1.1.3.8.4 Set 'Microsoft network server: Server SPN target name validation level' to 'Accept if provided by client'

Information

This policy setting controls the level of validation a computer with shared folders or printers (the server) performs
on the service principal name (SPN) that is provided by the client computer when it establishes a session using the
server message block (SMB) protocol.

Solution

Make sure 'Microsoft network server: Server SPN target name validation level' is set to 'Accept if provided by client'

See Also

https://workbench.cisecurity.org/files/17

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CSCv6|3.1, CSCv6|14

Plugin: Windows

Control ID: bdafc97d7f8e649c68eba93a5b76b3813820a78567af9b896f09430e243c33dc