Policy Rules
CIS Microsoft Windows 11 Stand-alone Benchmark: 484 Checks
CIS Benchmark checks for stand-alone Microsoft Windows 11: account and local policies, system services, Windows Firewall, audit policy, and administrative templates.
The Center for Internet Security (CIS) is a nonprofit that publishes the CIS Benchmarks: consensus-developed secure configuration guides for operating systems, cloud platforms, and applications. Each benchmark enumerates numbered recommendations, most assigned a Level 1 (broadly safe hardening) or Level 2 (defense-in-depth, may reduce functionality) profile, together with the audit procedure and remediation for each. Wartiva maps a benchmark's recommendations onto policy rules so an endpoint's observed configuration can be assessed against the published baseline.
These checks apply to domain-joined and Intune-managed Windows 11 machines as well as stand-alone ones.
- High 109
- Medium 338
- Low 37
No checks match your filter.
1 Account Policies 11 checks
- Ensure Enforce Password History Is 24 Or More Passwords
- Ensure Maximum Password Age Is 365 Or Fewer Days And Not Zero
- Ensure Minimum Password Age Is One Or More Days
- Ensure Minimum Password Length Is 14 Or More Characters
- Ensure Password Complexity Requirements Are Enabled
- Ensure Relax Minimum Password Length Limits Is Enabled
- Ensure Store Passwords Using Reversible Encryption Is Disabled
- Ensure Account Lockout Duration Is 15 Or More Minutes
- Ensure Account Lockout Threshold Is Five Or Fewer Attempts And Not Zero
- Ensure Allow Administrator Account Lockout Is Enabled
- Ensure Reset Account Lockout Counter Is 15 Or More Minutes
2.2 User Rights Assignment 38 checks
- Ensure 'Access Credential Manager as a trusted caller' Is Set To No One
- Ensure 'Access this computer from the network' Is Set To 'Administrators, Remote Desktop Users'
- Ensure 'Act as part of the operating system' Is Set To No One
- Ensure 'Adjust memory quotas for a process' Is Set To 'Administrators, LOCAL SERVICE, NETWORK SERVICE'
- Ensure 'Allow log on locally' Is Set To 'Administrators, Users'
- Ensure 'Allow log on through Remote Desktop Services' Is Set To 'Administrators, Remote Desktop Users'
- Ensure 'Back up files and directories' Is Set To 'Administrators'
- Ensure 'Change the system time' Is Set To 'Administrators, LOCAL SERVICE'
- Ensure 'Create a pagefile' Is Set To 'Administrators'
- Ensure 'Create a token object' Is Set To No One
- Ensure 'Create global objects' Is Set To 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE'
- Ensure 'Create permanent shared objects' Is Set To No One
- Ensure 'Create symbolic links' Is Set To 'Administrators'
- Ensure 'Debug programs' Is Set To 'Administrators'
- Ensure 'Deny access to this computer from the network' Is Set To Include Guests
- Ensure 'Deny log on as a batch job' Is Set To Include Guests
- Ensure 'Deny log on as a service' Is Set To Include Guests
- Ensure 'Deny log on locally' Is Set To Include Guests
- Ensure 'Deny log on through Remote Desktop Services' Is Set To Include Guests
- Ensure 'Enable computer and user accounts to be trusted for delegation' Is Set To No One
- Ensure 'Force shutdown from a remote system' Is Set To 'Administrators'
- Ensure 'Generate security audits' Is Set To 'LOCAL SERVICE, NETWORK SERVICE, RESTRICTED SERVICES\PrintSpoolerService'
- Ensure 'Impersonate a client after authentication' Is Set To 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE, RESTRICTED SERVICES\PrintSpoolerService'
- Ensure 'Increase scheduling priority' Is Set To 'Administrators, Window Manager\Window Manager Group'
- Ensure 'Load and unload device drivers' Is Set To 'Administrators'
- Ensure 'Lock pages in memory' Is Set To No One
- Ensure 'Log on as a batch job' Is Set To 'Administrators'
- Ensure 'Log on as a service' Is Set To No One
- Ensure 'Manage auditing and security log' Is Set To 'Administrators'
- Ensure 'Modify an object label' Is Set To No One
- Ensure 'Modify firmware environment values' Is Set To 'Administrators'
