18.4.9 (L1) Ensure 'Remove 'Run as Different User' from context menus' is set to 'Enabled (recommended)'

Information

This setting controls whether 'Run As Different User' appears on the Shift+RightClick context menu for .bat, .cmd, .exe, and .mcs files.

The recommended state for this setting is: Enabled

The

Remove 'Run as Different User' from context menus

allows the use of credentials other than that of the currently logged on user, which could lead to credential theft or running an application or file in the context of another user.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\MS Security Guide\Remove 'Run as Different User' from context menus

Note: This Group Policy path does not exist by default. An additional Group Policy template SecGuide.admx/adml is required - it is available from Microsoft at

this link

.

Impact:

The

Run As Different User

context will not appear if Shift+RightClick is used.

See Also

https://workbench.cisecurity.org/benchmarks/17610

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6

Plugin: Windows

Control ID: 4b8a8f9b3bca8e8ec6b5932d7305eaea2b4974dc1a8a6fba9ae91d9e7d8a3d0f