WN19-MS-000030 - Windows Server 2019 local users on domain-joined member servers must not be enumerated.

Information

The username is one part of logon credentials that could be used to gain access to a system. Preventing the enumeration of users limits this information to authorized personnel.

Solution

Configure the policy value for Computer Configuration >> Administrative Templates >> System >> Logon >> 'Enumerate local users on domain-joined computers' to 'Disabled'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_Server_2019_V2R3_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(10), CAT|II, CCI|CCI-000381, CSCv6|16.9, Rule-ID|SV-205696r569188_rule, STIG-ID|WN19-MS-000030, STIG-Legacy|SV-103505, STIG-Legacy|V-93419, Vuln-ID|V-205696

Plugin: Windows

Control ID: 59e530a7292ad38ae9b57838cc8896dea9226f495d5ab080e4a1e249e6e05549