Skip Navigation

Required group policies

The following account policies and their values are the defaults on Windows Server before any changes due to Security Technical Implementation Guide (STIG) or Group Policy Object (GPO). Any service account that is used to replace the 
AtHoc
 application pool identities or IIS_IUSRS must be a user or group member of the policies as shown in the table.
Policy
Values
Adjust memory quotas for a process
AtHoc
 application pools
Create global objects
SERVICE
Generate security audits
AtHoc
 application pools
Impersonate a client after authentication
IIS_IUSRS SERVICE 
Log on as a service
AtHoc
 application pools SERVICE
Replace a process level token
AtHoc
 application pools