Non-Sensitive User Rights and Privileges

There are 29 non-sensitive user rights and privileges -

  1. Access Credential Manager as a trusted caller
  2. Access this computer from the network
  3. Add workstations to domain
  4. Adjust memory quotas for a process
  5. Allow log on locally
  6. Allow log on through Remote Desktop Services
  7. Bypass traverse checking
  8. Change the system time
  9. Create a pagefile
  10. Create global objects
  11. Create permanent shared objects
  12. Create symbolic links
  13. Deny access to this computer from the network
  14. Deny log on as a batch job
  15. Deny log on as a service
  16. Deny log on locally
  17. Deny log on through Remote Desktop Services
  18. Force shutdown from a remote system
  19. Increase a process working set
  20. Lock pages in memory
  21. Log on as a batch job
  22. Log on as a service
  23. Modify an object label
  24. Perform volume maintenance tasks
  25. Profile single process
  26. Profile system performance
  27. Remove computer from docking station
  28. Shut down the system
  29. Synchronize directory service data

Note - It is in the context of auditing the use of privileges that the above user rights and privileges are considered sensitive. A description of these user rights and privileges can be found here.