WN19-MS-000030 - Windows Server 2019 local users on domain-joined member servers must not be enumerated.

Information

The username is one part of logon credentials that could be used to gain access to a system. Preventing the enumeration of users limits this information to authorized personnel.

Solution

Configure the policy value for Computer Configuration >> Administrative Templates >> System >> Logon >> 'Enumerate local users on domain-joined computers' to 'Disabled'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_Server_2019_V3R2_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a., CAT|II, CCI|CCI-000381, Rule-ID|SV-205696r958478_rule, STIG-ID|WN19-MS-000030, STIG-Legacy|SV-103505, STIG-Legacy|V-93419, Vuln-ID|V-205696

Plugin: Windows

Control ID: f75c377013b01162b528d42a81967e8d3049a72e8da88e2c0c98c48c53fc38b4