1.1.4.11 Set 'Enable computer and user accounts to be trusted for delegation' to 'No One'

Information

This policy setting allows users to change the Trusted for Delegation setting on a computer object in Active Directory.

Solution

Make sure 'Enable computer and user accounts to be trusted for delegation' is set to no one.

See Also

https://workbench.cisecurity.org/files/17

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(7)(b), CSCv6|5.1

Plugin: Windows

Control ID: 8927c794d4ad3b7a55f8e9f3e097e4e41c6786404b921d4bb303fe8d50cead94