4.3 KiB
title, description, ms.assetid, ms.pagetype, ms.prod, ms.mktglfcycl, ms.sitesec, author
title | description | ms.assetid | ms.pagetype | ms.prod | ms.mktglfcycl | ms.sitesec | author |
---|---|---|---|---|---|---|---|
Synchronize directory service data (Windows 10) | Describes the best practices, location, values, policy management, and security considerations for the Synchronize directory service data security policy setting. | 97b0aaa4-674f-40f4-8974-b4bfb12c232c | security | W10 | deploy | library | brianlic-msft |
Synchronize directory service data
Applies to
- Windows 10 Describes the best practices, location, values, policy management, and security considerations for the Synchronize directory service data security policy setting.
Reference
This policy setting determines which users and groups have authority to synchronize all directory service data, regardless of the protection for objects and properties. This privilege is required to use LDAP directory synchronization (dirsync) services. Domain controllers have this user right inherently because the synchronization process runs in the context of the System account on domain controllers. Constant: SeSyncAgentPrivilege
Possible values
- User-defined list of accounts
- Not defined
Best practices
- Ensure that no accounts are assigned the Synchronize directory service data user right. Only domain controllers need this privilege, which they inherently have.
Location
Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment
Default values
By default this setting is not defined on domain controllers and on stand-alone servers. The following table lists the actual and effective default policy values. Default values are also listed on the policy’s property page.
Server type or GPO | Default value |
---|---|
Default Domain Policy |
Not defined |
Default Domain Controller Policy |
Not defined |
Stand-Alone Server Default Settings |
Not defined |
Domain Controller Effective Default Settings |
Enabled |
Member Server Effective Default Settings |
Disabled |
Client Computer Effective Default Settings |
Disabled |