88c8f687-8262-44c9-aa73-234614ddbbb6
To the extent that anonymous access to directory data (outside the root DSE) is permitted, read access control of the data is effectively disabled. If other means of controlling access (such as network restrictions) are compromised, there may be nothing else to protect the confidentiality of sensitive directory data.
Configure directory data (outside the root DSE) of a nonpublic directory to prevent anonymous access.
For AD, there are multiple configuration items that could enable anonymous access.
Changing the access permissions on the domain naming context object (from the secure defaults) could enable anonymous access. If the check procedures indicate this is the cause, the process that was used to change the permissions must be reversed. This could have been through the Windows Support Tools ADSI Edit console (adsiedit.msc).
STIG: Server
2016: https://system32.eventsentry.com/stig/viewer/V-224978
2019: https://system32.eventsentry.com/stig/viewer/V-205875
2022: https://system32.eventsentry.com/stig/viewer/V-254399
2025: https://system32.eventsentry.com/stig/viewer/V-278146
NIST 800-53 : AC-3, AC-6, CM-6, SC-7
NIST 800-171: 3.1.1, 3.1.2, 3.4.6, 3.13.1
CMMC v2.0 L2: AC.L2-3.1.1, AC.L2-3.1.2, CM.L2-3.4.6, SC.L2-3.13.1
PCI-DSS v4.0: 2.2.1, 7.2.1
HIPAA SR : §164.312(a)(1), §164.312(e)(1)
HIPAA HICP : Practice 3 (Identity and Access Management), Practice 6 (Network Management)
Manage your cookie preferences below:
To learn more about our use of cookies, please see our
Privacy Policy.