diff --git a/windows/keep-secure/access-credential-manager-as-a-trusted-caller.md b/windows/keep-secure/access-credential-manager-as-a-trusted-caller.md index 6ffb57b6a7..f6f7140989 100644 --- a/windows/keep-secure/access-credential-manager-as-a-trusted-caller.md +++ b/windows/keep-secure/access-credential-manager-as-a-trusted-caller.md @@ -2,87 +2,84 @@ title: Access Credential Manager as a trusted caller (Windows 10) description: Describes the best practices, location, values, policy management, and security considerations for the Access Credential Manager as a trusted caller security policy setting. ms.assetid: a51820d2-ca5b-47dd-8e9b-d7008603db88 -ms.pagetype: security ms.prod: W10 ms.mktglfcycl: deploy ms.sitesec: library +ms.pagetype: security author: brianlic-msft --- + # Access Credential Manager as a trusted caller + **Applies to** - Windows 10 + Describes the best practices, location, values, policy management, and security considerations for the **Access Credential Manager as a trusted caller** security policy setting. + ## Reference + The **Access Credential Manager as a trusted caller** policy setting is used by Credential Manager during backup and restore. No accounts should have this privilege because it is assigned only to the Winlogon service. Saved credentials of users may be compromised if this privilege is given to other entities. + Constant: SeTrustedCredManAccessPrivilege + ### Possible values + - User-defined list of accounts - Not defined + ### Best practices + - Do not modify this policy setting from the default. + ### Location + Computer Configuration\\Windows Settings\\Security Settings\\Local Policies\\User Rights Assignment + ### Default values -The following table lists the actual and effective default policy values for the most recent supported versions of Windows. Default values are also listed on the policy’s property page. -
Server type or GPO | -Default value | -
---|---|
Default domain policy |
-Not defined |
-
Default domain controller policy |
-Not defined |
-
Stand-alone server default settings |
-Not defined |
-
Domain controller effective default settings |
-Not defined |
-
Member server effective default settings |
-Not defined |
-
Client computer effective default settings |
-Not defined |
-
Server type or GPO | -Default value | -
---|---|
Default domain policy |
-Not defined |
-
Default domain controller policy |
-Everyone, Administrators, Authenticated Users, Enterprise Domain Controllers, Pre-Windows 2000 Compatible Access |
-
Stand-alone server default settings |
-Everyone, Administrators, Users, Backup Operators |
-
Domain controller effective default settings |
-Everyone, Administrators, Authenticated Users, Enterprise Domain Controllers, Pre-Windows 2000 Compatible Access |
-
Member server effective default settings |
-Everyone, Administrators, Users, Backup Operators |
-
Client computer effective default settings |
-Everyone, Administrators, Users, Backup Operators |
-
Server type or Group Policy Object (GPO) | -Default value | -
---|---|
Default domain policy |
-Not defined |
-
Default domain controller policy |
-Not defined |
-
Stand-alone server default settings |
-Not applicable |
-
Domain controller effective default settings |
-Not defined |
-
Member server effective default settings |
-Not defined |
-
Client computer effective default settings |
-Not applicable |
-
Topic | -Description | -
---|---|
[Account lockout duration](account-lockout-duration.md) |
-Describes the best practices, location, values, and security considerations for the Account lockout duration security policy setting. |
-
[Account lockout threshold](account-lockout-threshold.md) |
-Describes the best practices, location, values, and security considerations for the Account lockout threshold security policy setting. |
-
[Reset account lockout counter after](reset-account-lockout-counter-after.md) |
-Describes the best practices, location, values, and security considerations for the Reset account lockout counter after security policy setting. |
-
Server type or Group Policy Object (GPO) | -Default value | -
---|---|
Default domain policy |
-0 invalid sign-in attempts |
-
Default domain controller policy |
-Not defined |
-
Stand-alone server default settings |
-0 invalid sign-in attempts |
-
Domain controller effective default settings |
-0 invalid sign-in attempts |
-
Member server effective default settings |
-0 invalid sign-in attempts |
-
Effective GPO default settings on client computers |
-0 invalid sign-in attempts |
-
Topic | -Description | -
---|---|
[Password Policy](password-policy.md) |
-An overview of password policies for Windows and links to information for each policy setting. |
-
[Account Lockout Policy](account-lockout-policy.md) |
-Describes the Account Lockout Policy settings and links to information about each policy setting. |
-
[Kerberos Policy](kerberos-policy.md) |
-Describes the Kerberos Policy settings and provides links to policy setting descriptions. |
-
Server type or GPO | -Default value | -
---|---|
Default Domain Policy |
-Not defined |
-
Default Domain Controller Policy |
-Not defined |
-
Stand-Alone Server Default Settings |
-Enabled |
-
DC Effective Default Settings |
-Enabled |
-
Member Server Effective Default Settings |
-Enabled |
-
Client Computer Effective Default Settings |
-Disabled |
-
Server type or GPO | -Default value | -
---|---|
Default Domain Policy |
-Not defined |
-
Default Domain Controller Policy |
-Not defined |
-
Stand-Alone Server Default Settings |
-Disabled |
-
DC Effective Default Settings |
-Disabled |
-
Member Server Effective Default Settings |
-Disabled |
-
Client Computer Effective Default Settings |
-Disabled |
-
Server type or GPO | -Default value | -
---|---|
Default Domain Policy |
-Not defined |
-
Default Domain Controller Policy |
-Not defined |
-
Stand-Alone Server Default Settings |
-Disabled |
-
DC Effective Default Settings |
-Disabled |
-
Member Server Effective Default Settings |
-Disabled |
-
Client Computer Effective Default Settings |
-Disabled |
-
Server type or GPO | -Default value | -
---|---|
Default Domain Policy |
-Not defined |
-
Default Domain Controller Policy |
-Not defined |
-
Stand-Alone Server Default Settings |
-Enabled |
-
DC Effective Default Settings |
-Enabled |
-
Member Server Effective Default Settings |
-Enabled |
-
Client Computer Effective Default Settings |
-Enabled |
-
Server type or GPO | -Default value | -
---|---|
Default Domain Policy |
-Not defined |
-
Default Domain Controller Policy |
-Not defined |
-
Stand-Alone Server Default Settings |
-Administrator |
-
DC Effective Default Settings |
-Administrator |
-
Member Server Effective Default Settings |
-Administrator |
-
Client Computer Effective Default Settings |
-Administrator |
-
Server type or GPO | -Default value | -
---|---|
Default Domain Policy |
-Guest |
-
Default Domain Controller Policy |
-Guest |
-
Stand-Alone Server Default Settings |
-Guest |
-
DC Effective Default Settings |
-Guest |
-
Member Server Effective Default Settings |
-Guest |
-
Client Computer Effective Default Settings |
-User-defined text |
-
Server type or GPO | -Default value | -
---|---|
Default domain policy |
-Not defined |
-
Default domain controller policy |
-Not defined |
-
Stand-alone server default settings |
-Not defined |
-
Domain controller effective default settings |
-Not defined |
-
Member server effective default settings |
-Not defined |
-
Client computer effective default settings |
-Not defined |
-