Skip to content

Windows Server 2016 must be configured to prevent anonymous users from having the same permissions as the Everyone group.

An XCCDF Rule

Description

Access by anonymous users must be restricted. If this setting is enabled, anonymous users have the same rights and permissions as the built-in Everyone group. Anonymous users must not have these permissions or rights.

ID
SV-225047r991589_rule
Version
WN16-SO-000290
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Network access: Let everyone permissions apply to anonymous users" to "Disabled".