Skip to content
This repository has been archived by the owner on Feb 12, 2025. It is now read-only.

Correction to what the Security Compliance Toolkit says #674

Open
AaronMargosis opened this issue Feb 15, 2024 · 7 comments
Open

Correction to what the Security Compliance Toolkit says #674

AaronMargosis opened this issue Feb 15, 2024 · 7 comments
Assignees
Labels
backlog-item-created Apply when a backlog item has been created for this issue microsoft-defender-for-identity/svc Pri1

Comments

@AaronMargosis
Copy link

AaronMargosis commented Feb 15, 2024

What this page says about the MS Security Compliance Toolkit recommendation for the "Access this computer from the network" user rights assignment is incorrect. The SCT recommends different values for Windows 10/11 from Windows Server.
For Windows Server (non-DC), it recommends Administrators + Authenticated Users, as this page says.
For Windows Server (DC), it recommends Administrators + Authenticated Users + Enterprise Domain Controllers.
But for Win10/11, it's only Administrators + Remote Desktop Users.


Document Details

Do not edit this section. It is required for learn.microsoft.com ➟ GitHub issue linking.

@batamig batamig self-assigned this Feb 29, 2024
@batamig batamig added the backlog-item-created Apply when a backlog item has been created for this issue label Feb 29, 2024
@batamig
Copy link
Collaborator

batamig commented Feb 29, 2024

Thank you for your comment. We'll investigate and get back to you.

@AaronMargosis
Copy link
Author

To save you some time: ask Rick Munck. He's in the GAL.

@batamig
Copy link
Collaborator

batamig commented Mar 14, 2024

Thanks @AaronMargosis! I've confirmed this update and changes should be going in shortly.
I'm going to close this for now, but please feel free to continue commenting if you have more feedback.
We appreciate your contribution to docs!
#please-close

@AaronMargosis
Copy link
Author

When will the changes be made, and what will the changes be? The text is still incorrect.

@batamig
Copy link
Collaborator

batamig commented Apr 15, 2024

Hi @AaronMargosis, the updated text reads

The Microsoft Security Compliance Toolkit recommends replacing the default Everyone with Authenticated Users to prevent anonymous connections from performing network sign-ins. Review your local policy settings before managing the Access this computer from the network setting from a GPO, and consider including Authenticated Users in the GPO if needed.

Please feel free to reopen this issue if there's something still missing.

@AaronMargosis
Copy link
Author

I don't see a way for me to reopen this issue, but the text is still incorrect. Per what I wrote when I first opened this issue, the SCT recommends against granting the logon right to Authenticated Users: "But for Win10/11, it's only Administrators + Remote Desktop Users."

@batamig batamig reopened this Apr 18, 2024
@batamig
Copy link
Collaborator

batamig commented Apr 18, 2024

Thanks! I reopened and will take this back to investigate.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
backlog-item-created Apply when a backlog item has been created for this issue microsoft-defender-for-identity/svc Pri1
Projects
None yet
Development

No branches or pull requests

2 participants