Security News > 2023 > January > Microsoft locks door to default guest authentication in Windows Pro
Microsoft wants to bulk up the security in Windows Pro editions by ensuring the SMB insecure guest authentication fallbacks are no longer the default setting in the operating system.
The move, which is included in the Windows 11 Insider Preview Build 25276 released this month, means that systems with Windows 10 version 1709 or later and Windows Server 2019, SMB2, and SMB3 will no longer allow by default guest account access to a remote server or for those who provide invalid credentials to fall back to the guest account.
This brings Windows Pro editions in line with the stronger security in Enterprise and Education editions, which stopped allowing the default setting since Windows 10, according to the enterprise software maker.
In another blog post, Microsoft wrote that Windows client and Windows Server haven't allowed guest access or remote users to connect as guest or anonymous users since Windows 2000.
Only third-party remote devices may require guest access by default, but systems running Windows don't.
If a remote device is configured to use guest credentials, the process should be for an administrator to disable guest access to the device and configure the correct authentication and authorization.
News URL
https://go.theregister.com/feed/www.theregister.com/2023/01/17/microsoft_windows_pro_guest/
Related news
- Microsoft says premature patch could make Windows Recall forget how to work (source)
- Microsoft says having a TPM is "non-negotiable" for Windows 11 (source)
- Microsoft lifts Windows 11 24H2 block on PCs with USB scanners (source)
- Microsoft says Auto HDR causes game freezes on Windows 11 24H2 (source)
- Microsoft adds another problem to the Windows 11 24H2 naughty list (source)
- Microsoft may have scrapped Windows 11's dynamic wallpapers feature (source)
- Microsoft to force install new Outlook on Windows 10 PCs in February (source)
- Microsoft 365 apps crash on Windows Server after Office update (source)
- Microsoft fixes actively exploited Windows Hyper-V zero-day flaws (source)
- Microsoft ends support for Office apps on Windows 10 in October (source)