Sensitive User Rights and Privileges

There are 13 sensitive user rights and privileges -

  1. Act as part of the operating system
  2. Backup files and directories
  3. Create a token object
  4. Debug programs
  5. Enable computer and user accounts to be trusted for delegation
  6. Generate security audits
  7. Impersonate a client after authentication
  8. Load and unload device drivers
  9. Manage auditing and security log
  10. Modify firmware environment variables
  11. Replace a process-level token
  12. Restore files and directories
  13. Take ownership of files or other objects

Note - It is in the context of auditing the use of privileges that the above user rights and privileges are considered sensitive. A description of these user rights and privileges can be found here.