Re: Where to Enable the Restricting NULL policies Settings

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Hi Florian:

Thanks for the response. I do understand the policies and have read about
them as well. Just want to make sure.

Thanks much!

"Florian Frommherz [MVP]" wrote:

Charles,

Charles schrieb:
Question about where to set the two network access policies called:
“Do not allow anonymous enumeration of SAM accounts and shares” and “Do not
allow anonymous enumeration of SAM”. If I want to prevent users from having
access to only 5 servers in the domain would I just enable these settings on
those 5 servers only? Initially I thought that this needed to be set on the
domain controllers only which would prevent this type of NULL access for all
servers in the domain since the accounts live on the DCs. But now I’m
thinking it only needs to be set on the servers that require this
restriction. Is this correct?

have you read the Explain texts of the policies? Just asking - people
sometimes get confused by those two policies and their use. Assuming you
know what these two policies are about, I suggest you enable these
settings on the five servers only. The best way to accomplish this is
create a new OU and move the five servers in there. Then apply a Group
Policy to it and enable the settings.

Cheers,
Florian
--
Microsoft MVP - Group Policy
eMail: prename [at] frickelsoft [dot] net.
blog: http://www.frickelsoft.net/blog.
Maillist (german): http://frickelsoft.net/cms/index.php?page=mailingliste

.



Relevant Pages

  • Re: Registry tatooing
    ... It can list and clean true policies, ... Speed Group Policy Troubleshooting with the NEW GPHealth Reporter tool at http://www.sdmsoftware.com/products.php ... Well, to his disliking, the settings remained. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Local caching of AD-based Group Policy
    ... Group Policy settings are not cached in the sense that they are not ... processed when a domain member computer is not connected to the network. ... Its role is to store all the merged policies when a computer or user is ...
    (microsoft.public.windows.group_policy)
  • Re: Assigning File and Folder Permissions Via Group Policy
    ... A few policies with a lot of settings in each policy may not be the best ... permissions changes into one group policy that gets pushed out to everyone, ...
    (microsoft.public.windows.group_policy)
  • Re: Disable Offline Files?
    ... Certain policies, apply to certain OS or higher version. ... > Synchronize all offline files before logging off ... > COMPUTER SETTINGS ... > Group Policy was applied from: ...
    (microsoft.public.windows.server.general)
  • Re: Disable Offline Files?
    ... Certain policies, apply to certain OS or higher version. ... > Synchronize all offline files before logging off ... > COMPUTER SETTINGS ... > Group Policy was applied from: ...
    (microsoft.public.windows.server.active_directory)