Sensitive User Rights and Privileges
There are 13 sensitive user rights and privileges -
- Act as part of the operating system
- Backup files and directories
- Create a token object
- Debug programs
- Enable computer and user accounts to be trusted for delegation
- Generate security audits
- Impersonate a client after authentication
- Load and unload device drivers
- Manage auditing and security log
- Modify firmware environment variables
- Replace a process-level token
- Restore files and directories
- Take ownership of files or other objects
Note - It is in the context of auditing the use of privileges that the above user rights and privileges are considered sensitive. A description of these user rights and privileges can be found here.