1.1.1.2.1.18 Set 'MSS: (AutoShareServer) Enable Administrative Shares (recommended except for highly secure environments)' to 'Enabled'

Information

This entry appears as MSS: (AutoShareServer) Enable Administrative Shares (not recommended except for highly secure environments) in the SCE. For additional information, see the Microsoft Knowledge Base article How to remove administrative shares in Windows Server 2008 at http://support.microsoft.com/kb/954422/en-us. Because these built-in administrative shares are well-known and present on most Windows computers, malicious users often target them for brute-force attacks to guess passwords as well as other types of attacks.

Solution

To implement the recommended configuration state, set the following Group Policy setting to 1.

Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\MSS- (AutoShareServer) Enable Administrative Shares (recommended except for highly secure environments)

Impact- If you delete these shares you could cause problems for administrators and programs or services that rely on these shares. For example, both Microsoft Systems Management Server (SMS) and Microsoft Operations Manager require administrative shares for correct installation and operation. Also, many third-party network backup applications require administrative shares.

See Also

https://workbench.cisecurity.org/files/42

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CCE|CCE-5026-0, CSCv6|3.1

Plugin: Windows

Control ID: 39f820e8274bd38f2de4fd1a0c5afc699af03e163f4dcd5b8826d3ab2e28390b