Skip to content

Windows Server 2022 directory data (outside the root DSE) of a nonpublic directory must be configured to prevent anonymous access.

An XCCDF Rule

Description

To the extent that anonymous access to directory data (outside the root DSE) is permitted, read access control of the data is effectively disabled. If other means of controlling access (such as network restrictions) are compromised, there may be nothing else to protect the confidentiality of sensitive directory data.

ID
SV-254399r991589_rule
Version
WN22-DC-000150
Severity
High
References
Updated

Remediation Templates

A Manual Procedure

Configure directory data (outside the root DSE) of a nonpublic directory to prevent anonymous access.

For AD, there are multiple configuration items that could enable anonymous access.

Changing the access permissions on the domain naming context object (from the secure defaults) could enable anonymous access. If the check procedures indicate this is the cause, the process that was used to change the permissions must be reversed. This could have been through the Windows Support Tools ADSI Edit console (adsiedit.msc).

The dsHeuristics option is used. This is addressed in check V-8555 in the AD Forest STIG.