20.44 Ensure 'Orphaned security identifiers (SIDs) must be removed from user rights'

Information

This policy setting ensures that orphaned security identifiers (SIDs) are removed from user rights.

Rationale:

Accounts or groups given rights on a system may show up as unresolved SIDs for various reasons including deletion of the accounts or groups. If the account or group objects are reanimated, there is a potential they may still have rights no longer intended. Valid domain accounts or groups may also show up as unresolved SIDs if a connection to the domain cannot be established for some reason.

Impact:

Orphaned security identifiers (SIDs) must removed from user rights.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Remove any unresolved SIDs found in User Rights assignments and determined to not be for currently valid accounts or groups by removing the accounts or groups from the appropriate group policy.

Default Value:

N/A




Additional Information:

Microsoft Windows Server 2016 Security Technical Implementation Guide:

Version 2, Release 2, Benchmark Date: May 04, 2021



Vul ID: V-224863

Rule ID: SV-224863r569186_rule

STIG ID: WN16-00-000460

Severity: CAT II

See Also

https://workbench.cisecurity.org/files/3476