22.06.2016 Views

CIS Microsoft Windows 10 Enterprise RTM (Release 1507) Benchmark

CIS_Microsoft_Windows_10_Enterprise_RTM_Release_1507_Benchmark_v1.0.0

CIS_Microsoft_Windows_10_Enterprise_RTM_Release_1507_Benchmark_v1.0.0

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

2.2.12 (L1) Set 'Create global objects' to 'Administrators, LOCAL SERVICE,<br />

NETWORK SERVICE, SERVICE' (Scored)<br />

Profile Applicability:<br />

Level 1<br />

Level 1 + BitLocker<br />

Description:<br />

This policy setting determines whether users can create global objects that are available to<br />

all sessions. Users can still create objects that are specific to their own session if they do not<br />

have this user right.<br />

Users who can create global objects could affect processes that run under other users'<br />

sessions. This capability could lead to a variety of problems, such as application failure or<br />

data corruption.<br />

The recommended state for this setting is: Administrators, LOCAL SERVICE, NETWORK<br />

SERVICE, SERVICE.<br />

Rationale:<br />

Users who can create global objects could affect <strong>Windows</strong> services and processes that run<br />

under other user or system accounts. This capability could lead to a variety of problems,<br />

such as application failure, data corruption and elevation of privilege.<br />

Audit:<br />

Navigate to the UI Path articulated in the Remediation section and confirm it is set as<br />

prescribed.<br />

Remediation:<br />

To establish the recommended configuration via GP, set the following UI path to<br />

Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE:<br />

Computer Configuration\Policies\<strong>Windows</strong> Settings\Security Settings\Local Policies\User<br />

Rights Assignment\Create global objects<br />

Impact:<br />

None. This is the default configuration.<br />

73 | P a g e

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!