Microsoft SCOM Security Technical Implementation Guide
Rules, Groups, and Values defined within the XCCDF Benchmark
-
SRG-APP-000033-NDM-000212
Group -
The Microsoft SCOM Agent Action Account must be a local system account.
The SCOM agent action account is the account agent used to perform tasks on an individual machine. By default, the action agent account is the local system account, but this can be configured to ru...Rule Medium Severity -
SRG-APP-000033-NDM-000212
Group -
The Microsoft SCOM Run As accounts must only use least access permissions.
The Microsoft SCOM privileged Run As accounts are used to execute work flow tasks on target endpoints. Run As Accounts are interactive logon sessions on a system. An attacker who has compromised on...Rule Medium Severity -
SRG-APP-000033-NDM-000212
Group -
SRG-APP-000033-NDM-000212
Group -
The Microsoft SCOM Service Accounts and Run As accounts must not be granted enterprise or domain level administrative privileges.
The Microsoft SCOM privileged Run As accounts are used to execute work flow tasks on target endpoints. A SCOM Run As account must only have the level of privileges required to perform the defined S...Rule High Severity -
SRG-APP-000033-NDM-000212
Group -
SCOM SQL Management must be configured to use least privileges.
Microsoft SCOM's SQL management requires a Run as solution because the local system account will not have the required permissions to monitor SQL. If the Run As account is created with elevated da...Rule High Severity -
SRG-APP-000516-NDM-000340
Group
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.