20.7 (L1) Ensure 'Standard user accounts do not have Administrator privileges'

Information

This setting ensures that the system is operated with a standard user account that does not have Administrator privileges. Standard user accounts must not be members of the local administrators group, Domain Admins or Enterprise Admins group.

A standard user that does not have administrator duties should not have Administrator rights on the system.

Standard users with Administrator rights can allow the account to bypass or modify required security restrictions on the system that could make it vulnerable to an attack. In addition, if the standard user account is breeched, the attacker will have administrator access to the system.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Remove any standard user accounts from the

Local Administrators

,

Domain Admins

, and

Enterprise Admins

groups to ensure that the system only includes administrator groups or accounts that are responsible for the administration of the system.

Impact:

The user will not be able to perform Administrative tasks on the system.

See Also

https://workbench.cisecurity.org/benchmarks/17610