Skip to content

Active Directory Domain Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-OS-000480

    <GroupDescription></GroupDescription>
    Group
  • User accounts with delegated authority must be removed from Windows built-in administrative groups or remove the delegated authority from the accounts.

    &lt;VulnDiscussion&gt;In AD it is possible to delegate account and other AD object ownership and administration tasks. (This is commonly done for h...
    Rule Low Severity
  • SRG-OS-000480

    <GroupDescription></GroupDescription>
    Group
  • Read-only Domain Controller (RODC) architecture and configuration must comply with directory services requirements.

    &lt;VulnDiscussion&gt;The RODC role provides a unidirectional replication method for selected information from your internal network to the DMZ. If...
    Rule Medium Severity
  • SRG-OS-000480

    <GroupDescription></GroupDescription>
    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules