2.3.8.3 Ensure 'Microsoft network client: Send unencrypted password to third-party SMB servers' is set to 'Disabled'

Information

This policy setting determines whether the SMB redirector will send plaintext passwords during authentication to third-party SMB servers that do not support password encryption.

It is recommended that you disable this policy setting unless there is a strong business case to enable it.

If this policy setting is enabled, unencrypted passwords will be allowed across the network.

The recommended state for this setting is: 'Disabled'.

Solution

To establish the recommended configuration via GP, set the following UI path to 'Disabled':

Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options\Microsoft network client: Send unencrypted password to third-party SMB servers

See Also

https://workbench.cisecurity.org/files/1941

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-5(7), CSCv6|13

Plugin: Windows

Control ID: 58d0e8ff6e626c1a72218ff3dbb7feeb3e6a46b15274a040a82d644123e73610