Skip to content

Active Directory Domain Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-OS-000480

    <GroupDescription></GroupDescription>
    Group
  • SRG-OS-000480

    <GroupDescription></GroupDescription>
    Group
  • Membership to the Enterprise Admins group must be restricted to accounts used only to manage the Active Directory Forest.

    &lt;VulnDiscussion&gt;The Enterprise Admins group is a highly privileged group. Personnel who are system administrators must log on to Active Dire...
    Rule High Severity
  • SRG-OS-000480

    <GroupDescription></GroupDescription>
    Group
  • Membership to the Domain Admins group must be restricted to accounts used only to manage the Active Directory domain and domain controllers.

    &lt;VulnDiscussion&gt;The Domain Admins group is a highly privileged group. Personnel who are system administrators must log on to Active Director...
    Rule High Severity
  • SRG-OS-000480

    <GroupDescription></GroupDescription>
    Group
  • Administrators must have separate accounts specifically for managing domain member servers.

    &lt;VulnDiscussion&gt;Personnel who are system administrators must log on to domain systems only using accounts with the minimum level of authority...
    Rule Medium Severity
  • SRG-OS-000480

    <GroupDescription></GroupDescription>
    Group
  • Administrators must have separate accounts specifically for managing domain workstations.

    &lt;VulnDiscussion&gt;Personnel who are system administrators must log on to domain systems only using accounts with the minimum level of authority...
    Rule Medium Severity
  • SRG-OS-000480

    <GroupDescription></GroupDescription>
    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules