Information
This policy setting enables the ability to rename the built-in local guest account. This account is a well-known account that is known to be targeted by threat actors.
It is recommended to rename this account to something that does not indicate its purpose, even if this account is disabled.
On Domain Controllers, since they do not have their own local accounts, this rule refers to the built-in Guest account that was established when the domain was first created.
The Guest account exists on all computers that run Windows 2000 or newer operating systems. If this account is renamed it is slightly more difficult for threat actors to guess this privileged username and password combination.
Solution
To establish the recommended configuration via GP, configure the following UI path:
Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options\Accounts: Rename guest account
Impact:
There should be little impact, because the Guest account is disabled by default.