2.2.24 Ensure 'Generate security audits' is set to 'LOCAL SERVICE, NETWORK SERVICE'

Information

This policy setting determines which users or processes can generate audit records in the Security log.

The recommended state for this setting is: 'LOCAL SERVICE, NETWORK SERVICE'.

Note: A Member Server that holds the _Web Server (IIS)_ Role with _Web Server_ Role Service will require a special exception to this recommendation, to allow IIS application pool(s) to be granted this user right.

Note #2: A Member Server that holds the _Active Directory Federation Services_ Role will require a special exception to this recommendation, to allow the 'NT SERVICE\ADFSSrv' and 'NT SERVICE\DRS 'services, as well as the associated Active Directory Federation Services service account, to be granted this user right.

Solution

To establish the recommended configuration via GP, set the following UI path to ''LOCAL SERVICE, NETWORK SERVICE'': Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment\Generate security audits

See Also

https://workbench.cisecurity.org/files/1941