I found an account named ILS_ANONYMOUS_USER in our environment. It was created in 2004 and has the description "Anonymous Account for ILS Server." Some documentation claims it may be used for inter-server communication and recommends not disabling it, but I haven't found reliable evidence confirming that. Has anyone actually disabled this account, and what should I check before doing so?
4 Answers
The last logon time is a useful clue. If it really hasn't logged on for roughly a year and a half, it is probably unused, although you should confirm whether an administrator or scheduled task accessed it. Check domain-controller security logs and enable Windows Event Forwarding so you can search which systems and source IPs have used the account. Also review scheduled tasks, services, scripts, and group memberships before disabling it.
ILS was associated with an older directory-based service for publishing names and current IP addresses, somewhat like an early dynamic-DNS system. An account this old may have been created for legacy compatibility, but that doesn't prove it is still needed. I wouldn't treat an undocumented, inactive account as harmless—verify its usage and plan a controlled disablement if nothing depends on it.
ILS can also mean an integrated library system. If this is a library environment, the account could belong to an old library-management application rather than a normal Windows component. Confirm whether any such software exists in the organization before changing the account.
Avoid simply disabling it and waiting to see what breaks. That kind of testing can cause an unexpected outage and still won't tell you what legitimate dependency was affected. Identify the owning service, review authentication events from all domain controllers, document a rollback plan, and then disable it during a maintenance window while monitoring for failures.

The last logon was about a year and a half ago, though a coworker may have used it manually. It isn't in any sensitive groups, but I'm still concerned that a compromised account could be used for lateral movement, so I'll check the logs and ask about that access first.