Skip Navigation

Required group policies

The following account policies are their values are the defaults on Windows Server before any changes due to Security Technical Implementation Guide (STIG) or Group Policy Object (GPO). Any service account that is used to replace the AtHoc application pool identities or IIS_IUSRS must be a User or Group member of the policies as shown in the table.
Policy
Values
Adjust memory quotas for a process
AtHoc application pools
Create global objects
Service
Generate security audits
AtHoc application pools
Impersonate a client after authentication
IIS_IUSRS Service 
Log on as a service
AtHoc application pools Service
Replace a process level token
AtHoc application pools