43
Domain member: Require strong (Windows 2000 or later) session key
Member Server
Default
Legacy Client
Enterprise Client
High Security Client
Disabled Enabled Enabled Enabled
Important:
Adm
i
nistrators will be unable to join computers running Windows 2000 with this setting
enabled to Windows NT 4.0 domains.
The
Domain member: Require strong (Windows 2000 or later) session key
security option setting
determines whether 128-bit key strength is required for encrypted secure channel data. Enabling this
setting prevents establishing a secure channel without 128-bit encryption. Disabling this setting
requires the domain member to negotiate key strength with the domain controller. Session keys used
to establish secure channel communications between domain controllers and member computers are
much stronger in Windows 2000 than they were in previous Microsoft operating systems. Therefore,
since the three security environments described in this guide contain Windows 2000 domain
controllers or later, this setting is configured to
Enabled
in all three environments.
Interactive logon: Do not display last user name
Member Server Default
Legacy Client
Enterprise Client
High Security Client
Disabled Enabled Enabled Enabled
The
Interactive logon: Do not display last user name
security option setting determines whether the
name of the last user to log on to the computer is displayed in the Windows logon screen. Enabling
this setting prevents displaying the last logged on user’s name in the
Log On to Windows
dialog box.
The
Interactive logon: Do not display last user name
setting is enabled in the baseline server policy in
the three environments defined in this guide.
Interactive logon: Do not require CTRL+ALT+DEL
Member Server Default
Legacy Client
Enterprise Client
High Security Client
Disabled Disabled Disabled Disabled
The
Interactive logon: Do not require CTRL+ALT+DEL
security option setting determines whether
pressing CTRL+ALT+DEL is required before a user can log on. Disabling this setting requires all users
to press CTRL+ALT+DEL before logging on to Windows (unless they are using a smart card for
Windows logon). This setting is set to
Disabled
in all three environments defined in this guide to
decrease the chance of an attacker being able to intercept user passwords via a Trojan horse
program.
Interactive logon: Message text for users attempting to log on
Member Server
Default
Legacy Client
Enterprise Client
High Security Client
Not Defined
This system is restricted
to authorized users.
Individuals attempting
unauthorized access
will be prosecuted. If
unauthorized, terminate
access now! Clicking
on OK indicates the
administrator’s
acceptance of the
information in the
background.
This system is restricted
to authorized users.
Individuals attempting
unauthorized access
will be prosecuted. If
unauthorized, terminate
access now! Clicking
on OK indicates the
administrator’s
acceptance of the
information in the
background.
This system is restricted
to authorized users.
Individuals attempting
unauthorized access
will be prosecuted. If
unauthorized, terminate
access now! Clicking
on OK indicates the
administrator’s
acceptance of the
information in the
background.