Lock pages in memoryID: oval:org.secpod.oval:def:36512 | Date: (C)2016-08-05 (M)2023-12-13 |
Class: COMPLIANCE | Family: windows |
This security setting determines which accounts can use a process to keep data in physical memory, which prevents the system from paging the data to virtual memory on disk. Exercising this privilege could significantly affect system performance by decreasing the amount of available random access memory (RAM).
Default: None.
Counter Measure:
Do not assign the Lock pages in memory user right to any accounts.
Potential Impact:
None. This is the default configuration.
Fix:
(1) GPO: Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment\Lock pages in memory
(2) REG: ###
(3) WMI: root\rsop\computer#RSOP_UserPrivilegeRight#AccountList#UserRight=;amp;apos;SeLockMemoryPrivilege;amp;apos; and precedence=1
Platform: |
Microsoft Windows 10 |