WN12-UR-000002-DC - Unauthorized accounts must not have the Access this computer from the network user right on domain controllers.

Information

Inappropriate granting of user rights can provide system, administrative, and other high-level capabilities.

Accounts with the 'Access this computer from the network' right may access resources on the system and should be limited to those requiring it.

Solution

Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> User Rights Assignment -> 'Access this computer from the network' to only include the following accounts or groups:

Administrators
Authenticated Users
Enterprise Domain Controllers

Severity Override Guidance: If an application requires this user right, this can be downgraded to not a finding if the following conditions are met:
- Vendor documentation must support the requirement for having the user right.
- The requirement must be documented with the ISSO.
- The application account must meet requirements for application account passwords, such as length (V-36661) and required changes frequency (V-36662).

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_2012_and_2012_R2_DC_V3R7_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3, CAT|II, CCI|CCI-000213, Rule-ID|SV-226371r794624_rule, STIG-ID|WN12-UR-000002-DC, STIG-Legacy|SV-51142, STIG-Legacy|V-26470, Vuln-ID|V-226371

Plugin: Windows

Control ID: 3bcc29da7a273438cd610c7b887c2feaf480a4f257858b4cc48ccb9f60276bf3