Disable Anonymous SID Enumeration Group Policy Setting in my Domain

seema kanwal 26 Reputation points
2022-05-16T11:44:09.83+00:00

Dear Community,

I want to apply this Policy i.e. "Disable Anonymous SID Enumeration". I researched on Internet and have found out that the Security Account Manager (SAM) is a Database that is present on Computers running Windows Operating Systems that stores User Accounts and security descriptors for users on the Local computer. So what does earlier mentioned Policy actally do? Is it safe to Apply this Policy?

I have below Questions:

Q1. What happens If I Apply this Policy?

Q2. How does Anonymous SID Enumeration work ("Does it Allow Anonymous Access to SAM users to Domain Users?")

Q3. What exactly does it Do?

Q4. How does it secure my Domain?

Please help me, as I want to secure my Environment by Applying these New Group Policies?

Note:
I have one domain. I have four sites with each domain controller on each Site.
Thanks.

Windows for business Windows Server User experience Other
Windows for business Windows Client for IT Pros User experience Other
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Limitless Technology 39,916 Reputation points
    2022-05-23T08:39:36.367+00:00

    Hi there,

    Anonymous enumeration of user accounts is one-way attackers can obtain usernames for use in social engineering or for which they can try to guess the passwords.
    An attacker can retrieve the SID of a known user on the domain and use the information to target the Administrator account.

    Once the SID for any account or system on the domain is discovered, the attacker could substitute the RID for the Administrator account and discover what the name of the Administrator user account is. To protect your computer or network from even the more dedicated attackers, you can disable the ability to enumerate the SIDs.

    Network access: Do not allow anonymous enumeration of SAM accounts and shares https://learn.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/network-access-do-not-allow-anonymous-enumeration-of-sam-accounts-and-shares

    -------------------------------------------------------------------------------------------------------------------------------------

    --If the reply is helpful, please Upvote and Accept it as an answer–

    0 comments No comments

  2. seema kanwal 26 Reputation points
    2022-06-29T10:23:18.933+00:00

    Dear Community,

    It says only authenticated Users will be able to access Shared Folders and Files. I am attaching screenshot below. Please explain to me what does the Highlighted text mean in below screenshot?

    216142-sid-enumeration.png

    0 comments No comments

  3. Seema Kanwal Gurmani 336 Reputation points
    2022-07-01T12:03:54.757+00:00

    Dear Community,

    Also tell me do I need to enable this setting on my Domain Controllers. As I have windows Server 2019 OS installed on my Domain Controller. Do i still need to enable this setting on 2019 as It is not an on old OS?

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.