Information
This policy setting ensures that directory data outside of the root DSE of a non-public directory is configured to prevent anonymous access.
To the extent that anonymous access to directory data (outside the root DSE) is permitted, read access control of the data is effectively disabled. If other means of controlling access (such as network restrictions) are compromised, there may be nothing else to protect the confidentiality of sensitive directory data.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
Configure directory data outside the root DSE) of a non-public directory to prevent anonymous access.
For Active Directory, there are multiple configuration items that could enable anonymous access.
Changing the access permissions on the domain naming context object (from the secure defaults) could enable anonymous access. If the check procedures indicate this is the cause, the process that was used to change the permissions should be reversed. This could have been through the Windows Support Tools ADSI Edit console (adsiedit.msc).
The dsHeuristics option is used. This is addressed in check V-8555 in the Active Directory Forest STIG.
Impact:
Anonymous access to directory data outside the root DSE will not be permitted.