SV-226052r569184_rule
V-226052
SRG-OS-000480-GPOS-00227
WN12-00-000190
CAT II
10
Remove any unresolved SIDs found in User Rights assignments and determined to not be for currently valid accounts or groups by removing the accounts or groups from the appropriate group policy.
Review the effective User Rights setting in Local Group Policy Editor.
Run "gpedit.msc".
Navigate to Local Computer Policy >> Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment.
Review each User Right listed for any unresolved SIDs to determine whether they are valid, such as due to being temporarily disconnected from the domain. (Unresolved SIDs have the format of "*S-1-…".)
If any unresolved SIDs exist and are not for currently valid accounts or groups, this is a finding.
V-226052
False
WN12-00-000190
Review the effective User Rights setting in Local Group Policy Editor.
Run "gpedit.msc".
Navigate to Local Computer Policy >> Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment.
Review each User Right listed for any unresolved SIDs to determine whether they are valid, such as due to being temporarily disconnected from the domain. (Unresolved SIDs have the format of "*S-1-…".)
If any unresolved SIDs exist and are not for currently valid accounts or groups, this is a finding.
M
4217