--- title: Synchronize directory service data (Windows 10) description: Describes the best practices, location, values, policy management, and security considerations for the Synchronize directory service data security policy setting. ms.assetid: 97b0aaa4-674f-40f4-8974-b4bfb12c232c ms.prod: W10 ms.mktglfcycl: deploy ms.sitesec: library author: brianlic-msft --- # Synchronize directory service data **Applies to** - Windows 10 **In this article** - [Reference](#reference) - [Policy management](#policy-management) - [Security considerations](#security-considerations) - [Related topics](#related-topics) Describes the best practices, location, values, policy management, and security considerations for the **Synchronize directory service data** security policy setting. ## Reference This policy setting determines which users and groups have authority to synchronize all directory service data, regardless of the protection for objects and properties. This privilege is required to use LDAP directory synchronization (dirsync) services. Domain controllers have this user right inherently because the synchronization process runs in the context of the **System** account on domain controllers. Constant: SeSyncAgentPrivilege ### Possible values - User-defined list of accounts - Not defined ### Best practices - Ensure that no accounts are assigned the **Synchronize directory service data** user right. Only domain controllers need this privilege, which they inherently have. ### Location Computer Configuration\\Windows Settings\\Security Settings\\Local Policies\\User Rights Assignment ### Default values By default this setting is not defined on domain controllers and on stand-alone servers. The following table lists the actual and effective default policy values. Default values are also listed on the policy’s property page.
Server type or GPO | Default value |
---|---|
Default Domain Policy |
Not defined |
Default Domain Controller Policy |
Not defined |
Stand-Alone Server Default Settings |
Not defined |
Domain Controller Effective Default Settings |
Enabled |
Member Server Effective Default Settings |
Disabled |
Client Computer Effective Default Settings |
Disabled |