29
Access This Computer From The Network
Member Server Default
Legacy Client
Enterprise Client
High Security Client
Administrators, Backup
Operators, Everyone,
Power Users, and Users
Not Defined
Not Defined Administrators,
Authenticated Users
Important:
Although in Windows Server 2003 permissions granted to the
Everyone
security group no
longer grant access to anonymous users, guest groups and accounts can still be granted access
through the
Everyone
security group. For this reason, this guide recommends removing the
Everyone
security group from the
Access this computer from the network
user right in the High Security
environment to further guard from attacks targeting guest access to the domain. However,
administrators still need to check and verify that existing 3
rd
party applications within their network
environment are functioning properly once this policy is set, especially with their NAS multi-protocol
applications.
The
Access this computer from the network
user right determines which users and groups are allowed
to connect to the computer over the network. This user right is required by a number of network
protocols including server message block (SMB)-based protocols, network basic input/output system
(NetBIOS), Common Internet File System (CIFS), Hypertext Transfer Protocol (HTTP).and Component
Object Model Plus (COM+).
Act As Part Of The Operating System
Member Server Default
Legacy Client
Enterprise Client
High Security Client
Not Defined
Not Defined
Not Defined
Revoke all security
groups and accounts
Important:
Since various 3
rd
party applications require and impersonate user and group accounts,
administrators should verify that these applications within their NAS system are still functioning
properly once this policy is set.
The
Act as part of the operating system
user right allows a process to assume the identity of any user
and thus gain access to the resources that the user is authorized to access. Typically, only low-level
authentication services require this privilege. There are no security groups defined by default;
therefore, this user right is sufficient for the Legacy Client and Enterprise Client environments.
However, in the High Security environment, configure this setting to
Revoke all security groups and
accounts.
Add Workstation To Domain
Member Server Default
Legacy Client
Enterprise Client
High Security Client
Not Defined
Not Defined
Not Defined
Administrators
The
Add workstations to domain
user right allows the user to add a computer to a specific domain.
For the privilege to take effect, it must be assigned to the user as part of the Default Domain
Controllers Policy for the domain. There are no security groups defined by default; therefore, this user
right is sufficient for the Legacy Client and Enterprise Client environments. However, this setting is
configured to grant only the
Administrators
group this user right in the High Security environment.