Skip to content

Membership to the Enterprise Admins group must be restricted to accounts used only to manage the Active Directory Forest.

An XCCDF Rule

Description

<VulnDiscussion>The Enterprise Admins group is a highly privileged group. Personnel who are system administrators must log on to Active Directory systems only using accounts with the level of authority necessary. Only system administrator accounts used exclusively to manage the Active Directory Forest may be members of the Enterprise Admins group. A separation of administrator responsibilities helps mitigate the risk of privilege escalation resulting from credential theft attacks.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>

ID
SV-243466r959010_rule
Severity
High
References
Updated



Remediation - Manual Procedure

Create the necessary documentation that identifies the members of the Enterprise Admins group.  Ensure that each member has a separate unique account that can only be used to manage the Active Directory Forest.  Remove any Enterprise Admin accounts from other administrator groups.