Forum Discussion
Question Regarding Server 2022 Domain & Controller MSCT baselines
- wbaumgardtJan 29, 2024Copper Contributor
Many thanks!
- criiserApr 08, 2024Copper Contributor
AaronMargosis_Tanium - Does the MSFT replace "Default Domain Controller Policy" aswell? If not, Should MSFT be higher linked than Default Domain Controller Policy?
- AaronMargosis_TaniumApr 09, 2024Iron Contributor
criiser - the recommended policies in the Security Compliance Toolkit baselines should take precedence over the built-in default GPOs.
- katPedrazaMay 23, 2024MicrosoftNo they do not replace the default domain controller policy. They are an enhancement to them. Take a look at the implementing security baselines on the premier/unified side of the hours. none of the settings should overlap the default domain controller policy, but you can verify that by utilizing the policy analyzer too.
- AaronMargosis_TaniumMay 24, 2024Iron Contributor
katPedraza-- I think you're mistaken about that. The SCT's baselines for DCs have many settings that intentionally override the "Default Domain Controllers Policy" that ships in Windows and that is created automatically on DCs. Just as a couple of examples, the baselines' SeBackupPrivilege and SeRestorePrivilege user rights assignments intentionally override the default and grant the privilege only to Administrators.
(Also, you accidentally marked criiser's question as the "Microsoft Verified Best Answer."))