Article ID: 323467 - Last Review: October 30, 2006 - Revision: 2.1 Issues that occur after you implement the Microsoft Baseline Security Analyzer recommendations in SBS 2000This article was previously published under Q323467 Important This article contains information about how to modify the registry. Make sure to back up the registry before you modify it. Make sure that you know how to restore the registry if a problem occurs. For more information about how to back up, restore, and modify the registry, click the following article number to view the article in the Microsoft Knowledge Base: 256986
(http://support.microsoft.com/kb/256986/
)
Description of the Microsoft Windows registry On This PageSUMMARY
This article describes some of the issues that may occur after you implement the recommendations made by Microsoft Baseline Security Analyzer (MBSA) on a computer that is running Small Business Server (SBS) 2000.
MORE INFORMATIONRestrict AnonymousWarning Serious problems might occur if you modify the registry incorrectly by using Registry Editor or by using another method. These problems might require that you reinstall your operating system. Microsoft cannot guarantee that these problems can be solved. Modify the registry at your own risk.MBSA recommends that you complete the following task:
Set RestrictAnonymous=2 to ensure maximum security.
If you click How to correct this, you receive the following message in the Caution section:
It is recommended that you do not set this value to 2 on Domain Controllers in mixed-mode environments.
If you have applied either the Q299687 Windows 2000 security hotfix or the Q311401 Windows 2000 security rollup package to the SBS 2000 server and you set the RestrictAnonymous value to 2 in the registry, you may experience one or more of the following issues:
For more information, click the following article number to view the article in the Microsoft Knowledge Base: 260910
(http://support.microsoft.com/kb/260910/
)
How to obtain the latest Windows 2000 service pack
How to obtain Small Business Server 2000 Service Pack 1a326924
(http://support.microsoft.com/kb/326924/
)
How to obtain Small Business Server 2000 Service Pack 1a
ServicesMBSA may send the following message:
Some potentially unnecessary services are installed.
If you click Result Details, MBSA displays the list of potentially unnecessary services that are installed. The following services may be listed:
IIS Lockdown ToolMBSA may send the following message:
The IIS Lockdown tool has not been run on the machine.
In Exchange 2000 environments, you cannot use the lockdown tool with Exchange 2000 installable file system (IFS) mounted drives (typically, drive M). To use the lockdown tool on Exchange 2000 servers, including SBS 2000 servers, see to the following Microsoft Knowledge Base article.309508
(http://support.microsoft.com/kb/309508/EN-US/
)
XCCC: IIS Lockdown and URLscan Configurations in an Exchange Environment
REFERENCES
For more information, click the following article number to view the article in the Microsoft Knowledge Base:
246261
(http://support.microsoft.com/kb/246261/
)
How to use the RestrictAnonymous registry value in Windows 2000
309622
(http://support.microsoft.com/kb/309622/
)
Clients cannot browse the Global Address List after you apply the Q299687 Windows 2000 security hotfix
For more information about a Post-SP2 Windows hotfix that resolves the regression introduced by Q299687 (which resolves the issues that are described in the present article), click the following article number to view the article in the Microsoft Knowledge Base:
318866
(http://support.microsoft.com/kb/318866/
)
Outlook clients cannot view global address list after you install Security Rollup Package 1 (SR about a Post-SP2 Windows hotfix that resolves the regression introduced by Q299687 (which resolves the issues that are described in the present article)) on Global Catalog Server
| Article Translations
|
Back to the top
