Inappropriate user with Add Workstations to Domain privilege |
---|
Risk Level: | High | Check or Attack Name: Add Workstation Privilege |
---|---|---|
Platforms: | Windows NT | |
Description: | A user has been detected with the Add Workstations to Domain privilege. This right allows users to add computers to the domain database in Server Manager, and is normally only granted to Domain Administrators. |
|
Remedy: | In Windows NT Workstation, check advanced user rights for Add workstations to domain. Remove any names that are disallowed by your security policy. To audit and revoke this privilege, follow these steps:
In Windows NT Server, check user rights for Add workstations to domain. Remove any names that are disallowed by your security policy. To audit and revoke this privilege, follow these steps:
|
|
References: | Microsoft Knowledge Base Article Q139365, Capabilities of the "Add Workstations To Domain" Right, http://support.microsoft.com/support/kb/articles/q139/3/65.asp |
Know Your Risks |