Skip Navigation

Required group policies

The following account policies and their values are the defaults on Windows Server before any changes are made due to Security Technical Implementation Guide (STIG) or Group Policy Object (GPO.) Any service account that is used to replace the
AtHoc
application pool identities or IIS_IUSRS must be a user or group member of the policies as shown in the following table.
Policy
Values
Adjust memory quotas for a process
AtHoc
application pools
Create global objects
SERVICE
Generate security audits
AtHoc
application pools
Impersonate a client after authentication
IIS_IUSRS SERVICE
Log on as a service
AtHoc
application pools SERVICE
Replace a process level token
AtHoc
application pools