- Ensure 'Perform volume maintenance tasks' Is Set To 'Administrators'
- Ensure 'Profile single process' Is Set To 'Administrators'
- Ensure 'Profile system performance' Is Set To 'Administrators, NT SERVICE\WdiServiceHost'
- Ensure 'Replace a process level token' Is Set To 'LOCAL SERVICE, NETWORK SERVICE'
- Ensure 'Restore files and directories' Is Set To 'Administrators'
- Ensure 'Shut down the system' Is Set To 'Administrators, Users'
- Ensure 'Take ownership of files or other objects' Is Set To 'Administrators'
2.3 Security Options 53 checks
- Ensure Guest Account Status Is Disabled
- Ensure Local Account Use Of Blank Passwords Is Limited To Console Logon Only
- Ensure The Built-in Administrator Account Is Renamed
- Ensure The Built-in Guest Account Is Renamed
- Ensure Audit Policy Subcategory Settings Override Category Settings
- Ensure The System Does Not Shut Down When Unable To Log Security Audits
- Ensure Users Are Prevented From Installing Printer Drivers
- Ensure A Logon Message Text For Users Attempting To Log On Is Configured
- Ensure A Logon Message Title For Users Attempting To Log On Is Configured
- Ensure CTRL+ALT+DEL Is Required For Logon
- Ensure Machine Inactivity Limit Is 900 Or Fewer Seconds And Not Zero
- Ensure Smart Card Removal Behavior Is Lock Workstation Or Higher
- Ensure The Last Signed-in User Is Not Displayed
- Ensure Users Are Prompted To Change Password Between 5 And 14 Days Before Expiration
- Ensure Microsoft Network Client Digitally Signs Communications Always
- Ensure Unencrypted Passwords Are Not Sent To Third-party SMB Servers
- Ensure Clients Are Disconnected When Logon Hours Expire
- Ensure Idle Time Before Suspending A Session Is 15 Or Fewer Minutes
- Ensure Microsoft Network Server Digitally Signs Communications Always
- Ensure Server SPN Target Name Validation Level Is Accept If Provided By Client Or Higher
- Ensure Anonymous Access To Named Pipes And Shares Is Restricted
- Ensure Anonymous Enumeration Of SAM Accounts And Shares Is Not Allowed
- Ensure Anonymous Enumeration Of SAM Accounts Is Not Allowed
- Ensure Clients Allowed To Make Remote Calls To SAM Are Restricted
- Ensure Everyone Permissions Do Not Apply To Anonymous Users
- Ensure No Named Pipes Can Be Accessed Anonymously
- Ensure No Shares Can Be Accessed Anonymously
- Ensure Remotely Accessible Registry Paths And Sub-paths Are Configured
- Ensure Remotely Accessible Registry Paths Are Configured
- Ensure Sharing And Security Model For Local Accounts Is Classic
- Ensure Storage Of Passwords And Credentials For Network Authentication Is Not Allowed
- Ensure Incoming NTLM Traffic Auditing Is Enabled For All Accounts
- Ensure Kerberos Encryption Types Are Limited To AES
- Ensure LAN Manager Authentication Level Refuses LM And NTLM
- Ensure LDAP Client Encryption Requirements Are Negotiate Sealing Or Higher
- Ensure LDAP Client Signing Requirements Are Negotiate Signing Or Higher
- Ensure Local System Uses Computer Identity For NTLM
- Ensure LocalSystem NULL Session Fallback Is Disabled
- Ensure Minimum NTLM Session Security For Clients Requires NTLMv2 And 128-bit Encryption
- Ensure Minimum NTLM Session Security For Servers Requires NTLMv2 And 128-bit Encryption
- Ensure Outgoing NTLM Traffic To Remote Servers Is Audited Or Denied
- Ensure PKU2U Authentication Requests Do Not Use Online Identities
- Ensure Strong Key Protection For User Keys Requires A Prompt Or Password
- Ensure Case Insensitivity Is Required For Non-Windows Subsystems
- Ensure Default Permissions Of Internal System Objects Are Strengthened
- Ensure Admin Approval Mode For The Built-in Administrator Account Is Enabled
- Ensure All Administrators Run In Admin Approval Mode
- Ensure Application Installations Are Detected And Prompt For Elevation
- Ensure File And Registry Write Failures Are Virtualized To Per-user Locations
- Ensure Only UIAccess Applications In Secure Locations Are Elevated
- Ensure The Elevation Prompt For Administrators Uses The Secure Desktop
- Ensure The Elevation Prompt For Standard Users Automatically Denies Elevation
