22.06.2016 Views

CIS Microsoft Windows 10 Enterprise RTM (Release 1507) Benchmark

CIS_Microsoft_Windows_10_Enterprise_RTM_Release_1507_Benchmark_v1.0.0

CIS_Microsoft_Windows_10_Enterprise_RTM_Release_1507_Benchmark_v1.0.0

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

2.3.9.5 (L1) Set '<strong>Microsoft</strong> network server: Server SPN target name<br />

validation level' to 'Accept if provided by client' or higher (Scored)<br />

Profile Applicability:<br />

Level 1<br />

Level 1 + BitLocker<br />

Description:<br />

This policy setting controls the level of validation a computer with shared folders or<br />

printers (the server) performs on the service principal name (SPN) that is provided by the<br />

client computer when it establishes a session using the server message block (SMB)<br />

protocol.<br />

The server message block (SMB) protocol provides the basis for file and print sharing and<br />

other networking operations, such as remote <strong>Windows</strong> administration. The SMB protocol<br />

supports validating the SMB server service principal name (SPN) within the authentication<br />

blob provided by a SMB client to prevent a class of attacks against SMB servers referred to<br />

as SMB relay attacks. This setting will affect both SMB1 and SMB2.<br />

This security setting determines the level of validation a SMB server performs on the<br />

service principal name (SPN) provided by the SMB client when trying to establish a session<br />

to an SMB server.<br />

The recommended state for this setting is: Accept if provided by client. Configuring<br />

this setting to Required from client also conforms with the benchmark.<br />

Rationale:<br />

The identity of a computer can be spoofed to gain unauthorized access to network<br />

resources.<br />

Audit:<br />

Navigate to the UI Path articulated in the Remediation section and confirm it is set as<br />

prescribed. This group policy setting is backed by the following registry location:<br />

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanManServer\Parameters:SMBServer<br />

NameHardeningLevel<br />

185 | P a g e

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!