Skip to content

Unauthenticated Remote Procedure Call (RPC) clients must be restricted from connecting to the RPC server.

An XCCDF Rule

Description

Unauthenticated RPC clients may allow anonymous access to sensitive information. Configuring RPC to restrict unauthenticated RPC clients from connecting to the RPC server will prevent anonymous connections.

ID
SV-225010r971545_rule
Version
WN16-MS-000040
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Configure the policy value for Computer Configuration >> Administrative Templates >> System >> Remote Procedure Call >> "Restrict Unauthenticated RPC clients" to "Enabled" with "Authenticated" selected.