WN16-SO-000260 - Anonymous enumeration of Security Account Manager (SAM) accounts must not be allowed.

Information

Anonymous enumeration of SAM accounts allows anonymous logon users (null session connections) to list all accounts names, thus providing a list of potential points to attack the system.

Solution

Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> 'Network access: Do not allow anonymous enumeration of SAM accounts' to 'Enabled'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_Server_2016_V2R10_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|I, CCI|CCI-000366, Rule-ID|SV-225045r991589_rule, STIG-ID|WN16-SO-000260, STIG-Legacy|SV-88331, STIG-Legacy|V-73667, Vuln-ID|V-225045

Plugin: Windows

Control ID: 4ea7501656c412b47788cb02e06e170e04993d51e4b3ff20fd957414032f9039