STIGQter STIGQter: STIG Summary: Microsoft Windows 11 Security Technical Implementation Guide Version: 2 Release: 8 Benchmark Date: 01 Jul 2026:

Only accounts responsible for the backup operations must be members of the Backup Operators group.

DISA Rule

SV-253270r991589_rule

Vulnerability Number

V-253270

Group Title

SRG-OS-000480-GPOS-00227

Rule Version

WN11-00-000075

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Create separate accounts for backup operations for users with this privilege.

Check Contents

Run "Computer Management".
Navigate to System Tools >> Local Users and Groups >> Groups.
Review the members of the Backup Operators group.

If the group contains no accounts, this is not a finding.

If the group contains any accounts, the accounts must be specifically for backup functions.

If the group contains any standard user accounts used for performing normal user tasks, this is a finding.

Vulnerability Number

V-253270

Documentable

False

Rule Version

WN11-00-000075

Severity Override Guidance

Run "Computer Management".
Navigate to System Tools >> Local Users and Groups >> Groups.
Review the members of the Backup Operators group.

If the group contains no accounts, this is not a finding.

If the group contains any accounts, the accounts must be specifically for backup functions.

If the group contains any standard user accounts used for performing normal user tasks, this is a finding.

Check Content Reference

M

Target Key

5471