WINGE-000200 - A group must be defined on domain systems to include all local administrator accounts.

Information

Several user rights on domain systems require that local administrator accounts be assigned to them. This is separate from the built-in Administrators group, which also contains domain administrative accounts/groups. Defining a consistent group name allows compliance to be more easily determined.

Solution

This requirement is NA for non domain-joined systems.

Create a local group with the name 'DenyNetworkAccess' or 'DeniedNetworkAccess' on the system.
Include all local administrator accounts as members of the group, including the built-in Administrator account. Do not include domain administrative accounts or groups.

See Also

http://iasecontent.disa.mil/stigs/zip/Oct2016/U_Windows_Vista_V6R41_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-58415r2_rule, STIG-ID|WINGE-000200, Vuln-ID|V-45589

Plugin: Windows

Control ID: bea071df669cccd93cd0182a99486e6d0d0344197cf7b72c5b3cf72dacd85351