Network access: Do not allow anonymous enumeration of SAM accounts and shares

Information

Network access: Do not allow anonymous enumeration of SAM accounts and shares

This security setting determines whether anonymous enumeration of SAM accounts and shares is allowed.

Windows allows anonymous users to perform certain activities, such as enumerating the names of domain accounts and network shares. This is convenient, for example, when an administrator wants to grant access to users in a trusted domain that does not maintain a reciprocal trust. If you do not want to allow anonymous enumeration of SAM accounts and shares, then enable this policy.

Default: Disabled.

Solution

Policy Path: Security Options
Policy Setting Name: Network access: Do not allow anonymous enumeration of SAM accounts and shares

See Also

https://techcommunity.microsoft.com/t5/microsoft-security-baselines/windows-server-2022-security-baseline/ba-p/2724685

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(10)

Plugin: Windows

Control ID: d3c15d5a07964bc6ddd39b8d108e79632c591f3f6c7e055bab55387362a17bc3