RE: SBS 2000 accounts security settings

From: Smith, Ricky D. (RICKY.D.SMITH@saic.com)
Date: 06/03/02


From: "Smith, Ricky D." <RICKY.D.SMITH@saic.com>
To: "'Perikles P. Mourikis'" <mourikis@dreamtech.gr>, focus-ms@securityfocus.com
Date: Mon, 3 Jun 2002 13:51:12 -0400 

There should be no problem removing the Guest user account from the Domain
User and Domain Guests groups.

The IUSR_MACHINE and IWAM_MACHINE accounts are used by/for IIS. If you have
disabled or are not using IIS, then removing them from those groups will not
affect anything.

Rick Smith
MCSE+I, MCSE (W2K), GCWN

-----Original Message-----
From: Perikles P. Mourikis [mailto:mourikis@dreamtech.gr]
Sent: Monday, June 03, 2002 0721
To: focus-ms@securityfocus.com
Subject: SBS 2000 accounts security settings

I have noticed that Microsoft's product Small Business Server 2000 (SBS
2000) has the "Guest" template group being a member of Domain Guests ,
Guests and Domain Users.

Also ISR_MACHINE and IWAM_MACHINE are members of Domain Users and Guests.

Does anybody knows any known issues with removing the Domain Users
membership from these accounts?

Are there any known exploits of this configuration? (assuming the SBS 2000
is patched properly...)

TIA

Perikles



Relevant Pages

  • Re: User Password Change
    ... Guests, or Temp workers, they have special accounts that just don't ... Dunno - why not just have them use OWA for this? ... (that said, if you have Exchange 2003, by all means click that link ...
    (microsoft.public.windows.server.scripting)
  • controlling guest account program access in XP
    ... I have a home machine that has several accounts, ... which is for guests that visit. ... Yahoo, ICQ, AIM etc on the machine, but these programs ... other non-admin accounts. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: News: Mark Sharpiros grand SF tour in Kentucky
    ... Shawn Mamros wrote: ... No on both accounts, or at least not that I can remember from my visits to Disneyland. ... They have custodians that are constantly cleaning each rest room throughout the day They do not have any specialized attendant stationed in any of them that assists guests, if that was what you were referring to when you said "attendant." ...
    (rec.roller-coaster)
  • Having To Log-in Twice
    ... I have two accounts setup on my PC, one for guests ... (friends that come over or whatever) ... Everytime I boot up the computer and login to my account, ...
    (microsoft.public.windowsxp.accessibility)
  • Re: Windows 2003 / IIS 6.0 Anonymous Access
    ... In IIS 6.0 the default logon type is Network_Cleartext when accessing IIS ... What other accounts are in the guests group? ... and then allow guests to access the computer from the network. ... As part of a W2K3 standard build I'm working on I've set the "Deny Access ...
    (microsoft.public.inetserver.iis.security)