1.197 WN22-MS-000070

Information

Windows Server 2022 Access this computer from the network user right must only be assigned to the Administrators and Authenticated Users groups on domain-joined member servers and standalone or nondomain-joined systems.

GROUP ID: V-254434
RULE ID: SV-254434r958472

Inappropriate granting of user rights can provide system, administrative, and other high-level capabilities.

Accounts with the 'Access this computer from the network' user right may access resources on the system, and this right must be limited to those requiring it.

Solution

Configure the policy value for

Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Access this computer from the network

to include only the following accounts or groups:

- Administrators
- Authenticated Users

See Also

https://workbench.cisecurity.org/benchmarks/22357

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3, CAT|II, CCI|CCI-000213, Rule-ID|SV-254434r958472_rule, STIG-ID|WN22-MS-000070, Vuln-ID|V-254434

Plugin: Windows

Control ID: 0eb43293868f577bf1fba7450b53643b68476c69a7984891b9a0edeadb22d17b