1.226 WN16-SO-000250

Information

Anonymous SID/Name translation must not be allowed.

GROUP ID: V-225044
RULE ID: SV-225044r991589

Allowing anonymous SID/Name translation can provide sensitive information for accessing a system. Only authorized users must be able to perform such translations.

Solution

Configure the policy value for

Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> 'Network access: Allow anonymous SID/Name translation'

to 'Disabled'.

See Also

https://workbench.cisecurity.org/benchmarks/23093

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

References: 800-53|AC-6(10), 800-53|IA-2(2)

Plugin: Windows

Control ID: a90e247cb8e5980d2937b8c6d397d60206f7a09859198274336d939d1dec70d5