Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

Windows Server 2003 domain controllers let anonymous users resolve a security identifier (SID) to a user name


View products that this article applies to.

Symptoms

By default, Windows Server 2003 domain controllers let anonymous users resolve a security identifier (SID) to a user name.

This configuration has security risks. For example, an anonymous user can use the well known Administrators SID to obtain the real name of the built-in Administrator account. This behavior may occur even though the account has been renamed.

↑ Back to the top


Cause

This configuration is automatically applied during the Active Directory directory service installation to support compatibility with earlier versions.

↑ Back to the top


Resolution

To avoid the potential risks of the default configuration, follow these steps:
  1. Edit the Group Policy object (GPO) that is linked to the domain controller organizational unit.
  2. In Group Policy Object Editor, locate the following node:
    Computer Configuration/Windows Settings/Security Settings/Local Policies/Security Options
  3. Open the following policy setting:
    Network access: Allow anonymous SID/Name translation
  4. Change this policy setting to Disabled.
  5. Reapply the policy settings to all domain controllers. To do this, type the following command at a command prompt on each domain controller:
    Gpupdate /force

↑ Back to the top


Status

Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section.

↑ Back to the top


More information

If the Network access: Allow anonymous SID/Name translation setting is disabled, earlier operating systems or applications may be unable to communicate with Windows Server 2003 domains. For more information, click the following article number to view the article in the Microsoft Knowledge Base:
823659� Client, service, and program incompatibilities that may occur when you modify security settings and user rights assignments

↑ Back to the top


Keywords: kbtshoot, kbexpertiseinter, kbprb, KB942428

↑ Back to the top

Article Info
Article ID : 942428
Revision : 3
Created on : 10/11/2007
Published on : 10/11/2007
Exists online : False
Views : 429