PolicySecurity Setting
Deze 2 zijn het probleem vermoed ik!
Accounts: Administrator account statusNot Applicable
Accounts: Guest account statusNot Applicable
Accounts: Limit local account use of blank passwords to console logon onlyEnabled
Accounts: Rename administrator accountAdministrator
Accounts: Rename guest accountGuest
Audit: Audit the access of global system objectsDisabled
Audit: Audit the use of Backup and Restore privilegeDisabled
Audit: Shut down system immediately if unable to log security auditsDisabled
Devices: Allow undock without having to log onEnabled
Devices: Allowed to format and eject removable mediaAdministrators
Devices: Prevent users from installing printer driversDisabled
Devices: Restrict CD-ROM access to locally logged-on user onlyDisabled
Devices: Restrict floppy access to locally logged-on user onlyDisabled
Devices: Unsigned driver installation behaviorWarn but allow installation
Domain controller: Allow server operators to schedule tasksNot defined
Domain controller: LDAP server signing requirementsNot defined
Domain controller: Refuse machine account password changesNot defined
Domain member: Digitally encrypt or sign secure channel data (always)Enabled
Domain member: Digitally encrypt secure channel data (when possible)Enabled
Domain member: Digitally sign secure channel data (when possible)Enabled
Domain member: Disable machine account password changesDisabled
Domain member: Maximum machine account password age30 days
Domain member: Require strong (Windows 2000 or later) session keyDisabled
Interactive logon: Do not display last user nameDisabled
Interactive logon: Do not require CTRL+ALT+DELNot defined
Interactive logon: Message text for users attempting to log on
Interactive logon: Message title for users attempting to log onNot defined
Interactive logon: Number of previous logons to cache (in case domain controller is not available)10 logons
Interactive logon: Prompt user to change password before expiration14 days
Interactive logon: Require Domain Controller authentication to unlock workstationDisabled
Interactive logon: Smart card removal behaviorNo Action
Microsoft network client: Digitally sign communications (always)Disabled
Microsoft network client: Digitally sign communications (if server agrees)Enabled
Microsoft network client: Send unencrypted password to third-party SMB serversDisabled
Microsoft network server: Amount of idle time required before suspending sessionNot defined
Microsoft network server: Digitally sign communications (always)Not defined
Microsoft network server: Digitally sign communications (if client agrees)Not defined
Microsoft network server: Disconnect clients when logon hours expireNot defined
Network access: Allow anonymous SID/Name translationNot Applicable
Network access: Do not allow anonymous enumeration of SAM accountsDisabled
Network access: Do not allow anonymous enumeration of SAM accounts and sharesDisabled
Network access: Do not allow storage of credentials or .NET Passports for network authenticationDisabled
Network access: Let Everyone permissions apply to anonymous usersEnabled
Network access: Named Pipes that can be accessed anonymouslyCOMNAP,COMNODE,SQL\QUERY,SPOOLSS,LLSRPC,EPMAPPER,LOCATOR,TrkWks,TrkSvr
Network access: Remotely accessible registry pathsSystem\CurrentControlSet\Control\ProductOptions,System\CurrentControlSet\Control\Print\Printers,System\CurrentControlSet\Control\Server Applications,System\CurrentControlSet\Services\Eventlog,Software\Microsoft\OLAP Server,Software\Microsoft\Windows NT\CurrentVersion,System\CurrentControlSet\Control\ContentIndex,System\CurrentControlSet\Control\Terminal Server,System\CurrentControlSet\Control\Terminal Server\UserConfig,System\CurrentControlSet\Control\Terminal Server\DefaultUserConfiguration
Network access: Shares that can be accessed anonymouslyCOMCFG,DFS$,IPC$
Network access: Sharing and security model for local accountsClassic - local users authenticate as themselves
Network security: Do not store LAN Manager hash value on next password changeDisabled
Network security: Force logoff when logon hours expireDisabled
Network security: LAN Manager authentication levelSend LM & NTLM responses
Network security: LDAP client signing requirementsNegotiate signing
Network security: Minimum session security for NTLM SSP based (including secure RPC) clientsNo minimum
Network security: Minimum session security for NTLM SSP based (including secure RPC) serversNo minimum
Recovery console: Allow automatic administrative logonDisabled
Recovery console: Allow floppy copy and access to all drives and all foldersDisabled
Shutdown: Allow system to be shut down without having to log onEnabled
Shutdown: Clear virtual memory pagefileDisabled
System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signingDisabled
System objects: Default owner for objects created by members of the Administrators groupObject creator
System objects: Require case insensitivity for non-Windows subsystemsEnabled
System objects: Strengthen default permissions of internal system objects (e.g. Symbolic Links)Enabled