Click here to get back home

When Should Anonymous Logons Show on Windows 200x?

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
When Should Anonymous Logons Show on Windows 200x? Will 02-13-2007
Posted by Will on February 13, 2007, 2:09 pm
Please log in for more thread options
On a Windows 2000 and Windows 2003 domain controller (maybe a different
answer for each?), when should you expect to see an Anonymous Logon in the
security eventviewer as a normal occurrence?

--
Will



Posted by Will on February 14, 2007, 12:00 am
Please log in for more thread options
> On a Windows 2000 and Windows 2003 domain controller (maybe a different
> answer for each?), when should you expect to see an Anonymous Logon in the
> security eventviewer as a normal occurrence?

I should have qualified this question. Assume that all of the standard
GPOs that forbid anonymous access and enumeration are enabled.

--
Will



Posted by Roger Abell [MVP] on February 14, 2007, 12:11 am
Please log in for more thread options
>> On a Windows 2000 and Windows 2003 domain controller (maybe a different
>> answer for each?), when should you expect to see an Anonymous Logon in
>> the
>> security eventviewer as a normal occurrence?
>
> I should have qualified this question. Assume that all of the standard
> GPOs that forbid anonymous access and enumeration are enabled.
>

Hi Will,
That is a great question.
I do wish someone from Microsoft would give a definitive answer.
I will not speak to the Windows 2000 case, as that is old and was
evolved before much of the world, including Microsoft, had this as
an issue in focus.
For Windows 2003 as best as I can tell it is not possible to prevent
all anonymous logins, at least I have not found a way to do so. As
best I can tell, after one has latched down the system as far as the
visible settings allow, when one does still see the Anonymous Login
success message it is coming from the initial negotiation used to
discover the SSPI that is in common and may be used for the required
login. I could easily be wrong, but that has been my working hypothesis.

Roger



Similar ThreadsPosted
creat a domain trust between Windows 2000 server, it show error message:"PRC server is unavailable" July 3, 2006, 3:59 pm
Windows server 2003 security. How to protect against 100's of invalid logons to the server?? August 12, 2005, 5:29 pm
Network drives show disconnected, sometimes, but still work? November 30, 2007, 8:31 pm
Show informational notifications for network printers with firewall February 5, 2008, 3:03 am
Prevent logons other than PC owner? January 16, 2006, 5:32 pm
Auditing Workstation logons from DC January 24, 2006, 7:29 pm
Number of logons when disconnected from the Domain? August 4, 2006, 2:37 am
How to use "Number of Previous Logons to Cache" setting September 5, 2005, 4:18 pm
remoted machines with cached domain logons August 30, 2006, 8:43 am
Any methods to restrict concurrent logons aside from cconnect (w2k resource kit) June 3, 2006, 11:12 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap