MSS: (AutoShareWks) Enable Administrative Shares (recommended except for highly secure environments)ID: oval:org.secpod.oval:def:35154 | Date: (C)2016-06-10 (M)2023-12-13 |
Class: COMPLIANCE | Family: windows |
MSS: (AutoShareWks) Enable Administrative Shares (recommended except for highly secure environments)
Counter Measure:
Do not configure the MSS: (AutoShareWks) Enable Administrative Shares (not recommended except for highly secure environments) entry except on computers in highly secured environments where administrative shares are not required.
The possible values for this registry entry are:
? 1 or 0. The default configuration is disabled.
In the SCE UI, these options appear as:
? Enabled
? Disabled
? Not Defined
Potential Impact:
If you delete these shares you could cause problems for administrators and programs or services that rely on these shares. For example, both Microsoft Systems Management Server (SMS) and Microsoft Operations Manager require administrative shares for correct installation and operation. Also, many third-party network backup applications require administrative shares.
Fix:
(1) GPO: Computer Configuration\Administrative Templates\MSS (Legacy)\MSS: (AutoShareWks) Enable Administrative Shares (recommended except for highly secure environments)
(2) REG: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanmanServer\Parameters!AutoShareWks
Platform: |
Microsoft Windows 10 |