OSX00125 - Securely configure Active Directory Access


The 'Allow administration by' setting should not be used in sensitive environments. It can cause unintended privilege escalation issues because any member of the group specified will have administrator privileges on your computer.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.


1. Open the Directory Utilities. 2. Click the Services tab. 3. Double-click on Active Directory. 4. Click on Show Advanced Options. 5. Click on Administrative tab and deselect 'Allow administration by' option.

See Also


Item Details

References: CAT|I, Rule-ID|SV-31327r1_rule, STIG-ID|OSX00125, Vuln-ID|V-25265

Plugin: Unix

Control ID: 418934f83b7e712672b2a2f2edc16f00c308c96ff4a323b6a28849594032426d