CTD-000163

AD domain without group policy restricting anonymous enumeration of SAM accounts and shared resources

Medium
Active Directory
Credential Access Discovery Initial Access
v21

Signature Identity

CTD-000163
Threat ID
21
Version
IOE
Indicator Type

Threat Description

In an Active Directory domain, where group policy does not restrict the anonymous enumeration of SAM accounts and shared resources, an unauthorized user could anonymously list account names and shared resources and use the information to attempt to guess passwords or perform social engineering attacks.

To mitigate this risk, a group policy with the Network access: Do not allow anonymous enumeration of SAM accounts and shares enabled setting should be applied to the domain. This ensures that only authenticated users can retrieve accounts and share information.

Applying this policy may introduce some operational limitations. In one-way trust environments, administrators in the trusting domain may be unable to list accounts from the trusted domain, which complicates access management. Additionally, users who attempt to access file and print servers anonymously will no longer be able to view shared resources. They will need to authenticate before they can see available shares and printers.

MITRE ATT&CK: Attack Tactics

Credential Access Discovery Initial Access

D3FEND: Defend Tactics

D3-ACH (Application Configuration Hardening)

Remediation

  1. Open Group Policy Management (gpmc.msc).
  2. In the console tree, expand Forest > Domains.
  3. Expand your domain.
  4. Right-click the Default Domain Policy shortcut.
  5. Select Edit to open the Group Policy Management Editor window.
  6. Select Computer ConfigurationWindows Settings > Security Settings > Local Policies to edit Security Options.
  7. Enable Network access: Do not allow anonymous enumeration of SAM accounts and shares.
  8. Apply the GPO by running the following command: gpupdate /force

Frequently Asked Questions

What does AD domain without group policy restricting anonymous enumeration of SAM accounts and shared resources mean?

In an Active Directory environment, the absence of a group policy setting that restricts anonymous enumeration of Security Accounts Manager (SAM) accounts and shared resources means that unauthorized users can access account names and shared resource listings without valid credentials.

This issue is rated medium severity because an attacker can use the gathered information to plan a more serious intrusion, such as password guessing or social engineering attacks. The risk is indirect but meaningful, placing it in the middle of the severity scale.

Attackers can use this vulnerability to anonymously list account names and shared resources, which can be used as reconnaissance data for more serious attacks. This information can also be used to identify potential vulnerabilities in the environment.

Cayosoft Guardian continuously monitors the group policy settings across the Active Directory environment to identify when the setting that restricts unauthorized access to account names and shared resources is disabled, flagging it as a security issue for administrators.

Cayosoft Guardian helps mitigate this risk by alerting administrators to enable the group policy setting that restricts unauthorized access, as well as supporting ongoing monitoring to quickly detect any changes to the setting. This provides visibility into potential security issues and supports investigation and response efforts.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Account protection
Attack Tactics
Credential Access Discovery Initial Access
Defend Tactics
D3-ACH (Application Configuration Hardening)
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical