Non-Sensitive User Rights and Privileges
There are 29 non-sensitive user rights and privileges -
- Access Credential Manager as a trusted caller
- Access this computer from the network
- Add workstations to domain
- Adjust memory quotas for a process
- Allow log on locally
- Allow log on through Remote Desktop Services
- Bypass traverse checking
- Change the system time
- Create a pagefile
- Create global objects
- Create permanent shared objects
- Create symbolic links
- Deny access to this computer from the network
- Deny log on as a batch job
- Deny log on as a service
- Deny log on locally
- Deny log on through Remote Desktop Services
- Force shutdown from a remote system
- Increase a process working set
- Lock pages in memory
- Log on as a batch job
- Log on as a service
- Modify an object label
- Perform volume maintenance tasks
- Profile single process
- Profile system performance
- Remove computer from docking station
- Shut down the system
- Synchronize directory service data
Note - It is in the context of auditing the use of privileges that the above user rights and privileges are considered sensitive. A description of these user rights and privileges can be found here.