5.20 Ensure 'Remote Procedure Call (RPC) Locator (RpcLocator)' is set to 'Disabled'

Information

In Windows 2003 and earlier versions of Windows, the Remote Procedure Call (RPC) Locator service manages the RPC name service database.

In Windows Vista and later versions of Windows, this service does not provide any functionality and is present for application compatibility.

The recommended state for this setting is: 'Disabled'.

Rationale:
This is a legacy service that has no value or purpose other than application compatibility for very old software.

It should be disabled unless there is a specific old application still in use on the system that requires it.

Solution

To establish the recommended configuration via GP, set the following UI path to: 'Disabled'.


Computer Configuration\Policies\Windows Settings\Security Settings\System Services\Remote Procedure Call (RPC) Locator

Impact:
No impact, unless an old, legacy application requires it.

See Also

https://workbench.cisecurity.org/files/1933

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7

Plugin: Windows

Control ID: 5ac50f07fd9e8e807d62b3c318a73e87deea0b6445147159bc860911c2412f3b