5.0 KiB
title, description, ms.assetid, ms.pagetype, ms.prod, ms.mktglfcycl, ms.sitesec, author
title | description | ms.assetid | ms.pagetype | ms.prod | ms.mktglfcycl | ms.sitesec | author |
---|---|---|---|---|---|---|---|
Create global objects (Windows 10) | Describes the best practices, location, values, policy management, and security considerations for the Create global objects security policy setting. | 9cb6247b-44fc-4815-86f2-cb59b6f0221e | security | W10 | deploy | library | brianlic-msft |
Create global objects
Applies to
- Windows 10 Describes the best practices, location, values, policy management, and security considerations for the Create global objects security policy setting.
Reference
This policy setting determines which users can create global objects that are available to all sessions. Users can still create objects that are specific to their own session if they do not have this user right. A global object is an object that is created to be used by any number of processes or threads, even those not started within the user’s session. Remote Desktop Services uses global objects in its processes to facilitate connections and access. Constant: SeCreateGlobalPrivilege
Possible values
- User-defined list of accounts
- Default accounts listed below
Best practices
- Do not assign any user accounts this right.
Location
Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment
Default values
By default, members of the Administrators group have this right, as do Local Service and Network Service accounts on the supported versions of Windows. Service is included for backwards compatibility with earlier versions of Windows. The following table lists the actual and effective default policy values. Default values are also listed on the policy’s property page.
Server type or GPO | Default value |
---|---|
Default Domain Policy |
Not Defined |
Default Domain Controller Policy |
Administrators Local Service Network Service Service |
Stand-Alone Server Default Settings |
Administrators Local Service Network Service Service |
Domain Controller Effective Default Settings |
Administrators Local Service Network Service Service |
Member Server Effective Default Settings |
Administrators Local Service Network Service Service |
Client Computer Effective Default Settings |
Administrators Local Service Network Service Service |