CIS Microsoft Windows 10 Enterprise Release 1909 Benchmark

Impact:

None - this is the default behavior. If you choose to enable this setting and are supporting Windows NT 4.0 domains, you should check if any of the named pipes are required to maintain trust relationships between the domains, and then add the pipe to the Network access: Named pipes that can be accessed anonymously list:

COMNAP: SNA session access COMNODE: SNA session access SQL\QUERY: SQL instance access

     

SPOOLSS: Spooler service

LLSRPC: License Logging service NETLOGON: Net Logon service

LSARPC: LSA access

 SAMR: Remote access to SAM objects  BROWSER: Computer Browser service

Previous to the release of Windows Server 2003 with Service Pack 1 (SP1) these named pipes were allowed anonymous access by default, but with the increased hardening in Windows Server 2003 with SP1 these pipes must be explicitly added if needed.

Default Value:

Enabled. (Anonymous access is restricted to shares and pipes listed in the Network access: Named pipes that can be accessed anonymously and Network access: Shares that can be accessed anonymously settings.)

References:

1. CCE-33563-8

243 | P a g e

Made with FlippingBook - Online magazine maker