- Ensure The Secure Desktop Is Used When Prompting For Elevation
5 System Services 44 checks
- Ensure Bluetooth Audio Gateway Service Is Disabled
- Ensure Bluetooth Support Service Is Disabled
- Ensure Computer Browser Service Is Disabled
- Ensure Downloaded Maps Manager Service Is Disabled
- Ensure GameInput Service Is Disabled
- Ensure Geolocation Service Is Disabled
- Ensure IIS Admin Service Is Disabled
- Ensure Infrared Monitor Service Is Disabled
- Ensure Link-Layer Topology Discovery Mapper Service Is Disabled
- Ensure Microsoft FTP Service Is Disabled
- Ensure Microsoft iSCSI Initiator Service Is Disabled
- Ensure OpenSSH SSH Server Is Disabled
- Ensure Peer Name Resolution Protocol Service Is Disabled
- Ensure Peer Networking Grouping Service Is Disabled
- Ensure Peer Networking Identity Manager Service Is Disabled
- Ensure PNRP Machine Name Publication Service Is Disabled
- Ensure Print Spooler Service Is Disabled
- Ensure Problem Reports And Solutions Control Panel Support Is Disabled
- Ensure Remote Access Auto Connection Manager Is Disabled
- Ensure Remote Desktop Configuration Service Is Disabled
- Ensure Remote Desktop Services Is Disabled
- Ensure Remote Desktop Services UserMode Port Redirector Is Disabled
- Ensure Remote Procedure Call (RPC) Locator Is Disabled
- Ensure Remote Registry Service Is Disabled
- Ensure Routing And Remote Access Service Is Disabled
- Ensure Server Service Is Disabled
- Ensure Simple TCP/IP Services Is Disabled
- Ensure SNMP Service Is Disabled
- Ensure Special Administration Console Helper Is Disabled
- Ensure SSDP Discovery Service Is Disabled
- Ensure UPnP Device Host Is Disabled
- Ensure Web Management Service Is Disabled
- Ensure Windows Error Reporting Service Is Disabled
- Ensure Windows Event Collector Service Is Disabled
- Ensure Windows Media Player Network Sharing Service Is Disabled
- Ensure Windows Mobile Hotspot Service Is Disabled
- Ensure Windows Push Notifications System Service Is Disabled
- Ensure Windows PushToInstall Service Is Disabled
- Ensure Windows Remote Management (WS-Management) Is Disabled
- Ensure World Wide Web Publishing Service Is Disabled
- Ensure Xbox Accessory Management Service Is Disabled
- Ensure Xbox Live Auth Manager Is Disabled
- Ensure Xbox Live Game Save Is Disabled
- Ensure Xbox Live Networking Service Is Disabled
9 Windows Defender Firewall with Advanced Security 14 checks
- Ensure Windows Firewall Private Profile Blocked-Program Notifications Are Disabled
- Ensure Windows Firewall Private Profile Inbound Connections Are Blocked By Default
- Ensure Windows Firewall Private Profile Logging File Path Is Configured
- Ensure Windows Firewall Private Profile Logging Size Limit Is 16,384 KB Or Greater
- Ensure Windows Firewall Private Profile Logs Dropped Packets
- Ensure Windows Firewall Private Profile Logs Successful Connections
- Ensure Windows Firewall Private Profile State Is On
- Ensure Windows Firewall Public Profile Blocked-Program Notifications Are Disabled
- Ensure Windows Firewall Public Profile Inbound Connections Are Blocked By Default
- Ensure Windows Firewall Public Profile Logging File Path Is Configured
- Ensure Windows Firewall Public Profile Logging Size Limit Is 16,384 KB Or Greater
- Ensure Windows Firewall Public Profile Logs Dropped Packets
- Ensure Windows Firewall Public Profile Logs Successful Connections
- Ensure Windows Firewall Public Profile State Is On
17 Advanced Audit Policy Configuration 27 checks
- Ensure Credential Validation Auditing Is Set To Success And Failure
- Ensure Application Group Management Auditing Is Set To Success And Failure
- Ensure Security Group Management Auditing Is Set To Include Success
- Ensure User Account Management Auditing Is Set To Success And Failure
- Ensure PNP Activity Auditing Is Set To Include Success
- Ensure Process Creation Auditing Is Set To Include Success
- Ensure Account Lockout Auditing Is Set To Include Failure
- Ensure Group Membership Auditing Is Set To Include Success
