Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Questions about baselines #7

Open
StefanSa opened this issue Dec 18, 2019 · 3 comments
Open

Questions about baselines #7

StefanSa opened this issue Dec 18, 2019 · 3 comments

Comments

@StefanSa
Copy link

Hi rich,
in the baseline Excel sheet you write e.g. following.

Ensure 'Generate security audits' is set to 'LOCAL SERVICE, NETWORK SERVICE' (Scored)

Your remark:

Note: A Member Server that holds the Web Server (IIS) Role with Web Server Role Service will require a special exception to this recommendation, to allow IIS application pool(s) to be granted this user right.

My question about this:
Where and how do i best make these special exceptions for this PAW AD GPO structure?
can you please show an example in such a case?

Thanks again for your help
regards
Stefan

@utsecnet
Copy link
Owner

Of course! Group Policies are applied to OU's in AD. Each GPO you apply to the same container immediately overwrites any conflicting previously-applied policy via inheritance. You can change the inheritance order in GPMC by clicking the container in question and selecting the "Group Policy Inheritance" tab at the top right. So, say you have a GPO that sets ALL of your audit policy settings that you apply to your Computers OU, with a security filtering of Tier1-servers. You may also have another GPO that sets ONLY the conflicting audit policy settings (generate security audits) applied to the same Computers OU, but security filter on your IIS-servers group. Then in the GP inheritance tab, you would have your IIS-Servers policy have higher precedence than your Tier1-Servers GPO by moving it above the Tier1-Servers OU.

Hope that helps.

@StefanSa
Copy link
Author

Rich,
thanks for the exact explanation and your time, but now i have the following problem.

Example:
User Rights Assignment -> Generate security audits.
For an IIS, all "IIS APPPools" must be added.
However, i cannot add local groups directly to a GPO if i edit them on the DC.
What am i doing wrong or how do i add these "IIS APPPools"
or how do i best make an exception for an IIS / MSSQL?

@utsecnet
Copy link
Owner

utsecnet commented Dec 19, 2019 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants