專案

一般

配置概況

動作

專案資訊 #1074

進行中

專案資訊 #1064: 2025-PenTest

Use of ""Pre-Windows 2000 Compatible Access

是由 Joy Liao3 個月 前加入. 於 約 2 個月 前更新.

狀態:
Resolved-解决
優先權:
Normal
被分派者:
分類:
-
開始日期:
2025-08-01
完成日期:
2025-12-31 (逾期 25 天)
完成百分比:

100%

預估工時:

概述

N bookmark2025052801463337292181788 "Use of ""Pre-Windows 2000 Compatible Access"" group

" "The “Pre-Windows 2000 Compatible Access” group allows its members read access to all user and computer objects in Active Directory, which can expose sensitive information. If an attacker gains membership in this group, they can exploit these permissions to gather valuable data and potentially elevate their privileges, compromising the security of the entire network.

" "Remove ""Anonymous Logon"" from the ""Pre-Windows 2000 Compatible Access"" group.

The Builtin\Pre-Windows 2000 Compatible Access group was originally designed to ensure backward compatibility for systems that predate Windows 2000 (Windows NT 4.0). It is imperative that this group exclusively encompass Authenticated Users (S-1-5-11). ADCS servers are automatically added to this group upon installation. Review any other membership to ensure that there is a business purpose of maintaining the membership. Should it not be necessary anymore, consider removing the membership."


檔案

動作

匯出至 Atom PDF