- Ensure Logoff Auditing Is Set To Include Success
- Ensure Logon Auditing Is Set To Success And Failure
- Ensure Other Logon/Logoff Events Auditing Is Set To Success And Failure
- Ensure Special Logon Auditing Is Set To Include Success
- Ensure Detailed File Share Auditing Is Set To Include Failure
- Ensure File Share Auditing Is Set To Success And Failure
- Ensure Other Object Access Events Auditing Is Set To Success And Failure
- Ensure Removable Storage Auditing Is Set To Success And Failure
- Ensure Audit Policy Change Auditing Is Set To Include Success
- Ensure Authentication Policy Change Auditing Is Set To Include Success
- Ensure Authorization Policy Change Auditing Is Set To Include Success
- Ensure MPSSVC Rule-Level Policy Change Auditing Is Set To Success And Failure
- Ensure Other Policy Change Events Auditing Is Set To Include Failure
- Ensure Sensitive Privilege Use Auditing Is Set To Success
- Ensure IPsec Driver Auditing Is Set To Success And Failure
- Ensure Other System Events Auditing Is Set To Success And Failure
- Ensure Security State Change Auditing Is Set To Include Success
- Ensure Security System Extension Auditing Is Set To Include Success
- Ensure System Integrity Auditing Is Set To Success And Failure
18.1 Control Panel 4 checks
18.4 MS Security Guide 6 checks
18.5 MSS (Legacy) 12 checks
- Ensure Automatic Logon Is Disabled
- Ensure Computer Ignores NetBIOS Name Release Requests Except From WINS Servers
- Ensure ICMP Redirects Cannot Override OSPF Generated Routes
- Ensure IPv4 IP Source Routing Is Set To Highest Protection
- Ensure IPv4 TCP Maximum Data Retransmissions Is Set To Three
- Ensure IPv6 IP Source Routing Is Set To Highest Protection
- Ensure IPv6 TCP Maximum Data Retransmissions Is Set To Three
- Ensure IRDP Router Discovery Is Disabled
- Ensure Safe DLL Search Mode Is Enabled
- Ensure Saving Of Dial-up And VPN Passwords Is Prevented
- Ensure Security Event Log Warning Threshold Is 90 Percent Or Less
- Ensure TCP Keep-Alive Time Is Set To Five Minutes
18.6 Network 27 checks
- Ensure Default IPv6 DNS Servers Are Turned Off
- Ensure Font Providers Are Disabled
- Ensure SMB Server Audits Clients That Do Not Support Encryption
- Ensure SMB Server Audits Clients That Do Not Support Signing
- Ensure SMB Server Audits Insecure Guest Logons
- Ensure SMB Server Authentication Rate Limiter Delay Is 2000 Milliseconds Or More
- Ensure SMB Server Authentication Rate Limiter Is Enabled
- Ensure SMB Server Minimum Version Is Mandated As 3.1.1
- Ensure SMB Server Remote Mailslots Are Disabled
- Ensure SMB Client Audits Insecure Guest Logons
- Ensure SMB Client Audits Servers That Do Not Support Encryption
- Ensure SMB Client Audits Servers That Do Not Support Signing
- Ensure SMB Client Insecure Guest Logons Are Disabled
- Ensure SMB Client Minimum Version Is Mandated As 3.1.1
- Ensure SMB Client Remote Mailslots Are Disabled
- Ensure SMB Client Requires Encryption
- Ensure Mapper I/O (LLTDIO) Driver Is Disabled
- Ensure Responder (RSPNDR) Driver Is Disabled
- Ensure Microsoft Peer-To-Peer Networking Services Are Turned Off
- Ensure Installation And Configuration Of Network Bridge Is Prohibited
- Ensure Use Of Internet Connection Sharing Is Prohibited
- Ensure Hardened UNC Paths Are Configured For NETLOGON And SYSVOL Shares
- Ensure IPv6 Is Disabled Via DisabledComponents
- Ensure Access Of The Windows Connect Now Wizards Is Prohibited
- Ensure Configuration Of Wireless Settings Using Windows Connect Now Is Disabled
- Ensure Simultaneous Connections To The Internet Or A Windows Domain Are Minimized
- Ensure Automatic Connection To Suggested Open Hotspots Is Disabled
18.7 Printers 18 checks
- Ensure Incoming Printer RPC Connections Use Negotiate Authentication Or Higher
- Ensure Incoming Printer RPC Connections Use RPC Over TCP
- Ensure IPP Printers Disallow An Invalid Certificate Authority
- Ensure IPP Printers Disallow An Invalid Certificate Common Name
- Ensure IPP Printers Disallow An Invalid Certificate Date
- Ensure IPP Printers Disallow Non-Server Certificates
