30
Adjust Memory Quotas For A Process
Member Server Default
Legacy Client
Enterprise Client
High Security Client
Administrators,
NETWORK SERVICE,
LOCAL SERVICE
Not Defined
Not Defined Administrators,
NETWORK SERVICE,
LOCAL SERVICE
The
Adjust memory quotas for a process
user right allows a user to adjust the maximum memory that
is available to a process. This privilege is useful for system tuning, but it can be abused. In the wrong
hands, this user right can be used to launch a DoS attack. The default security groups for this user
right are sufficient for the
Legacy Client and Enterprise Client
environments. However, this user right is
configured to enforce
Administrators, NETWORK SERVICE, LOCAL SERVICE
value only in the
High
Security
environment.
Allow Log On Locally
Member Server Default
Legacy Client
Enterprise Client
High Security Client
Administrators, Backup
Operators, Power
Users, and Users
Administrators, Backup
Operators, Power
Users
Administrators, Backup
Operators, Power
Users
Administrators, Backup
Operators, Power
Users
The
Allow log on locally
user right determines which users can interactively log on to the specified
computer. Logons initiated by pressing the CTRL+ALT+DEL key-combination on the keyboard require
the user to have this logon right. Any account with this user right could be used to log on to the local
console of the computer. Restricting this privilege to legitimate users who need to be able to log on to
the system prevents unauthorized users from elevating their privileges or from introducing viruses into
the computing environment.
Allow Log On Through Terminal Services
Member Server Default
Legacy Client
Enterprise Client
High Security Client
Administrators and
Remote Desktop Users
Administrators and
Remote Desktop Users
Administrators and
Remote Desktop Users
Administrators
The
Allow log on through Terminal Services
user right determines which users or groups have
permission to log on as a Terminal Services client. The default security groups for this user right are
sufficient for the Legacy Client and Enterprise Client environments. However, in the High Security
environment, only
Administrators
should have the ability to log on as a Terminal Services client.
Change The System Time
Member Server Default
Legacy Client
Enterprise Client
High Security Client
Administrators and
Power Users
Not Defined
Not Defined Administrators
The
Change the system time
user right determines which users and groups can change the time and
date on the internal clock of the computer. Users with this user right can affect the appearance of
event logs because event logs will reflect the new time, not the actual time that the events occurred.
Limit the
Change the system time
privilege to users with a legitimate need to be able to change the
time, such as members of the IT department. Discrepancies between the time on the local computer
and on the domain controllers may cause problems for the Kerberos authentication protocol, which