Specify the list of Users to 'Manage auditing and security log'
|ID: oval:org.secpod.oval:def:36548||Date: (C)2016-08-05 (M)2017-10-13|
|Class: COMPLIANCE||Family: windows|
This policy setting determines which users can change the auditing options for files and directories and clear the Security log.
When configuring a user right in the SCM enter a comma delimited list of accounts. Accounts can be either local or located in Active Directory, they can be groups, users, or computers.
Ensure that only the local Administrators group has the Manage auditing and security log user right.
None. This is the default configuration.
(1) GPO: Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment\Manage auditing and security log
(2) REG: ###
(3) WMI: root\rsop\computer
UserRight='SeSecurityPrivilege' and precedence=1
|Microsoft Windows 10|