SV-220971r569187_rule
V-220971
SRG-OS-000080-GPOS-00048
WN10-UR-000085
CAT II
10
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> "Deny log on locally" to include the following.
Domain Systems Only:
Enterprise Admins Group
Domain Admins Group
Privileged Access Workstations (PAWs) dedicated to the management of Active Directory are exempt from denying the Enterprise Admins and Domain Admins groups. (See the Windows Privileged Access Workstation STIG for PAW requirements.)
All Systems:
Guests Group
Verify the effective setting in Local Group Policy Editor.
Run "gpedit.msc".
Navigate to Local Computer Policy >> Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment.
If the following groups or accounts are not defined for the "Deny log on locally" right, this is a finding.
Domain Systems Only:
Enterprise Admins Group
Domain Admins Group
Privileged Access Workstations (PAWs) dedicated to the management of Active Directory are exempt from denying the Enterprise Admins and Domain Admins groups. (See the Windows Privileged Access Workstation STIG for PAW requirements.)
All Systems:
Guests Group
V-220971
False
WN10-UR-000085
Verify the effective setting in Local Group Policy Editor.
Run "gpedit.msc".
Navigate to Local Computer Policy >> Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment.
If the following groups or accounts are not defined for the "Deny log on locally" right, this is a finding.
Domain Systems Only:
Enterprise Admins Group
Domain Admins Group
Privileged Access Workstations (PAWs) dedicated to the management of Active Directory are exempt from denying the Enterprise Admins and Domain Admins groups. (See the Windows Privileged Access Workstation STIG for PAW requirements.)
All Systems:
Guests Group
M
4072