Check: AD.3058_2008_R2
Win2k8 R2 Audit:
AD.3058_2008_R2
(in version v1 r8)
Title
The Server Operators group must have the ability to schedule jobs by means of the AT command disabled. (Cat II impact)
Discussion
This policy controls the ability of members of the local Server Operators group to schedule AT jobs. If disabled, only administrators can schedule jobs that use AT commands. Unlike Scheduled Tasks which require you to specify the credential under which the task will run, AT jobs run under the authority of whatever account the AT service runs (SYSTEM by default). Non administrators who can schedule AT commands, thus have a means to elevate their privileges. Although this setting is disabled, Server Operators will still be able to schedule jobs using Task Scheduler.
Check Content
Fix Text
Set the value for “Domain Controller: Allow server operators to schedule tasks” to “Disabled”. The policy referenced configures the following registry value: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \System\CurrentControlSet\Control\LSA\ Value Name: SubmitControl Value Type: REG_DWORD Value: 0
Additional Identifiers
Rule ID: SV-36168r1_rule
Vulnerability ID: V-2373
Group Title: Task Scheduling - Server Operators
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |