Deny log on as a batch job
Verified with Windows Security Options 25H2 — updated on July 25, 2026
Security policy
This is a Security Options policy (Windows Settings > Security Settings), applied by the security engine — not an Administrative Template (ADMX). In GPMC/gpedit it is configured under Local Policies > Security Options.
Path in the GPO console
Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment Description
This security setting determines which accounts are prevented from being able to log on as a batch job. This policy setting supersedes the Log on as a batch job policy setting if a user account is subject to both policies. Default: None.
Local security policy
SeDenyBatchLogonRight This setting has no registry key. It is stored in the local security database (LSA) and is configured through the Group Policy console or secpol.msc.