- Ensure IPPS Is Required For IPP Printers
- Ensure Outgoing Printer RPC Connections Use Default Authentication
- Ensure Outgoing Printer RPC Connections Use RPC Over TCP
- Ensure Point And Print Shows Warning And Elevation Prompt When Installing New Drivers
- Ensure Point And Print Shows Warning And Elevation Prompt When Updating Existing Drivers
- Ensure Print Driver Installation Is Limited To Administrators
- Ensure Print Spooler Does Not Accept Client Connections
- Ensure Printer Redirection Guard Is Enabled
- Ensure Printer RPC Over TCP Port Is Set To Zero
- Ensure Queue-Specific Files Are Limited To Color Profiles
- Ensure RPC Packet Level Privacy Is Enabled For Incoming Printer Connections
- Ensure Windows Protected Print Is Enabled
18.8 Start Menu and Taskbar 2 checks
18.9 System 57 checks
- Ensure The Sudo Command Is Disabled
- Ensure Command Line Is Included In Process Creation Events
- Ensure Encryption Oracle Remediation Forces Updated Clients
- Ensure Remote Host Delegation Of Non-Exportable Credentials Is Enabled
- Ensure Credential Guard Is Enabled With UEFI Lock
- Ensure Kernel Mode Hardware Enforced Stack Protection Is In Enforcement Mode
- Ensure Secure Launch Is Enabled
- Ensure Virtualization Based Protection Of Code Integrity Uses UEFI Lock
- Ensure Virtualization Based Security Is Enabled
- Ensure Virtualization Based Security Platform Level Is Secure Boot Or Higher
- Ensure Virtualization Based Security Requires UEFI Memory Attributes Table
- Ensure Automatic Download Of Device Metadata From The Internet Is Prevented
- Ensure Device Setup Class Restrictions Apply To Already Installed Devices
- Ensure IEEE 1394 Device Setup Classes Are In The Prevented Device List
- Ensure Installation Of Devices Matching Configured Setup Classes Is Prevented
- Ensure Boot Start Driver Initialization Allows Good Unknown And Critical Bad Drivers
- Ensure CLFS Logfile Authentication Is Enabled
- Ensure Continue Experiences On This Device Is Disabled
- Ensure Access To The Store For Unknown File Types Is Turned Off
- Ensure Downloading Of Print Drivers Over HTTP Is Turned Off
- Ensure Handwriting Personalization Data Sharing Is Turned Off
- Ensure Handwriting Recognition Error Reporting Is Turned Off
- Ensure Internet Connection Wizard Cannot Connect To Microsoft.com
- Ensure Internet Download For Web Publishing And Ordering Wizards Is Turned Off
- Ensure Printing Over HTTP Is Turned Off
- Ensure Registration Referring To Microsoft.com Is Turned Off
- Ensure Search Companion Content File Updates Are Turned Off
- Ensure The Order Prints Picture Task Is Turned Off
- Ensure The Publish To Web Task For Files And Folders Is Turned Off
- Ensure The Windows Customer Experience Improvement Program Is Turned Off
- Ensure The Windows Messenger Customer Experience Improvement Program Is Turned Off
- Ensure Windows Error Reporting Is Turned Off
- Ensure Device Authentication Using Certificate Is Set To Automatic
- Ensure External Devices Incompatible With Kernel DMA Protection Are Blocked
- Ensure Custom SSPs And APs Cannot Be Loaded Into LSASS
- Ensure LSASS Runs As A Protected Process With UEFI Lock
- Ensure Copying Of User Input Methods To The System Account For Sign In Is Disallowed
- Ensure App Notifications On The Lock Screen Are Turned Off
- Ensure Convenience PIN Sign In Is Disabled
- Ensure The Network Selection UI Is Not Displayed
- Ensure Users Are Blocked From Showing Account Details On Sign In
- Ensure Clipboard Synchronization Across Devices Is Disabled
- Ensure Upload Of User Activities Is Disabled
- Ensure A Password Is Required When Waking On Battery
- Ensure A Password Is Required When Waking Plugged In
- Ensure Network Connectivity During Connected Standby On Battery Is Disabled
- Ensure Network Connectivity During Connected Standby Plugged In Is Disabled
- Ensure Standby States When Sleeping On Battery Are Disabled
- Ensure Standby States When Sleeping Plugged In Are Disabled
- Ensure Offer Remote Assistance Is Disabled
