74.1 (L1) Ensure 'Access Credential Manager As Trusted Caller' is set to 'No One'

Information

This security setting is used by Credential Manager during Backup and Restore. No accounts should have this user right, as it is only assigned to Winlogon. Users' saved credentials might be compromised if this user right is assigned to other entities.

The recommended state for this setting is: No One

If an account is given this right the user of the account may create an application that calls into Credential Manager and is returned the credentials for another user.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to (<![CDATA[]]>) which represents No One

User Rights\Access Credential Manager As Trusted Caller

Note: Using (<![CDATA[]]>) to represent a blank value or No One is recommended by Microsoft. However, there is a known issue where an error occurs in Endpoint Manger (Intune) but this does not affect the policy setting from being applied properly to the system.

Impact:

None - this is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/16853