Language:
Group Policy Objects (GPOs) configure Windows systems and perform tasks at a high level of privileges. However, only legitimate administrative accounts should manage GPOs linked to sensitive containers, such as the ones containing administrators or domain controllers.
Permissions on sensitive GPO files or object should only allow control access to legitimate administrative accounts.
Name: Verify Sensitive GPO Objects and Files Permissions
Codename: C-GPO-SD-CONSISTENCY
Severity: Critical