53
Network security: Minimum session security for NTLM SSP based (including secure RPC) servers
Member Server Default
Legacy Client
Enterprise Client
High Security Client
No minimum
No minimum
Enabled all settings
Enabled all settings
Important:
Administrators within multi-protocol heterogeneous environments may want to verify all
applications and protocol communications are working properly within their NAS box, and other
servers within the network, once this setting is set.
The
Network security: Minimum session security for NTLM SSP based (including secure RPC) servers
security option setting allows a server to require the negotiation of message confidentiality
(encryption), message integrity, 128-bit encryption, or NTLMv2 session security. Configure this setting
as high as possible while still allowing the applications on the network to function fully to ensure that
network traffic from NTLM SSP based clients is protected from man-in-the-middle attacks and data
exposure.
Recovery console: Allow automatic administrative logon
Member Server Default
Legacy Client
Enterprise Client
High Security Client
Disabled Disabled Disabled Disabled
The
Recovery console: Allow automatic administrative logon
security option setting determines
whether the password for the
Administrator
account must be given before access to the system is
granted. If this option is enabled, the Recovery Console does not require users to provide a password,
and it automatically logs on to the system. The
Recovery Console can be very useful when troubleshooting and repairing systems that cannot be
restarted normally. However, enabling this setting can be detrimental because anyone can then walk
up to the server, shut it down by disconnecting the power, restart it, select
Recover Console
from the
Restart
menu, and then assume full control of the server. Therefore, this setting is configured to the
default for the three environments defined in this guide. To use the Recovery Console when this setting
is disabled, the user will have to enter a user name and password to access the Recovery Console
account.
Recovery console: Allow floppy copy and access to all drives and all folders
Member Server Default
Legacy Client
Enterprise Client
High Security Client
Disabled Enabled Enabled Disabled
Enabling the
Recovery console: Allow floppy copy and access to all drives and all folders
security
option setting makes the Recovery Console
SET
command available, which allows users to set the
following Recovery Console environment variables:
•
AllowWildCards:
Enables wildcard support for some commands (such as the DEL command)
•
AllowAllPaths:
Allows access to all files and folders on the computer
•
AllowRemovableMedia:
Allows files to be copied to removable media, such as a floppy disk
•
NoCopyPrompt:
Does not prompt when overwriting an existing file
For maximum security, this setting is configured to
Disabled
in the High Security environment.
Shutdown: Allow system to be shut down without having to log on
Member Server Default
Legacy Client
Enterprise Client
High Security Client
Disabled Disabled Disabled Disabled
The
Shutdown: Allow system to be shut down without having to log on
security option setting
determines whether a computer can be shut down without having to log on to the Windows operating