en-US windows-security computer

Create permanent shared objects

Verified with Windows Security Options 25H2 — updated on July 25, 2026

Security policy

This is a Security Options policy (Windows Settings > Security Settings), applied by the security engine — not an Administrative Template (ADMX). In GPMC/gpedit it is configured under Local Policies > Security Options.

Path in the GPO console

Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment

Description

This user right determines which accounts can be used by processes to create a directory object using the object manager. This user right is used internally by the operating system and is useful to kernel-mode components that extend the object namespace. Because components that are running in kernel mode already have this user right assigned to them, it is not necessary to specifically assign it. Default: None.

Local security policy

SeCreatePermanentPrivilege

This setting has no registry key. It is stored in the local security database (LSA) and is configured through the Group Policy console or secpol.msc.

Embed this policy on your site

What to embed
Theme

Adds one script line: the theme follows your site’s appearance and the height fits the content. If your site blocks scripts, the embed follows the visitor’s system theme.

Preview