2.2.20 Ensure 'Enable computer and user accounts to be trusted for delegation' is set to 'No One'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

This policy setting allows users to change the Trusted for Delegation setting on a computer object in Active Directory.

The recommended state for this setting is: No One.

Note: This user right is considered a 'sensitive privilege' for the purposes of auditing.

Misuse of this user right could allow unauthorized users to impersonate other users on the network. A threat actor could exploit this privilege to gain access to network resources and make it difficult to determine what has happened after a security incident.

Solution

To establish the recommended configuration via GP, set the following UI path to No One :

Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment\Enable computer and user accounts to be trusted for delegation

Impact:

None - this is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/25561