSystemEnvironmentPrivilege` are not exactly Administrators.

**Rationale:** Altering firmware values could misconfigure hardware and cause data corruption or failure.

**Impact:** Only administrators can modify firmware environment values.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Modify firmware environment values'** to **Administrators**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Reliability Impact

MITRE ATT&CK tactic

Impact ([TA0040](https://attack.mitre.org/tactics/TA0040/))

## [Ensure 'Perform volume maintenance tasks' Is Set To 'Administrators'](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#perform-volume-maintenance-tasks-is-set-to-administrators)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Perform volume maintenance tasks' is not restricted to Administrators.

Checks which accounts may perform volume and disk maintenance tasks.

This rule fails when the accounts assigned to `seManageVolumePrivilege` are not exactly Administrators.

**Rationale:** This right could be used to delete a volume, causing data loss or a denial of service.

**Impact:** Only administrators can perform volume maintenance tasks.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Perform volume maintenance tasks'** to **Administrators**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Unprotected Data

MITRE ATT&CK tactic

Impact ([TA0040](https://attack.mitre.org/tactics/TA0040/))

## [Ensure 'Profile single process' Is Set To 'Administrators'](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#profile-single-process-is-set-to-administrators)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Profile single process' is not restricted to Administrators.

Checks which accounts may profile the performance of individual processes.

This rule fails when the accounts assigned to `seProfileSingleProcessPrivilege` are not exactly Administrators.

**Rationale:** Process profiling could help an attacker identify critical processes to target.

**Impact:** Only administrators can profile a single process.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Profile single process'** to **Administrators**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Unprotected Principal

MITRE ATT&CK tactic

Discovery ([TA0007](https://attack.mitre.org/tactics/TA0007/))

## [Ensure 'Profile system performance' Is Set To 'Administrators, NT SERVICE\WdiServiceHost'](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#profile-system-performance-is-set-to-administrators-nt-service-wdiservicehost)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Profile system performance' is not restricted to Administrators, NT SERVICE\WdiServiceHost.

Checks which accounts may profile overall system performance.

This rule fails when the accounts assigned to `seSystemProfilePrivilege` are not exactly Administrators, NT SERVICE\WdiServiceHost.

**Rationale:** System profiling could reveal critical processes an attacker may wish to target.

**Impact:** Only administrators and the diagnostics service host can profile system performance.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Profile system performance'** to **Administrators, NT SERVICE\WdiServiceHost**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Unprotected Principal

MITRE ATT&CK tactic

Discovery ([TA0007](https://attack.mitre.org/tactics/TA0007/))

## [Ensure 'Replace a process level token' Is Set To 'LOCAL SERVICE, NETWORK SERVICE'](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#replace-a-process-level-token-is-set-to-local-service-network-service)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Replace a process level token' is not restricted to LOCAL SERVICE, NETWORK SERVICE.

Checks which accounts may replace the token of a process.

This rule fails when the accounts assigned to `seAssignPrimaryTokenPrivilege` are not exactly LOCAL SERVICE, NETWORK SERVICE.

**Rationale:** This right lets a caller start processes under other users' credentials, hiding unauthorized activity.

**Impact:** Only LOCAL SERVICE and NETWORK SERVICE can replace a process-level token.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Replace a process level token'** to **LOCAL SERVICE, NETWORK SERVICE**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Unprotected Principal

MITRE ATT&CK tactic

Privilege Escalation ([TA0004](https://attack.mitre.org/tactics/TA0004/))

## [Ensure 'Restore files and directories' Is Set To 'Administrators'](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#restore-files-and-directories-is-set-to-administrators)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Restore files and directories' is not restricted to Administrators.

Checks which accounts may bypass permissions to restore files and directories.

This rule fails when the accounts assigned to `seRestorePrivilege` are not exactly Administrators.

**Rationale:** This right bypasses ACLs and could overwrite newer data or restore malicious files.

**Impact:** Only administrators can restore files and directories.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Restore files and directories'** to **Administrators**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Unprotected Data

MITRE ATT&CK tactic

Privilege Escalation ([TA0004](https://attack.mitre.org/tactics/TA0004/))

## [Ensure 'Shut down the system' Is Set To 'Administrators, Users'](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#shut-down-the-system-is-set-to-administrators-users)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Shut down the system' is not restricted to Administrators, Users.

Checks which accounts logged on locally may shut the system down.

This rule fails when the accounts assigned to `seShutdownPrivilege` are not exactly Administrators, Users.

**Rationale:** Shutdown should be available to authorized users but not to guests or unauthorized accounts.

**Impact:** Only administrators and standard users can shut down the system.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Shut down the system'** to **Administrators, Users**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Reliability Impact

MITRE ATT&CK tactic

Impact ([TA0040](https://attack.mitre.org/tactics/TA0040/))

## [Ensure 'Take ownership of files or other objects' Is Set To 'Administrators'](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/user-rights-assignment.html#take-ownership-of-files-or-other-objects-is-set-to-administrators)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 2.2

**Finding:** 'Take ownership of files or other objects' is not restricted to Administrators.

Checks which accounts may take ownership of files and other objects.

This rule fails when the accounts assigned to `seTakeOwnershipPrivilege` are not exactly Administrators.

**Rationale:** Taking ownership bypasses any permissions and lets the holder gain control of any object.

**Impact:** Only administrators can take ownership of files or other objects.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment** and set **'Take ownership of files or other objects'** to **Administrators**.

Framework mappings

- **CIS Controls v8**: 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- **PCI DSS v4.0.1**: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Unprotected Principal

MITRE ATT&CK tactic

Privilege Escalation ([TA0004](https://attack.mitre.org/tactics/TA0004/))

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
