1.1.4.11 Set 'Enable computer and user accounts to be trusted for delegation' to 'No One'

Information

This policy setting allows users to change the Trusted for Delegation setting on a computer object in Active Directory.

Solution

Make sure 'Enable computer and user accounts to be trusted for delegation' is set to no one.

See Also

https://workbench.cisecurity.org/files/17

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(7)(b), CSCv6|5.1

Plugin: Windows

Control ID: b172ce1d9392e3db6a1b196c01d5d698d8bca2466dbda5f540b045e7aa9d0c9c