Bypass Traverse Checking Security

Can someone please tell me if Backup Operators and Users groups actually need to be given this right?  We follow DISA Stigs and this was a finding.  We need to know if they can be removed safely and if not, sound justification.  Thanks in advance.
LVL 2
BrianRBAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Mike KlineCommented:
It should give you some performance gains on long/deep folders, because the account can traverse the path.  Having said that I don't have stats to know how noticeable the gain would be.

Is this a CAT I, II, or III finding (for those not familiar with the DISA stigs CAT1 is most critical)

Thanks

Mike
0
BrianRBAuthor Commented:
3 I believe.  I'll confirm.  Do you see why Backup Ops and the users groups need to be added?
0
Mike KlineCommented:
I could see the case for backup ops as accounts used to backup do have to go through the entire directory.
0
Protecting & Securing Your Critical Data

Considering 93 percent of companies file for bankruptcy within 12 months of a disaster that blocked access to their data for 10 days or more, planning for the worst is just smart business. Learn how Acronis Backup integrates security at every stage

BrianRBAuthor Commented:
V-26475      STIG.DOD.MIL      WINUR-000008      Automated      CAT III      Unauthorized accounts will not have the "Bypass traverse checking" user right      "Inappropriate granting of user rights can provide system, administrative, and other high level capabilities.

Accounts with the ""Bypass traverse checking"" right can pass through folders when browsing even if they do not have the Traverse Folder access permission. They could potentially view sensitive file and folder names. They would not have additional access to the files and folders unless it is granted through permissions"      "Analyze the system using the Security Configuration and Analysis snap-in.
Expand the Security Configuration and Analysis tree view.
Navigate to Local Policies -> User Rights Assignment.

If any accounts or groups other than the following are granted the “Bypass traverse checking” right, this is a finding:

Administrators
Authenticated Users
Local Service
Network Service"
0
Adam BrownSr Solutions ArchitectCommented:
Heh. That's hilarious. It's barking about the Backup Operators group having Bypass Traverse checking, but that explanation says it's okay for the Authenticated Users group to have it. That means everyone is going to have it anyway.

Generally it's safe to remove the Bypass right from the Backup Operators group, particularly if it is already assigned to the Authenticated Users group. Again, if you're not using the Backup Operators group, this finding is mostly mitigated by that. The end result of removing the right from that group is that backup processes that use accounts in the Backup Operators group for authentication (not particularly common) will not be able to read the entire file structure if they are not granted permission to do so. This will affect those backups. It's generally a better idea to configure backup services to run using the local service or a highly secured specialized administrative account with no local or remote login rights.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
BrianRBAuthor Commented:
You guys are the best.  Thx.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2008

From novice to tech pro — start learning today.