1.132 WN10-CC-000165

Information

Unauthenticated RPC clients must be restricted from connecting to the RPC server.

GROUP ID: V-220824RULE ID: SV-220824r971545

Configuring RPC to restrict unauthenticated RPC clients from connecting to the RPC server will prevent anonymous connections.

Solution

Configure the policy value for

Computer Configuration >> Administrative Templates >> System >> Remote Procedure Call >> 'Restrict Unauthenticated RPC clients'

to 'Enabled' and 'Authenticated'.

See Also

https://workbench.cisecurity.org/benchmarks/23869