18.6.8.1 (L1) Ensure 'Audit insecure guest logon' is set to 'Enabled'

Information

This policy determines whether the Server Message Block (SMB) client will log events when the client is logged on as guest account.

Enabling this will create event log entries in Applications and Service Logs\Microsoft\Windows\SMBClient\Security with Event IDs 3023 31017 31018 and 31022

The recommended state for this setting is: Enabled

Insecure guest logons can be used by file servers to allow unauthenticated access to shared folders.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\Network\Lanman Workstation\Audit insecure guest logon

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template LanmanWorkstation.admx/adml that is included with the Microsoft Windows 11 Release 24H2 Administrative Templates (or newer).

Impact:

All insecure guest logons will be logged as an event.

See Also

https://workbench.cisecurity.org/benchmarks/21318