- Ensure Solicited Remote Assistance Is Disabled
- Ensure RPC Endpoint Mapper Client Authentication Is Enabled
- Ensure Unauthenticated RPC Clients Are Restricted
- Ensure MSDT Interactive Communication With Support Provider Is Disabled
- Ensure PerfTrack Is Disabled
- Ensure The Advertising ID Is Turned Off
- Ensure The Windows NTP Client Is Enabled
18.10 Windows Components 158 checks
- Ensure App And Device Inventory API Sampling Is Turned Off
- Ensure App And Device Inventory Application Footprint Is Turned Off
- Ensure App And Device Inventory Install Tracing Is Turned Off
- Ensure Non-Admin Users Are Prevented From Installing Packaged Windows Apps
- Ensure Per-User Unsigned Package Installation Is Disallowed By Default
- Ensure Windows Apps Are Prevented From Sharing Application Data Between Users
- Ensure Voice Activation Of Apps While The System Is Locked Is Forced Off
- Ensure Launching Universal Windows Apps With WinRT Access From Hosted Content Is Blocked
- Ensure Microsoft Accounts Are Optional For Store Apps
- Ensure Autoplay Is Disallowed For Non-Volume Devices
- Ensure Autoplay Is Turned Off For All Drives
- Ensure The Default AutoRun Behavior Does Not Execute Any AutoRun Commands
- Ensure Enhanced Anti-Spoofing For Facial Features Is Enabled
- Ensure A 256-Bit Recovery Key Is Allowed For BitLocker-Protected Fixed Data Drives
- Ensure A 48-Digit Recovery Password Is Allowed For BitLocker-Protected Fixed Data Drives
- Ensure A Data Recovery Agent Is Allowed For BitLocker-Protected Fixed Data Drives
- Ensure Access To BitLocker-Protected Fixed Data Drives From Earlier Windows Versions Is Disabled
- Ensure Hardware-Based Encryption For BitLocker Fixed Data Drives Is Disabled
- Ensure Password Unlock For BitLocker Fixed Data Drives Is Disabled
- Ensure Recovery Of BitLocker-Protected Fixed Data Drives Is Configured
- Ensure Recovery Options Are Omitted From The BitLocker Setup Wizard For Fixed Data Drives
- Ensure Smart Card Use For BitLocker Fixed Data Drives Is Enabled
- Ensure Smart Card Use Is Required For BitLocker Fixed Data Drives
- Ensure A 256-Bit Recovery Key Is Not Allowed For BitLocker-Protected Operating System Drives
- Ensure A 48-Digit Recovery Password Is Required For BitLocker-Protected Operating System Drives
- Ensure A Data Recovery Agent Is Not Allowed For BitLocker-Protected Operating System Drives
- Ensure Enhanced PINs For BitLocker Startup Are Allowed
- Ensure Hardware-Based Encryption For BitLocker Operating System Drives Is Disabled
- Ensure Recovery Of BitLocker-Protected Operating System Drives Is Configured
- Ensure Recovery Options Are Omitted From The BitLocker Setup Wizard For Operating System Drives
- Ensure Secure Boot For BitLocker Integrity Validation Is Allowed
- Ensure A 256-Bit Recovery Key Is Not Allowed For BitLocker-Protected Removable Data Drives
- Ensure A 48-Digit Recovery Password Is Not Allowed For BitLocker-Protected Removable Data Drives
- Ensure A Data Recovery Agent Is Allowed For BitLocker-Protected Removable Data Drives
- Ensure Access To BitLocker-Protected Removable Data Drives From Earlier Windows Versions Is Disabled
- Ensure Cross-Organization Write Access For BitLocker Removable Drives Is Not Denied
- Ensure Hardware-Based Encryption For BitLocker Removable Data Drives Is Disabled
- Ensure Password Unlock For BitLocker Removable Data Drives Is Disabled
- Ensure Recovery Of BitLocker-Protected Removable Data Drives Is Configured
- Ensure Recovery Options Are Omitted From The BitLocker Setup Wizard For Removable Data Drives
- Ensure Smart Card Use For BitLocker Removable Data Drives Is Enabled
- Ensure Smart Card Use Is Required For BitLocker Removable Data Drives
- Ensure Write Access To Removable Drives Not Protected By BitLocker Is Denied
- Ensure Use Of The Camera Is Disabled
- Ensure Cloud Consumer Account State Content Is Turned Off
- Ensure Cloud Optimized Content Is Turned Off
- Ensure Microsoft Consumer Experiences Are Turned Off
- Ensure A PIN Is Required For Wireless Display Pairing
- Ensure Administrator Accounts Are Not Enumerated On Elevation
