Skip to main content
CUI

Documentation - V-243469

V-243469

Active Directory Domain Security Technical Implementation Guide

CAT II

Title

Administrators must have separate accounts specifically for managing domain workstations.

Description

<VulnDiscussion>Personnel who are system administrators must log on to domain systems only using accounts with the minimum level of authority necessary. Only system administrator accounts used exclusively to manage domain workstations may be members of an administrators group for domain workstations. A separation of administrator responsibilities helps mitigate the risk of privilege escalation resulting from credential theft attacks.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegativ...

Fix Text (Documentation Requirement)

Create the necessary documentation that identifies the members of domain workstation administrator groups. Ensure that each member has a separate unique account that can only be used to manage domain workstations. Remove any domain workstation administrator accounts from other administrator groups.

Documentation Status

Select the document that satisfies this documentation requirement. Upload new document

Cancel

Last updated: 2026-02-09 18:37:06

Linked to: USNS Montford Point eMASS Security Plan (SP)

CUI