Securing Windows Server 2003 tasks
Cisco TMS Secure Server Configuration Guide 13.0
Page 22 of 34
Policy
Security Setting
Act as part of the operating system
(SeTcbPrivilege)
Add workstations to domain
(SeMachineAccountPrivilege)
Adjust memory quotas for a process
(SeIncreaseQuotaPrivilege)
Administrators, LOCAL SERVICE, NETWORK SERVICE,
IWAM_<machinename>,
SQLServer2005MSSQLUser$ComputerName$InstanceName
Allow logon locally
(SeInteractiveLogonRight)
Administrators
Allow logon Through Terminal
Services
(SeRemoteInteractiveLogonRight)
Administrators
Back up files and directories
(SeBackupPrivilege)
Administrators
Bypass traverse checking
(SeChangeNotifyPrivilege)
Administrators, Authenticated Users,
SQLServer2005MSSQLUser$ComputerName$InstanceName
Change the system time
(SeSystemTimePrivilege)
Administrators
Create a pagefile
(SeCreatePagefilePrivilege)
Administrators
Create a token object
(SeCreateTokenPrivilege)
Create global objects
(SeCreateGlobalPrivilege)
Administrators, SERVICE
Create permanent shared objects
(SeCreatePermanentPrivilege)
Debug programs
(SeDebugPrivilege)
Deny access to this computer from
the network
(SeDenyNetworkLogonRight)
Support_388945a0, ANONYMOUS LOGON,
Deny logon as a batch job
(SeDenyBatchLogonRight)
SUPPORT_388945a0
Deny logon as a service
(SeDenyBatchLogonRight)
Deny logon locally
(SeDenyInteractiveLogonRight)
Guests, SUPPORT_388945a0, ASPNET, tmsserviceuser,
sqlserviceuser
Deny log on Through Terminal
Services
(SeDenyRemoteInteractiveLogon
Right)
Guests, SUPPORT_388945a0, ASPNET, tmsserviceuser,
sqlserviceuser
Enable computer and user accounts
to be trusted for delegation
(SeEnableDelegationPrivilege)
Administrators
Force shutdown from a remote
system
(SeRemoteShutdownPrivilege)