Can't disable anonymous enumeration



I am having a problem blocking anonymous enumeration on my Windows 2003
domain controller. I have applied all of the "network access" settings
that should prevent this in Group Policy (shown below). I have then
double-checked that these are applied in both secpol.msc and the
registry. However, I am still able to enumerate usernames and password
policies from a non-trusted client (not part of the domain) from a
completely different segment using a tool called "enum.exe". Any ideas
why I would still be able to enumerate? FYI... this server was not
upgraded from W2K... It was built fresh as a W2K3 DC.

Network access: Allow anonymous SID/Name translation|DISABLED
Network access: Do not allow anonymous enumeration of SAM
accounts|ENABLED
Network access: Do not allow anonymous enumeration of SAM accounts and
shares|ENABLED
Network access: Let Everyone permissions apply to anonymous
users|DISABLED
Network access: Named pipes can be accessed anonymously|DISABLED
Network access: Restrict anonymous access to Named Pipes and
shares|ENABLED

.



Relevant Pages

  • Re: Access Denied Browsing Solution
    ... >I then went into Local Security Policy and set: ... >Network Access: Do not allow anonymous enumeration of SAM ... registry keys do, and if they are the same as the LSP settings. ...
    (microsoft.public.windowsxp.network_web)
  • RE: Cannot connect via Linked Server
    ... Network access: Do not allow anonymous enumeration of SAM accounts and shares: Disabled ... assistance from a Microsoft Support Professional through Microsoft Product ... Microsoft SQL Server Support Professional ...
    (microsoft.public.sqlserver.connect)
  • Re: LookupAccountName behavior dependent upon operating system of global catalog (GC)
    ... I checked the policy settings you noted earlier. ... Network access: Do not allow anonymous enumeration of SAM accounts - ENABLED ...
    (microsoft.public.platformsdk.security)
  • Anonymous enumeration still enabled
    ... domain controller. ... I have applied all of the "network access" settings ... Do not allow anonymous enumeration of SAM ... Named pipes can be accessed anonymously|DISABLED ...
    (microsoft.public.security)
  • Re: Printers dont assign after GPO Security changes...
    ... Network access: Do not allow anonymous enumeration of SAM accounts ... As for the printers users were getting their access via the EVERYONE ... The logon script says that if you are a member of that group, ...
    (microsoft.public.security)