Information
This policy setting determines which communication sessions, or pipes, will have attributes and permissions that allow anonymous access.
The recommended state for this setting is: <blank> (i.e. None), or (when the legacy
Computer Browser
service is enabled) BROWSER
Note: A Member Server that holds the
Remote Desktop Services
Role with
Remote Desktop Licensing
Role Service will require a special exception to this recommendation, to allow the HydraLSPipe and TermServLicensing Named Pipes to be accessed anonymously.
Limiting named pipes that can be accessed anonymously will reduce the attack surface of the system.
Solution
To establish the recommended configuration via GP, configure the following UI path:
Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options\Network access: Named Pipes that can be accessed anonymously
Impact:
Null session access over named pipes will be disabled unless they are included, and applications that rely on this feature or on unauthenticated access to named pipes will no longer function. The BROWSER named pipe may need to be added to this list if the
Computer Browser
service is needed for supporting legacy components. The
Computer Browser
service is disabled by default.