I found an account named ILS_ANONYMOUS_USER in our environment. It was created in 2004 and has the description "Anonymous Account for ILS Server." Some documentation suggests it may be used for inter-server communication, so disabling it could affect services, but I have not found clear evidence that it is still needed. Has anyone disabled this account successfully, and what should I check before doing so?
4 Answers
Rather than simply disabling it and waiting for someone to complain, first search authentication and process logs for recent use. If you have a maintenance window, disable the account in a controlled manner, monitor services and authentication failures, and keep a documented rollback plan. If it is not used, leaving an old account enabled only increases the attack surface.
The account’s last logon is a useful first check. If it has not been used for more than a year, that is encouraging, but it does not prove the account is unused—some services may authenticate in ways that are not reflected there. Review domain-controller security logs or configure Windows Event Forwarding to identify the source machines and account activity before making a decision.
ILS was an old directory-based service associated with dynamic name-to-IP registration and inter-server communication. In a modern environment it is probably legacy compatibility baggage, but the account’s purpose depends entirely on what is still running in your environment. Do not assume the generic documentation applies unchanged to your domain.
Check whether your organization runs an integrated library system or another older application that might use this account. The name can refer to library software, and disabling it in that kind of environment could interrupt an important service. Confirm with application owners before making the change.

The last logon was about a year and a half ago, although a coworker may have used it manually. I’ll confirm that and review the logs before changing anything.