

You can specify one or more user groups within the CDATA tag by using 0xF000 as the delimiter/separator. If you use Intune custom profiles to assign UserRights policies, you must use the CDATA tag ( ) to wrap the data fields. Grant a user right to multiple groups (Authenticated Users, Administrators) via strings: Authenticated Users AdministratorsĮmpty input indicates that there are no users configured to have that user right: Grant a user right to multiple groups (Administrators, Authenticated Users) via a mix of SID and Strings: *S-1-5-32-544 Authenticated Users Grant a user right to multiple groups (Administrators, Authenticated Users) via SID: *S-1-5-32-544 *S-1-5-11 Grant a user right to Administrators group via SID: *S-1-5-32-544 The encoded 0xF000 is the standard delimiter/separator.

Device/Vendor/MSFT/Policy/Config/UserRights/BackupFilesAndDirectoriesĪuthenticated Users Administrators Here's an example for setting the user right BackupFilesAndDirectories for Administrators and Authenticated Users groups. Some user rights allow things like AccessFromNetwork, while others disallow things, like DenyAccessFromNetwork. For more information, see Well-known SID structures.Įven though strings are supported for well-known accounts and groups, it's better to use SIDs, because strings are localized for different languages. Values can be represented as Security Identifiers (SID) or strings. The name of the policy defines the user right in question, and the values are always users or groups. User rights are assigned for user accounts or groups. These policies are subject to change and may have dependencies on other features or services in preview.
#TIME CLOCK PLUS COPY USER PROFILES WINDOWS#
This CSP contains preview policies that are under development and only applicable for Windows Insider Preview builds.
