Endpoint configuration · GraphQL type

NetworkAccessPolicy type

Controls anonymous access, shares, and remote access restrictions for the Windows network stack.

Fields

Field Name Description
restrictAnonymousSAM - Boolean Restrict anonymous SID/Name translation for SAM accounts.
restrictAnonymous - Boolean Restrict enumeration of SAM accounts.
disableDomainCreds - Boolean Restrict storage of passwords and credentials for network authentication.
everyoneIncludesAnonymous - Boolean Let everyone permissions apply to anonymous users.
nullSessionPipes - [String!] Named pipes that can be accessed anonymously.
allowedExactPaths - [String!] Remotely accessible registry paths.
allowedPaths - [String!] Remotely accessible registry path and sub-paths.
restrictNullSessAccess - Boolean Restrict anonymous access to named pipes and shares.
restrictRemoteSAM - String Restrict clients allowed to make remote calls to SAM.
nullSessionShares - [String!] Shares that can be accessed anonymously.
forceGuest - ForceGuestType Sharing and security model for local accounts.

Used by

Example

Example

{
  "restrictAnonymousSAM": false,
  "restrictAnonymous": true,
  "disableDomainCreds": false,
  "everyoneIncludesAnonymous": false,
  "nullSessionPipes": ["abc123"],
  "allowedExactPaths": ["abc123"],
  "allowedPaths": ["xyz789"],
  "restrictNullSessAccess": false,
  "restrictRemoteSAM": "xyz789",
  "nullSessionShares": ["xyz789"],
  "forceGuest": "LOCAL_USERS_AUTHENTICATE_AS_THEMSELVES"
}