Local administrative shares such as C$, ADMIN$, and IPC$ are created by default on Windows Server and are intended for remote administration. By design, if a user connects over the network using credentials that are members of the local Administrators group on the server, that user can access these administrative shares.
In the scenario described, the key factor is not that the workstation is non–domain-joined, but that the credentials used over the network are recognized as administrative on the target server. For example:
- If the same local administrator account (same name and password) exists on both the non-domain Windows 11 workstation and the Windows Server, Windows can treat that as the same security principal and grant access.
- Administrative shares are hidden (C$, ADMIN$) but not restricted to domain accounts; they are available to any account that has administrative rights on the server.
This behavior is not new; administrative shares have long been used for remote management and are automatically created on Windows Server.
To mitigate or remove this access:
- Verify and control administrative shares
- On the server, check whether the default administrative shares are enabled:
- Open Registry Editor.
- Navigate to
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanmanServer\Parameters.
- Check the
AutoShareServer (for servers) or AutoShareWks (for workstations) values.
- If they exist and are set to
0, administrative shares are disabled; if set to 1, they are enabled.
- If these values do not exist, the default behavior is to automatically create the administrative shares.
- After changes, restart the server and verify with
net share that Admin$, C$, and IPC$ are or are not present as desired.
- Be aware that disabling administrative shares can impact legitimate remote administration and some services.
- Harden who can access administrative shares
- Ensure that only trusted accounts are members of the local Administrators group on each server.
- Avoid reusing the same local administrator name/password combinations on multiple machines, especially between servers and non-domain workstations.
- Prefer domain accounts with least-privilege assignments for administration.
- Monitor and secure SMB/file services
- Review SMB/file service security options (for example, SMB signing, NTLM restrictions, and other SMB security enhancements) to ensure that only authenticated and authorized users can access shares.
These steps reduce or eliminate the ability of local administrators on non-domain machines to access default administrative shares on domain-joined servers, while still allowing necessary management where explicitly configured.
References: