Domain Controller: Deny access to this computer from the network user right on DC must be configured to prevent unauth access

80a51e10-6e8d-4c26-9493-d3a41e531df0

Inappropriate granting of user rights can provide system, administrative, and other high-level capabilities.

The "Deny access to this computer from the network" user right defines the accounts that are prevented from logging on from the network.

The Guests group must be assigned this right to prevent unauthenticated access.

Remediation

To fix this configure the policy value for
Computer Configuration
|_ Windows Settings
|_ Security Settings
|_ Local Policies
|_ User Rights Assignment
|_ Deny access to this computer from the network to include the following:
- Guests Group

STIG: Server
2025: https://system32.eventsentry.com/stig/viewer/V-278168
2022: https://system32.eventsentry.com/stig/viewer/V-254421
2019: https://system32.eventsentry.com/stig/viewer/V-205667
2016: https://system32.eventsentry.com/stig/viewer/V-225000

NIST 800-53 : AC-3, AC-6, CM-6
NIST 800-171: 3.1.1, 3.1.2, 3.4.6
CMMC v2.0 L2: AC.L2-3.1.1, AC.L2-3.1.2, CM.L2-3.4.6
PCI-DSS v4.0: 2.2.1, 7.2.1
HIPAA SR : ยง164.312(a)(1)
HIPAA HICP : Practice 3 (Identity and Access Management)