CIS Microsoft Windows 10 Enterprise Release 1909 Benchmark
Remediation:
To establish the recommended configuration via GP, set the following UI path to include Guests, Local account :
Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment\Deny log on through Remote Desktop Services
Impact:
If you assign the Deny log on through Remote DesktopServices user right to other groups, you could limit the abilities of users who are assigned to specific administrative roles in your environment. Accounts that have this user right will be unable to connect to the computer through either Remote Desktop Services or Remote Assistance. You should confirm that delegated tasks will not be negatively impacted.
Default Value:
No one.
References:
1. CCE-33787-3
CIS Controls:
Version 6
16 Account Monitoring and Control Account Monitoring and Control
Version 7
16.8 Disable Any Unassociated Accounts Disable any account that cannot be associated with a business process or business owner.
110 | P a g e
Made with FlippingBook - Online magazine maker