1.1.1.2.1.68 Set 'Network access: Allow anonymous SID/Name translation' to 'Disabled'

Information

This policy setting determines whether an anonymous user can request security identifier (SID) attributes for another user, or use a SID to obtain its corresponding user name. Disable this policy setting to prevent unauthenticated users from obtaining user names that are associated with their respective SIDs. If this policy setting is enabled, a user with local access could use the well-known Administrator's SID to learn the real name of the built-in Administrator account, even if it has been renamed. That person could then use the account name to initiate a password guessing attack.

Solution

To implement the recommended configuration state, set the following Group Policy setting to False.

Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\Network access- Allow anonymous SID/Name translation

Impact- Disabled is the default configuration for this policy setting on member computers; therefore it will have no impact on them. If you disable this policy setting on domain controllers, legacy computers may be unable to communicate with other computers in the domain. For example, the following computers may not work- . Windows NT 4.0based Remote Access Service servers. . Microsoft SQL Servers that run on Windows NT 3.xbased or Windows NT 4.0based computers. . Remote Access Service or Microsoft SQL servers that run on Windows 2000based computers and are located in Windows NT 3.x domains or Windows NT 4.0 domains.

See Also

https://workbench.cisecurity.org/files/42

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

References: 800-53|AC-6(10), 800-53|IA-2(2), CCE|CCE-3402-5

Plugin: Windows

Control ID: 943185111efd16f922458242814646cf891405751e959186e0f5ae0bf5bed71a