New
#1
Domain users group - no domain?
Hi,
I'm using Windows 7 Home Premium x64, IE9, with Comodo Firewall and HIPs, Avast AV, MBAM, EMET and SAS.
I have one LUA and one Admin a/c, both strong passworded---Guest a/c is disabled, Real Administrator is enabled, passworded, and never used. I'm behind a router with no network or file & printer sharing and have all recommended blocks on my firewall.
I've just replaced my admin and lua accounts after finding a lot of null sid logon fails at all my accounts over a few months. It might have been a self-snafu, but I seem to have cured the issue. All except Type 3 Anon Logons at every boot, but i read somewhere that too can be a snafu. I'll keep an eye on them.
Meanwhile, eventlog showed my old accounts being removed from a 'no name' global group that had the Domain users group sid S-1-5-21-*-*-*-513. The new accounts were both added to this 'no name' global group. I'm a workgroup pc, not domain.
Home premium doesn't have secpol and I can't get NET command to enlighten me on this domain group. Should I have any global/ domain groups?
Finally, Is there a way to enforce 'Do not allow enumeration of SAM accounts and shares from the Local policy' or disable 'Network access: Allow anonymous SID/Name translation' or equivalent on Win 7 Home Premium?
Cheers :)