1.1.1.2.1.6 Set 'System objects: Default owner for objects created by members of the Administrators group' to 'Object creator'

Information

This policy setting determines whether the Administrators group or an object creator is the default owner of any system objects that are created. When system objects are created, the ownership will reflect which account created the object rather than the more generic Administrators group. If you configure this policy setting to Administrators group, it will be impossible to hold individuals accountable for the creation of new system objects.

Solution

To implement the recommended configuration state, set the following Group Policy setting to 1.

Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\System objects- Default owner for objects created by members of the Administrators group

Impact- When system objects are created, the ownership will reflect which account created the object instead of the more generic Administrators group. A consequence of this policy setting is that objects will become orphaned when user accounts are deleted. For example, when a member of the information technology group leaves, any objects that they created anywhere in the domain will have no owner. This situation could become an administrative burden as administrators have to manually take ownership of orphaned objects to update their permissions. This potential burden can be minimized if you can ensure that Full Control is always assigned to new objects for a domain group such as Domain Admins.

See Also

https://workbench.cisecurity.org/files/42

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3(4), CCE|CCE-2947-0

Plugin: Windows

Control ID: d709885caf9eca89b70ffbd3032562947d38a0b57ff6bcbda39a716bc35cd7b9