Anonymous enumeration still enabled



I am having a problem blocking anonymous enumeration on my Windows 2003
domain controller. I have applied all of the "network access" settings
that should prevent this in Group Policy (shown below). I have then
double-checked that these are applied in both secpol.msc and the
registry. However, I am still able to enumerate usernames and password
policies from a non-trusted client (not part of the domain) from a
completely different segment using a tool called "enum.exe". Any ideas
why I would still be able to enumerate? FYI... this server was not
upgraded from W2K... It was built fresh as a W2K3 DC.

Network access: Allow anonymous SID/Name translation|DISABLED
Network access: Do not allow anonymous enumeration of SAM
accounts|ENABLED
Network access: Do not allow anonymous enumeration of SAM accounts and
shares|ENABLED
Network access: Let Everyone permissions apply to anonymous
users|DISABLED
Network access: Named pipes can be accessed anonymously|DISABLED
Network access: Restrict anonymous access to Named Pipes and
shares|ENABLED

.



Relevant Pages

  • Re: Access Denied Browsing Solution
    ... >I then went into Local Security Policy and set: ... >Network Access: Do not allow anonymous enumeration of SAM ... registry keys do, and if they are the same as the LSP settings. ...
    (microsoft.public.windowsxp.network_web)
  • RE: Cannot connect via Linked Server
    ... Network access: Do not allow anonymous enumeration of SAM accounts and shares: Disabled ... assistance from a Microsoft Support Professional through Microsoft Product ... Microsoft SQL Server Support Professional ...
    (microsoft.public.sqlserver.connect)
  • Re: LookupAccountName behavior dependent upon operating system of global catalog (GC)
    ... I checked the policy settings you noted earlier. ... Network access: Do not allow anonymous enumeration of SAM accounts - ENABLED ...
    (microsoft.public.platformsdk.security)
  • RE: Windows 95 - DSCLIENT
    ... your nt 4 pcs should be fine as well as any win 98 SECOND edition pcs. ... > B. Microsoft network client: ... > D. Network access: Do not allow anonymous enumeration of SAM accounts ...
    (microsoft.public.windows.server.migration)
  • Cant disable anonymous enumeration
    ... domain controller. ... I have applied all of the "network access" settings ... Do not allow anonymous enumeration of SAM ... Named pipes can be accessed anonymously|DISABLED ...
    (microsoft.public.windows.group_policy)