1.2.4.3.3 Set 'Enumerate administrator accounts on elevation' to 'Disabled'

Information

This control defines whether a user is allowed to see all administrator accounts displayed when a user attempts to
elevate a running application.

Solution

Make sure 'Enumerate administrator accounts on elevation' is set to 'Disabled'

See Also

https://workbench.cisecurity.org/files/17

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(10), CSCv6|16

Plugin: Windows

Control ID: 8143f297efd15b8f1e0ffbddb66ebf3e0ad357e32e3408c386a09c2e2d8dd775