STIGQter STIGQter: STIG Summary: Active Directory Domain Security Technical Implementation Guide (STIG) Version: 2 Release: 13 Benchmark Date: 26 Apr 2019:

Separate domain accounts must be used to manage public facing servers from any domain accounts used to manage internal servers.

DISA Rule

SV-56473r2_rule

Vulnerability Number

V-43652

Group Title

AD.0013

Rule Version

AD.0013

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

If the domain does not have any public facing servers, this is NA.

Configure the system to include only administrator groups or accounts that are responsible for the system in the local Administrators group.

For public facing servers, replace the Domain Admins group with a domain member server administrator group whose members are different from any used to manage internal servers.

Check Contents

If the domain does not have any public facing servers, this is NA.

Review the local Administrators group on public facing servers. Only the appropriate administrator groups or accounts responsible for administration of the system may be members of the group.

For public facing servers, the Domain Admins group must be replaced by a domain member server administrator group whose members are different from any used to manage internal servers.

If any domain accounts or groups used to manage internal servers are members of the local administrators group, this is a finding.

Vulnerability Number

V-43652

Documentable

False

Rule Version

AD.0013

Severity Override Guidance

If the domain does not have any public facing servers, this is NA.

Review the local Administrators group on public facing servers. Only the appropriate administrator groups or accounts responsible for administration of the system may be members of the group.

For public facing servers, the Domain Admins group must be replaced by a domain member server administrator group whose members are different from any used to manage internal servers.

If any domain accounts or groups used to manage internal servers are members of the local administrators group, this is a finding.

Check Content Reference

M

Target Key

870

Comments