- Ensure Security Questions For Local Accounts Are Prevented
- Ensure The Password Reveal Button Is Not Displayed
- Ensure Authenticated Proxy Usage For The Connected User Experience And Telemetry Service Is Disabled
- Ensure Diagnostic Data Is Limited To Required Or Off
- Ensure Diagnostic Log Collection Is Limited
- Ensure Dump Collection Is Limited
- Ensure Feedback Notifications Are Not Shown
- Ensure OneSettings Auditing Is Enabled
- Ensure Delivery Optimization Download Mode Is Not Set To Internet
- Ensure App Installer Experimental Features Are Disabled
- Ensure App Installer Hash Override Is Disabled
- Ensure App Installer Local Archive Malware Scan Override Is Disabled
- Ensure App Installer Microsoft Store Source Certificate Validation Bypass Is Disabled
- Ensure The App Installer Is Disabled
- Ensure The App Installer Ms-Appinstaller Protocol Is Disabled
- Ensure Windows Package Manager Command Line Interfaces Are Disabled
- Ensure The Application Event Log Maximum Size Is At Least 32,768 KB
- Ensure The Application Event Log Overwrites Events When Full
- Ensure The Security Event Log Maximum Size Is At Least 196,608 KB
- Ensure The Security Event Log Overwrites Events When Full
- Ensure The Setup Event Log Maximum Size Is At Least 32,768 KB
- Ensure The Setup Event Log Overwrites Events When Full
- Ensure The System Event Log Maximum Size Is At Least 32,768 KB
- Ensure The System Event Log Overwrites Events When Full
- Ensure Account-Based Insights And Recommended Files In File Explorer Are Turned Off
- Ensure Data Execution Prevention For File Explorer Is Not Turned Off
- Ensure Heap Termination On Corruption Is Not Turned Off
- Ensure Shell Protocol Protected Mode Is Not Turned Off
- Ensure The Mark Of The Web Tag Is Applied To Files From Insecure Sources
- Ensure The Location Feature Is Turned Off
- Ensure Message Service Cloud Sync Is Disabled
- Ensure Consumer Microsoft Account User Authentication Is Blocked
- Ensure Auditing Events In Microsoft Defender Application Guard Are Allowed
- Ensure Camera And Microphone Access In Microsoft Defender Application Guard Is Disabled
- Ensure Data Persistence For Microsoft Defender Application Guard Is Disabled
- Ensure Downloading And Saving Files To The Host From Microsoft Defender Application Guard Is Disabled
- Ensure Microsoft Defender Application Guard Clipboard Is Limited To Isolated-Session-To-Host
- Ensure Microsoft Defender Application Guard Is Turned On In Managed Mode For Edge
- Ensure News And Interests On The Taskbar Is Disabled
- Ensure Use Of OneDrive For File Storage Is Prevented
- Ensure Turn Off Push To Install Service Is Enabled
- Ensure Disable Cloud Clipboard Integration For Server To Client Is Enabled
- Ensure Do Not Allow Passwords To Be Saved Is Enabled
- Ensure Allow Users To Connect Remotely By Using Remote Desktop Services Is Disabled
- Ensure Allow UI Automation Redirection Is Disabled
- Ensure Do Not Allow Drive Redirection Is Enabled
- Ensure Do Not Allow Location Redirection Is Enabled
- Ensure Do Not Allow LPT Port Redirection Is Enabled
- Ensure Do Not Allow Supported Plug And Play Device Redirection Is Enabled
- Ensure Do Not Allow WebAuthn Redirection Is Enabled
- Ensure Restrict Clipboard Transfer From Server To Client Is Set To Disable Clipboard Transfers
- Ensure Always Prompt For Password Upon Connection Is Enabled
- Ensure Require Secure RPC Communication Is Enabled
- Ensure Require Use Of Specific Security Layer For Remote Connections Is Set To SSL
- Ensure Require User Authentication For Remote Connections By Using Network Level Authentication Is Enabled
- Ensure Set Client Connection Encryption Level Is Set To High Level
- Ensure Set Time Limit For Active But Idle Remote Desktop Services Sessions Is 15 Minutes Or Less
- Ensure Temporary Folders Are Deleted Upon Remote Desktop Session Exit
- Ensure Prevent Downloading Of Enclosures Is Enabled
- Ensure Allow Cloud Search Is Set To Disable Cloud Search
- Ensure Allow Cortana Above Lock Screen Is Disabled
