Re: Domain policy "Do not allow anonymous enumeration" not applying

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Hi
In the machine go to:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\NT\CurrentVersion\Winlogon
Criate an entry with:
Value: UserEnvDebugLevel
Value Type: REG_DWORD
Value Data: 10002 (hexadecimal)

Logoff and log back

The file is saved to
File is written to:
%SystemRoot%\Debug\UserMode\Userenv.log

Open the file and search for errors

--
I hope that the information above helps you.
Have a Nice day.

Jorge Silva
MVP Directory Services
"Pete" <Pete@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:B43D520F-1014-440A-AC98-D891F94C902B@xxxxxxxxxxxxxxxx
Hello All,
I running into this weird problem, the domain policy listed below is not
applying to few win2k workstation:

Do not allow anonymous enumeration of SAM accounts and shares=enabled
Do not allow anonymous enumeration of SAM accounts=enabled

I am using NBTenum 3.3 to check the anonymous binding. The other machines in
the network are not allowing anonymous binding so not sure what could be
causing few workstations to behave differently. I also checked the registry
on these workstation

HKLM\system\CurrentControlSet\Control\LSA\RestricAnonymous=1, I even this
entry to 2 and still have to bind anonymously.


Thanks in advance for reading this post...


.



Relevant Pages

  • Re: Domain policy "Do not allow anonymous enumeration" not applyin
    ... I checked the workstation itself and following policies are under effective ... "Do not allow enumeration of SAM accounts and share", ... I am using NBTenum 3.3 to check the anonymous binding. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Domain policy "Do not allow anonymous enumeration" not applyin
    ... "Everyone" was in the Power Users group, ... power users group on the workstation, I couldn't retrieve info as anonymous ... Do not allow anonymous enumeration of SAM accounts and shares=enabled ... I am using NBTenum 3.3 to check the anonymous binding. ...
    (microsoft.public.windows.server.active_directory)
  • Domain policy "Do not allow anonymous enumeration" not applying
    ... applying to few win2k workstation: ... Do not allow anonymous enumeration of SAM accounts and shares=enabled ... I am using NBTenum 3.3 to check the anonymous binding. ...
    (microsoft.public.windows.server.active_directory)
  • Re: CDE problem in 11i ?
    ... If the workstation is set up to use DHCP, ... containing the workstation's IP address and hostname. ... There MUST also be an entry for "localhost" with IP address 127.0.0.1. ...
    (comp.sys.hp.hpux)
  • How do I push out manual entries in DNS to my workstations?
    ... try running ipconfig /flushdns on your workstation. ... >a mistake in the ip entry for ftp. ... But my workstation still resolves to ... On the DC if I ping ftp or ftp.domain.com it ...
    (microsoft.public.windows.server.dns)