--- title: Create global objects (Windows 10) description: Describes the best practices, location, values, policy management, and security considerations for the Create global objects security policy setting. ms.assetid: 9cb6247b-44fc-4815-86f2-cb59b6f0221e ms.prod: W10 ms.mktglfcycl: deploy ms.sitesec: library author: brianlic-msft --- # Create global objects **Applies to** - Windows 10 **In this article** - [Reference](#reference) - [Policy management](#policy-management) - [Security considerations](#security-considerations) - [Related topics](#related-topics) Describes the best practices, location, values, policy management, and security considerations for the **Create global objects** security policy setting. ## Reference This policy setting determines which users can create global objects that are available to all sessions. Users can still create objects that are specific to their own session if they do not have this user right. A global object is an object that is created to be used by any number of processes or threads, even those not started within the user’s session. Remote Desktop Services uses global objects in its processes to facilitate connections and access. Constant: SeCreateGlobalPrivilege ### Possible values - User-defined list of accounts - Default accounts listed below ### Best practices - Do not assign any user accounts this right. ### Location Computer Configuration\\Windows Settings\\Security Settings\\Local Policies\\User Rights Assignment ### Default values By default, members of the Administrators group have this right, as do Local Service and Network Service accounts on the supported versions of Windows. Service is included for backwards compatibility with earlier versions of Windows. The following table lists the actual and effective default policy values. Default values are also listed on the policy’s property page.
Server type or GPO | Default value |
---|---|
Default Domain Policy |
Not Defined |
Default Domain Controller Policy |
Administrators Local Service Network Service Service |
Stand-Alone Server Default Settings |
Administrators Local Service Network Service Service |
Domain Controller Effective Default Settings |
Administrators Local Service Network Service Service |
Member Server Effective Default Settings |
Administrators Local Service Network Service Service |
Client Computer Effective Default Settings |
Administrators Local Service Network Service Service |