36
Profile system performance
Member Server Default
Legacy Client
Enterprise Client
High Security Client
Administrators Not
Defined Not Defined
Administrators
The
Profile system performance
user right allows a user to monitor the performance of system
processes. Not restricting this user right presents a moderate vulnerability; an attacker with this
privilege could monitor a computer’s performance to help identify critical processes that he or she
might want to attack directly. The attacker could also determine what processes are running on the
system to identify countermeasures to avoid, such as antivirus software or an intrusion-detection
system. The default security groups for this user right are sufficient for the Legacy Client and Enterprise
Client environments. However, this user right is configured to enforce the default
Administrators
group in the High Security environment.
Replace a process level token
Member Server Default
Legacy Client
Enterprise Client
High Security Client
LOCAL SERVICE,
NETWORK SERVICE
Not Defined
Not Defined
LOCAL SERVICE,
NETWORK SERVICE
The
Replace a process level token
user right allows a parent process to replace the access token that is
associated with a child process. The default security groups for this user right are sufficient for the
Legacy Client and Enterprise Client environments. However, this user right is configured to enforce
the default
LOCAL SERVICE
and
NETWORK SERVICE
groups in the High Security environment.
Restore files and directories
Member Server Default
Legacy Client
Enterprise Client
High Security Client
Administrators and
Backup
Operators
Not Defined
Administrators Administrators
The
Restore files and directories
user right determines which users can bypass file, directory, registry,
and other persistent objects permissions when restoring backed up files and directories. It also
determines which users can set any valid security principal as the owner of an object. In an Enterprise
or High Security environment, only
Administrators
should have the right to restore files and
directories. The job of restoring files is usually carried out by administrators or another specifically
delegated security group, especially for highly sensitive servers and domain controllers.
The
Shut down the system
user right determines which locally logged on users can shut down the
operating system using the
Shut Down
command. Misuse of this user right can result in a DoS attack.
The ability to shut down domain controllers should be limited to a very small number of trusted
administrators. Even though a system shutdown requires the ability to log on to the server,
administrators should be very careful about the accounts and groups that they allow to shut down a
domain controller. In the High Security environment, only
Administrators
should be granted the
Shut
down the system
user right.
Synchronize directory service data
Member Server Default
Legacy Client
Enterprise Client
High Security Client
Not Defined
Not Defined
Not Defined
Revoke all security
groups
and accounts