Information
This policy setting determines which users can use tools to monitor the performance of non-system processes. Typically, this setting does not need to be configured to use the Microsoft Management Console (MMC) Performance snap-in. However, this user right is needed if System Monitor is configured to collect data using Windows Management Instrumentation (WMI).
The recommended state for this setting is: Administrators.
Note: Certain policy settings must be configured in the Default Domain Controller Policy to ensure they are applied globally to domain controllers. Exercise caution when modifying these policies, as improper changes can negatively impact the environment.
Only policies that are configured by Microsoft by default should reside in these baseline GPOs. Any additional or custom policy settings should be implemented through separate GPOs rather than modifying the default policies.
The Profile single process user right presents a moderate vulnerability. A threat actor with this user right could monitor a computer's performance to help identify critical processes that they might wish to attack directly. The threat actor may also be able to determine what processes run on the computer so that they can identify countermeasures that they may need to avoid, such as antivirus software, an intrusion-detection system, or which other users are logged on to a computer.
Solution
To establish the recommended configuration via GP, set the following UI path to Administrators :
Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment\Profile single process
Impact:
None - this is the default behavior.