42.1 (L1) Ensure 'Enable insecure guest logons' is set to 'Disabled'

Information

This policy setting determines if the SMB client will allow insecure guest logons to an SMB server.

The recommended state for this setting is: Disabled

Insecure guest logons are used by file servers to allow unauthenticated access to shared folders.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Disabled:

Lanman Workstation\Enable insecure guest logons

Impact:

The SMB client will reject insecure guest logons. This was not originally the default behavior in older versions of Windows, but Microsoft changed the default behavior starting with Windows 10 R1709:

Guest access in SMB2 disabled by default in Windows 10 and Windows Server 2016

See Also

https://workbench.cisecurity.org/benchmarks/16852

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, CSCv7|9.2

Plugin: Windows

Control ID: 371c3af9ed1e7d8f2784752d694d1cb4aeacd0d37f36c449c8c14cd647dc8939