Hello I am looking into better securing my Windows domain environment by following the steps per MS15-011 (KB3000483), where you use UNC hardening in Group Policy to specify the UNC paths domain workstations can connect to.
I'm a bit confused -- are you only suppose to add UNC paths to your domain controllers?
Or does this mean you're supposed to add any potential UNC path for any server, that any potential domain workstation or server could possible connect to (like a file share or anything else)?
Or is this only UNC path for Workstations pointing to Domain controller for group policy retrieval?
https://support.microsoft.com/en-us/kb/3000483
Like \\file01.domain.com\share1
Or the SCCM server for software deployments, or WSUS.
Or does this GPO not apply to UNC paths users may be accessing from their computer for things like that?
Only GPO's for computers?