|Platform: win8.1||Date: (C)2015-10-14 (M)2017-09-28|
Log on as a service
This policy setting allows accounts to launch network services or to register a process as a service running on the system. This user right should be restricted on any computer in a high security environment, but because many applications may require this privilege, it should be carefully evaluated and tested before configuring it in an enterprise environment. On Windows Vista?based computers, no users or groups have this privilege by default.
When configuring a user right in the SCM enter a comma delimited list of accounts. Accounts can be either local or located in Active Directory, they can be groups, users, or computers.
(1) GPO: Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment!Log on as a service
(2) WMI: root\rsop\computer#RSOP_UserPrivilegeRight#AccountList#UserRight='SeServiceLogonRight' and precedence=1
|SCAP Repo OVAL Definition||oval:org.secpod.oval:def:22657|