Do not enumerate connected users on domain-joined computers

Information

This policy setting prevents connected users from being enumerated on domain-joined computers. If you enable this policy setting, the Logon UI will not enumerate any connected users on domain-joined computers.

If you disable or do not configure this policy setting, connected users will be enumerated on domain-joined computers.

Solution

Policy Path: System\Logon
Policy Setting Name: Do not enumerate connected users on domain-joined computers

See Also

https://blogs.technet.microsoft.com/secguide/2016/01/22/security-baseline-for-windows-10-v1511-threshold-2-final/

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(10), CSCv6|16.9

Plugin: Windows

Control ID: d0670d52bea7689897c9a907195d63d46760cd8e74d769f1d9975037901f431b