STIGQter STIGQter: STIG Summary: Active Directory Domain Security Technical Implementation Guide (STIG) Version: 2 Release: 13 Benchmark Date: 26 Apr 2019:

Membership to the Domain Admins group must be restricted to accounts used only to manage the Active Directory domain and domain controllers.

DISA Rule

SV-47838r2_rule

Vulnerability Number

V-36432

Group Title

Domain Admins Group Members

Rule Version

AD.0002

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Create the necessary documentation that identifies the members of the Domain Admins group. Ensure that each member has a separate unique account that can only be used to manage the Active Directory domain and domain controllers. Remove any Domain Admin accounts from other administrator groups.

Check Contents

Review the Domain Admins group in Active Directory Users and Computers. Any accounts that are members of the Domain Admins group must be documented with the IAO. Each Domain Administrator must have a separate unique account specifically for managing the Active Directory domain and domain controllers.

If any account listed in the Domain Admins group is a member of other administrator groups including the Enterprise Admins group, domain member server administrators groups, or domain workstation administrators groups, this is a finding.

Vulnerability Number

V-36432

Documentable

False

Rule Version

AD.0002

Severity Override Guidance

Review the Domain Admins group in Active Directory Users and Computers. Any accounts that are members of the Domain Admins group must be documented with the IAO. Each Domain Administrator must have a separate unique account specifically for managing the Active Directory domain and domain controllers.

If any account listed in the Domain Admins group is a member of other administrator groups including the Enterprise Admins group, domain member server administrators groups, or domain workstation administrators groups, this is a finding.

Check Content Reference

M

Target Key

870

Comments