[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248678

 
 

909

 
 

195426

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Enumerate administrator accounts on elevation

ID: oval:org.secpod.oval:def:83600Date: (C)2022-09-02   (M)2023-05-09
Class: COMPLIANCEFamily: windows




This policy setting controls whether administrator accounts are displayed when a user attempts to elevate a running application. By default, administrator accounts are not displayed when the user attempts to elevate a running application. If you enable this policy setting, all local administrator accounts on the PC will be displayed so the user can choose one and enter the correct password. If you disable this policy setting, users will always be required to type a user name and password to elevate. Counter Measure: Enable this policy. Potential Impact: If you enable this policy setting, all local administrator accounts on the machine will be displayed so the user can choose one and enter the correct password. If you disable this policy setting, users will be required to always type in a username and password to elevate. Fix: (1) GPO: Computer Configuration\Administrative Templates\Windows Components\Credential User Interface\Enumerate administrator accounts on elevation (2) REG: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\CredUI!EnumerateAdministrators

Platform:
Microsoft Windows Server 2016
Reference:
CCE-47646-5
CPE    1
cpe:/o:microsoft:windows_server_2016
CCE    1
CCE-47646-5
XCCDF    1
xccdf_org.secpod_benchmark_general_Windows_Server_2016

© SecPod Technologies