Securing Windows Server 2003 tasks
Cisco TMS Secure Server Configuration Guide 13.0
Page 26 of 34
Policy
Security Setting
Network access: Named Pipes that can be
accessed anonymously
COMNAP
COMNODE
SQL\QUERY
SPOOLSS
LLSRPC
netlogon
lsarpc
samr
browser
Network access: Remotely accessible registry
paths
System\CurrentControlSet\Control\ProductOptions
System\CurrentControlSet\Control\Server
Applications
Software\Microsoft\Windows NT\CurrentVersion
Network access: Remotely accessible registry
paths and subpaths
System\CurrentControlSet\Control\Print\Printers
System\CurrentControlSet\Services\Eventlog
Software\Microsoft\OLAP Server
Software\Microsoft\Windows
NT\CurrentVersion\Print
Software\Microsoft\Windows
NT\CurrentVersion\Windows
Network access: Restrict anonymous access to
Named Pipes and Shares
Enabled
Network access: Shares that can be accessed
anonymously
Network access: Sharing and security model for
local accounts
Classic - Local users …
Network security: Do not store LAN Manager
hash value on next password change
Enabled
Network security: Force logoff when logon hours
expire
Disabled
Network security: LAN Manager authentication
level
Send NTMLv2 response only
Network security: LDAP client signing
requirements
Negotiate Signing
Network security: Minimum session security for
NTLM SSP based (including secure RPC)
clients
Enabled all settings
Network security: Minimum session security for
NTLM SSP based (including secure RPC)
servers
Enabled all settings
Recovery console: Allow automatic
administrative logon
Disabled
Recovery console: Allow floppy copy and
access to all drives and all folders
Disabled
Shutdown: Allow system to be shut down
without having to log on
Disabled
Shutdown: Clear virtual memory pagefile
Disabled