GPO policy: "Restrict Unauthenticated RPC clients" under Computer Configuration > Administrative Templates > System > Remote Procedure Call. Controls whether the RPC runtime on a server restricts unauthenticated RPC clients connecting to that server. Helps prevent anonymous access to RPC-exposed services. Registry: HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Rpc:RestrictRemoteClients (REG_DWORD). CIS Benchmark recommends value 1 (Authenticated) for most environments. Reference: Policy CSP - RemoteProcedureCall
Values
| Enum Value | Description |
|---|---|
|
|
None (registry value 0). No restrictions on remote RPC clients; anonymous connections are allowed. Default on Windows Server 2003 SP1 and older. |
|
|
Authenticated (registry value 1). Only authenticated remote RPC clients are allowed; anonymous calls are rejected except those arriving over named pipes (ncacn_np). Default on Windows Vista and later. CIS L1 recommended value. |
|
|
Authenticated without exceptions (registry value 2). All anonymous remote RPC calls are rejected with no exceptions — including calls that would otherwise be allowed over named pipes. Most restrictive. |
Used by
ComputerAdministrativeTemplatestype: Computer-specific Administrative Templates (ADMX) settings on an Endpoint.
Example
Example
"NONE"