Restrict Anonymous

P

Pat

the Msba is telling me my W2k server is running Restrict Anonymous
at 0 and should chnage it to 1 or 2. what does this option do and why
should I change it?
 
S

Steven L Umbach

It restricts the use of anonymous/null sessions to retrieve information on
your computer such as user/group information and even a bunch more. A
properly configured firewall will also block access to that info. Setting 1
for do not allow anonymous enumeration of sam accounts and shares is usually
safe to use. The 2 setting for no access wihout explicit anonymous
permissions should be used with caution, particualrly on domain controllers
as downlevel clients such as W98/NT4.0 and even XP can have problems with
things like accessing resources or changing passwords. The free Windows 2000
Security Hardening Guide has specific recommendations on that setting and
the KB link below details potential issues. --- Steve

http://support.microsoft.com/default.aspx?scid=kb;en-us;823659
 
T

ThePsyko

The 2 setting for no access wihout explicit anonymous
permissions should be used with caution, particualrly on domain
controllers as downlevel clients such as W98/NT4.0 and even XP can
have problems with things like accessing resources or changing
passwords.

I've had NT4 clients whose 'computer account in the domain' became
corrupted after setting a 2 on a 2k DC and was then unable to re-add them
to the domain (unable to find a domain controller) until I changed the
setting to 1. The 2k clients had no problems - it was just the three NT4
systems.

--
/(bb|[^b]{2})/ that is the Question

ThePsyko
Public Enemy #7
http://prozac.iscool.net
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top