Information
This policy setting allows users to change the Trusted for Delegation setting on a computer object in Active Directory.
The recommended state for this setting on Member Servers is: No One.
Note: This user right is considered a 'sensitive privilege' for the purposes of auditing.
Misuse of this user right could allow unauthorized users to impersonate other users on the network. A threat actor could exploit this privilege to gain access to network resources and make it difficult to determine what has happened after a security incident.
Solution
To establish the recommended configuration via GP, configure the following UI path to No One :
Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment\Enable computer and user accounts to be trusted for delegation
Impact:
None - this is the default behavior.