Security: System must have orphaned security identifiers (SIDs) removed from user rights

2b73adc9-8ed0-41c7-8ffe-30e59930865f

Accounts or groups given rights on a system may show up as unresolved SIDs for various reasons including deletion of the accounts or groups. If the account or group objects are reanimated, there is a potential they may still have rights no longer intended. Valid domain accounts or groups may also show up as unresolved SIDs if a connection to the domain cannot be established.

Remediation

Remove any unresolved SIDs found in User Rights assignments and determined to not be for currently valid accounts or groups by removing the accounts or groups from the appropriate group policy.
Navigate to Local Computer Policy
|_ Computer Configuration
|_ Windows Settings
|_ Security Settings
|_ Local Policies
|_ User Rights Assignment

STIG: Server
2022: https://system32.eventsentry.com/stig/viewer/V-254282
2019: https://system32.eventsentry.com/stig/viewer/V-205855
2016: https://system32.eventsentry.com/stig/viewer/V-224863

Desktop
W11: https://system32.eventsentry.com/stig/viewer/V-253290
W10: https://system32.eventsentry.com/stig/viewer/V-220733

NIST 800-53 : AC-2, AC-6, CM-6
NIST 800-171: 3.1.1, 3.1.2, 3.4.6
CMMC v2.0 L2: AC.L2-3.1.1, AC.L2-3.1.2, CM.L2-3.4.6
PCI-DSS v4.0: 2.2.1, 7.2.1
HIPAA SR : ยง164.312(a)(1)
HIPAA HICP : Practice 3 (Identity and Access Management)