1.153 WN16-DC-000080

Information

The Active Directory SYSVOL directory must have the proper access control permissions.

GROUP ID: V-224971
RULE ID: SV-224971r958726

Improper access permissions for directory data files could allow unauthorized users to read, modify, or delete directory data.

The SYSVOL directory contains public files (to the domain) such as policies and logon scripts. Data in shared subdirectories are replicated to all domain controllers in a domain.

Solution

Maintain the permissions on the SYSVOL directory. Do not allow greater than 'Read & execute' permissions for standard user accounts or groups. The defaults below meet this requirement.

C:\Windows\SYSVOLType - 'Allow' for allInherited from - 'None' for all

Principal - Access - Applies to

- Authenticated Users - Read & execute - This folder, subfolder, and files
- Server Operators - Read & execute- This folder, subfolder, and files
- Administrators - Special - This folder only (Special = Basic Permissions: all selected except Full control)
- CREATOR OWNER - Full control - Subfolders and files only
- Administrators - Full control - Subfolders and files only
- SYSTEM - Full control - This folder, subfolders, and files

See Also

https://workbench.cisecurity.org/benchmarks/23093