2.2.34 Ensure 'Load and unload device drivers' is set to 'Administrators'

Information

This policy setting allows users to dynamically load a new device driver on a system. This user right is not required if a signed driver for the new hardware already exists in the Driver.cab file on the system.

The recommended state for this setting is: Administrators.

Note: Certain policy settings must be configured in the Default Domain Controller Policy to ensure they are applied globally to domain controllers. Exercise caution when modifying these policies, as improper changes can negatively impact the environment.

Only policies that are configured by Microsoft by default should reside in these baseline GPOs. Any additional or custom policy settings should be implemented through separate GPOs rather than modifying the default policies.

Note #2: This user right is considered a 'sensitive privilege' for the purposes of auditing.

Device drivers run as highly privileged code. A user or threat actor who has the Load and unload device drivers user right could unintentionally install malicious code that masquerades as a device driver. Administrators should exercise greater care and install only drivers with verified digital signatures.

Solution

To establish the recommended configuration via GP, set the following UI path to Administrators :

Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment\Load and unload device drivers

Impact:

If the Load and unload device drivers user right is removed from the Print Operators group or other accounts, it could limit the abilities of users who are assigned to specific administrative roles in your environment. Ensure that delegated tasks will not be negatively affected by this setting.

See Also

https://workbench.cisecurity.org/benchmarks/27461