Information
This policy setting allows users to change the Trusted for Delegation setting on a computer object in Active Directory.
The recommended state for this setting on Domain Controllers is: Administrators.
Note: Certain policy settings must be configured in the Default Domain Controller Policy to ensure they are applied globally to domain controllers. Exercise caution when modifying these policies, as improper changes can negatively impact the environment.
Only policies that are configured by Microsoft by default should reside in these baseline GPOs. Any additional or custom policy settings should be implemented through separate GPOs rather than modifying the default policies.
Note #2: This user right is considered a 'sensitive privilege' for the purposes of auditing.
Misuse of this user right could allow unauthorized users to impersonate other users on the network. A threat actor could exploit this privilege to gain access to network resources and make it difficult to determine what has happened after a security incident.
Solution
To establish the recommended configuration via GP, configure the following UI path to Administrators :
Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment\Enable computer and user accounts to be trusted for delegation
Impact:
None - this is the default behavior.