48
passwords, credentials, or Microsoft .NET Passports for later use after gaining domain authentication.
This setting is configured to
Enabled
in the three security environments defined in this guide.
Note:
When configuring this security setting, changes will not take effect until Windows is restarted.
Network access: Let Everyone permissions apply to anonymous users
Member Server Default
Legacy Client
Enterprise Client
High Security Client
Disabled Disabled Disabled Disabled
Important:
Domains with this setting will be unable to establish or maintain trusts with Windows NT
4.0 domains or domain controllers. This setting should be set to
Enabled
for all HP NAS server
systems requiring anonymous user access within multi-protocol network environments.
The
Network access: Let Everyone permissions apply to anonymous users
security option setting
determines what additional permissions are granted for anonymous connections to the computer.
Enabling this setting allows anonymous Windows users to perform certain activities, such as
enumerating the names of domain accounts and network shares. An unauthorized user could
anonymously list account names and shared resources and use the information to guess passwords or
perform social engineering attacks. Therefore, this setting is configured to
Disabled
in the three
environments defined in this guide.
Network access: Named Pipes that can be accessed anonymously
Member Server Default
Legacy Client
Enterprise Client
High Security Client
Not Defined
None
None
None
Important:
If this setting is enabled, only add the named pipes that are needed to support the
applications within the company’s network environment. As with all recommended settings in this
guide, this setting should be carefully tested in production environments.
The
Network access: Named Pipes that can be accessed anonymously
security option setting
determines which communication sessions (named pipes) will have attributes and permissions that
allow anonymous access. The value for the
Network access: Named Pipes that can be accessed
anonymously
setting should be configured to
None
in Enterprise Client and High Security
environments.