UCF STIG Viewer Logo

User Right to Deny Access to this computer from the network is not configured to include Guests. (Anonymous Logon and Support_388945a0 in applicable Windows versions).


Overview

Finding ID Version Rule ID IA Controls Severity
V-1155 4.025 SV-29597r1_rule ECLP-1 High
Description
This is a Category 1 finding because allowing network logins by the built-in guest accounts, which are a member of the Everyone group and Guests group, with all the rights and permissions associated with that group, could provide anonymous access to system resources to unauthorized users. Anonymous Logon and Support_388945a0 are also included in applicable Windows versions.
STIG Date
Windows 2003 Domain Controller Security Technical Implementation Guide 2012-07-02

Details

Check Text ( C-421r1_chk )
Analyze the system using the Security Configuration and Analysis snap-in.
Expand the Security Configuration and Analysis tree view.
Navigate to Local Policies -> User Rights Administration.

If the following groups/accounts are not listed under the right "Deny access to this computer from the network", then this is a finding.

Windows 2000 - Guests

Windows 2003 - Guests, Anonymous Logon, Support_388945a0

Windows XP - Guests, Support_388945a0

Vista - Guests

Windows 2008 - Guests

Note: If an account listed has been deleted from the system such as the Support_388945a0 account, the Gold Disk may incorrectly report the account as a finding. If the account does not exist on a system it would not be a finding.

Documentable Explanation: On Exchange Server 2003 supporting OWA, the Guests group should be removed and replaced with “Anonymous Logon”. Document with the IAO
Fix Text (F-5770r1_fix)
Configure the system to give the right "Deny access to this computer from the network" to the Accounts/Groups specified in the manual check.