- Ensure Allow Cortana Is Disabled
- Ensure Allow Indexing Of Encrypted Files Is Disabled
- Ensure Allow Search And Cortana To Use Location Is Disabled
- Ensure Allow Search Highlights Is Disabled
- Ensure Turn Off KMS Client Online AVS Validation Is Enabled
- Ensure Disable All Apps From Microsoft Store Is Configured
- Ensure Turn Off Automatic Download And Install Of Updates Is Disabled
- Ensure Turn Off The Offer To Update To The Latest Version Of Windows Is Enabled
- Ensure Turn Off The Store Application Is Enabled
- Ensure Allow Widgets Is Disabled
- Ensure Allow Recall To Be Enabled Is Disabled
- Ensure Enhanced Phishing Protection Automatic Data Collection Is Enabled
- Ensure Enhanced Phishing Protection Notify Malicious Is Enabled
- Ensure Enhanced Phishing Protection Notify Password Reuse Is Enabled
- Ensure Enhanced Phishing Protection Notify Unsafe App Is Enabled
- Ensure Enhanced Phishing Protection Service Is Enabled
- Ensure Configure Windows Defender SmartScreen Is Set To Warn And Prevent Bypass
- Ensure Windows Game Recording And Broadcasting Is Disabled
- Ensure Enable Enhanced Sign In Security With Supported Peripherals Is Enabled
- Ensure Allow Suggested Apps In Windows Ink Workspace Is Disabled
- Ensure Allow Windows Ink Workspace Is Disabled Or On Without Access Above The Lock Screen
- Ensure Allow User Control Over Installs Is Disabled
- Ensure Always Install With Elevated Privileges Is Disabled
- Ensure Prevent Internet Explorer Security Prompt For Windows Installer Scripts Is Disabled
- Ensure Sign In And Lock Last Interactive User Automatically After A Restart Is Disabled
- Ensure Transmission Of The User Password In MPR Notifications Sent By Winlogon Is Disabled
- Ensure Turn On PowerShell Script Block Logging Is Enabled
- Ensure Turn On PowerShell Transcription Is Enabled
- Ensure WinRM Client Allow Basic Authentication Is Disabled
- Ensure WinRM Client Allow Unencrypted Traffic Is Disabled
- Ensure WinRM Client Disallow Digest Authentication Is Enabled
- Ensure Allow Remote Server Management Through WinRM Is Disabled
- Ensure Disallow WinRM From Storing RunAs Credentials Is Enabled
- Ensure WinRM Service Allow Basic Authentication Is Disabled
- Ensure WinRM Service Allow Unencrypted Traffic Is Disabled
- Ensure Allow Remote Shell Access Is Disabled
- Ensure Allow Clipboard Sharing With Windows Sandbox Is Disabled
- Ensure Allow Mapping Folders Into Windows Sandbox Is Disabled
- Ensure Allow Networking In Windows Sandbox Is Disabled
- Ensure Prevent Users From Modifying Exploit Protection Settings Is Enabled
- Ensure No Auto Restart With Logged On Users For Scheduled Automatic Updates Installations Is Disabled
- Ensure Configure Automatic Updates Is Enabled
- Ensure Configure Automatic Updates Scheduled Install Day Is Set To Every Day
- Ensure Enable Features Introduced Via Servicing That Are Off By Default Is Disabled
- Ensure Remove Access To Pause Updates Feature Is Enabled
- Ensure Enable Optional Updates Is Disabled
- Ensure Manage Preview Builds Is Disabled
- Ensure Select When Quality Updates Are Received Is Set To Zero Days
18.11 Custom Settings 2 checks
19 Administrative Templates (User) 11 checks
- Ensure Toast Notifications On The Lock Screen Are Turned Off
- Ensure Help Experience Improvement Program Is Turned Off
- Ensure Antivirus Programs Are Notified When Opening Attachments
- Ensure Zone Information Is Preserved In File Attachments
- Ensure All Windows Spotlight Features Are Turned Off
- Ensure Diagnostic Data Is Not Used For Tailored Experiences
- Ensure Spotlight Collection On Desktop Is Turned Off
- Ensure Third-Party Content Suggestions In Windows Spotlight Are Disabled
- Ensure Windows Spotlight On Lock Screen Is Disabled
- Ensure Users Are Prevented From Sharing Files Within Their Profile
- Ensure Windows Media Player Codec Download Is Prevented
See your environment the way it really exists
Wartiva is in early access. Request your spot and talk to the team that built the endpoint platform they always wished they had.