WinSecWiki > Security Settings > Local Policies > Security Options > Domain Controller > Allow server operators to schedule tasks

Domain Controller: Allow server operators to schedule tasks

This policy does not affect Scheduled Tasks (aka Task Scheduler) under Accessories on the Start Menu; it only affects your ability to schedule jobs by means of the AT command.

Unlike Scheduled Tasks which require you to specify the credential under which the task will run, AT jobs run under the authority of whatever account the AT service runs which is SYSTEM by default. Non administrators who can schedule AT commands thus have a means to elevate their privileges. This policy controls whether members of the local Server Operators group can schedule AT jobs. If disabled, only administrators can.

Bottom line

I suggest disabling this policy. Server Operators will still be able to schedule jobs using Task Scheduler without being able to elevate their privileges.

Back to top

 

Upcoming Webinars
    Additional Resources