The SharePoint Central Administration site must not be accessible from Extranet or Internet connections.

From MS SharePoint 2013 Security Technical Implementation Guide

Part of SRG-APP-000212

Associated with: CCI-001083

SV-74423r1_rule The SharePoint Central Administration site must not be accessible from Extranet or Internet connections.

Vulnerability discussion

SharePoint must prevent the presentation of information system management-related functionality at an interface utilized by general, (i.e., non-privileged), users. The Central Administrator is an application used to manage SharePoint system settings and the settings of the web applications running under SharePoint. The Central Administrator application should both be protected using a defense-in-depth approach. Regular users should not be able to access the Central Administrator as the first line of defense. The second line of defense is regular users do not have user ids defined in the Central Administration application.

Check content

Review the SharePoint server configuration to ensure Central Administration site is not accessible from Extranet or Internet connections. Check outside access to Central Administration. On an administrative work station, open Central Administration and make note of the URL (i.e., http://sharepointserver:7040). Try to open the Central Administration application on a regular user's workstation. Open a Web browser and type in the URL to Central Administration. If the Central Administration can be opened, this is a finding.

Fix text

Configure the SharePoint Central Administration site to not be accessible from Extranet or Internet connections. Block outside Central Administrator access. Use an IIS IP address restrictions, firewall, or other filtering solutions to limit access to Central Administration site.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer