This policy setting allows users to change the Trusted for Delegation setting on a computer object in Active Directory. The recommended state for this setting is: No One. Note: This user right is considered a 'sensitive privilege' for the purposes of auditing. Misuse of this user right could allow unauthorized users to impersonate other users on the network. A threat actor could exploit this privilege to gain access to network resources and make it difficult to determine what has happened after a security incident.
Solution
To establish the recommended configuration via GP, set the following UI path to No One : Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment\Enable computer and user accounts to be trusted for delegation Impact: None - this is the default behavior.