1.228 WN19-SO-000210

Information

Windows Server 2019 must not allow anonymous SID/Name translation.

GROUP ID:V-205913
RULE ID:SV-205913r991589

Allowing anonymous SID/Name translation can provide sensitive information for accessing a system. Only authorized users must be able to perform such translations.

Solution

Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> 'Network access: Allow anonymous SID/Name translation' to 'Disabled'.

See Also

https://workbench.cisecurity.org/benchmarks/22176

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

References: 800-53|AC-6(10), 800-53|IA-2(2)

Plugin: Windows

Control ID: 17898a1bfc8f21bf219352dd6b9a8d1ceac26ff148a3310083c5001d2ee5ce88