CIS Microsoft Windows 10 Enterprise Release 1909 Benchmark
Impact:
None - this is the default behavior. If you choose to enable this setting and are supporting Windows NT 4.0 domains, you should check if any of the named pipes are required to maintain trust relationships between the domains, and then add the pipe to the Network access: Named pipes that can be accessed anonymously list:
COMNAP: SNA session access COMNODE: SNA session access SQL\QUERY: SQL instance access
SPOOLSS: Spooler service
LLSRPC: License Logging service NETLOGON: Net Logon service
LSARPC: LSA access
SAMR: Remote access to SAM objects BROWSER: Computer Browser service
Previous to the release of Windows Server 2003 with Service Pack 1 (SP1) these named pipes were allowed anonymous access by default, but with the increased hardening in Windows Server 2003 with SP1 these pipes must be explicitly added if needed.
Default Value:
Enabled. (Anonymous access is restricted to shares and pipes listed in the Network access: Named pipes that can be accessed anonymously and Network access: Shares that can be accessed anonymously settings.)
References:
1. CCE-33563-8
243 | P a g e
Made with FlippingBook - Online magazine maker