By default, Windows Server 2003 domain controllers let anonymous users resolve a security identifier (SID) to a user name.
This configuration has security risks. For example, an anonymous user can use the well known Administrators SID to obtain the real name of the built-in Administrator account. This behavior may occur even though the account has been renamed.
Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.