How to collect security settings on client machines?

(imported topic written by drbyars91)

I am in need of an analysis that will pull the security settings of several User Rights Assignment policies on various client machines. On client systems I can open Administrative Tools -> Local Security Policy, and navigate to Local Policies -> User Rights Assignments to manually check which accounts are configured for ‘Allow log on locally’, ‘Bypass traverse checking’, ‘Create global objects’, etc. My desire is to pull those policy settings into a set of properties so I may audit settings across clients.

I’m currently running BF 6 but will be upgrading to 7.2 in the next few months, so at this point I’ll take a solution on either platform.

My best attempt was utilizing 'rsop user wmi ’ but I could not get at the specific security setting I desire…

(imported comment written by BenKus)

Hi drbyars,

I believe the Security Policy Manager Fixlet site has what you need… do you have that site subscribed?

Ben