Groups guest belongs to (Windows)
Module: Account
Integrity
Supported Platforms:
Windows 2000, Windows 2003, Windows 2008, Windows Vista, Windows
XP
This check reports groups
that the guest account belongs to. By default, the guest account
does not have a password, so its system access must be tightly
controlled. You can use the name list to exclude groups that the
guest account is permitted to belong to, which should not be
reported.
The following table lists
the error message for the check.
Table: Error message for Groups guest belongs
to
Message String ID and Category
|
Platform and Message Numeric ID
|
Message Title and Description
|
Additional Information
|
String ID: ESM_GUEST_GROUPS
Category: Policy Compliance
|
-
Windows 2000 (105909)
-
Windows 2003 (205909)
-
Windows 2008 (248909)
-
Windows Vista (228909)
-
Windows XP (200909)
|
Title: Guest account is a member of unauthorized groups
Description:The guest account is a member of disallowed groups.
Users logging on as guest may have too much access to the system.
Remove guest membership from the reported groups. You can use the
check's name list to exclude authorized groups from the check.
|
Severity: yellow-1
Correctable: false
Snapshot Updatable: false
Template Updatable: false
Information Field Format: [%s]
|