1.1.3.8.4 Set 'Microsoft network server: Server SPN target name validation level' to 'Accept if provided by client'

Information

This policy setting controls the level of validation a computer with shared folders or printers (the server) performs
on the service principal name (SPN) that is provided by the client computer when it establishes a session using the
server message block (SMB) protocol.

Solution

Make sure 'Microsoft network server: Server SPN target name validation level' is set to 'Accept if provided by client'

See Also

https://workbench.cisecurity.org/files/17

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CSCv6|3.1, CSCv6|14

Plugin: Windows

Control ID: 519739074b3d6e9e4fc76a130a234f1c38f75b7a89be4dc7e60532f294e87dd3