2.3.10.1 Ensure 'Network access: Allow anonymous SID/Name translation' is set to 'Disabled'

Information

This policy setting determines whether an anonymous user can request security identifier (SID) attributes for another user, or use a SID to obtain its corresponding user name.

The recommended state for this setting is: Disabled.

Note: Certain policy settings must be configured in the Default Domain Policy to ensure they are applied globally. Exercise caution when modifying these policies, as improper changes can negatively impact the environment.

Only policies that are configured by Microsoft by default should reside in these baseline GPOs. Any additional or custom policy settings should be implemented through separate GPOs rather than modifying the default policies.

If this policy setting is enabled, a user with local access could use the well-known Administrator's SID to learn the real name of the built-in Administrator account, even if it has been renamed. That person could then use the account name to initiate a password guessing attack.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled :

Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options\Network access: Allow anonymous SID/Name translation

Impact:

None - this is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/27453

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

References: 800-53|AC-6(10), 800-53|IA-2(2)

Plugin: Windows

Control ID: 2789116eeb0e614cf7d456cb5682ac6847612c9720db4c5cd428711e36f10337