CIS Microsoft Windows 11 Stand-alone Benchmark · Section 18.11

Windows 11 Custom Settings: 2 Checks

Wartiva runs 2 checks for section 18.11, Custom Settings, of the CIS Microsoft Windows 11 Stand-alone Benchmark. Each one lists what it finds, why it matters, and how to fix it.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →

All 2 checks on this page

Ensure HTTP Proxy Authentication Over Loopback Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.11

Finding: HTTP proxy authentication over loopback is allowed.

Checks whether Windows HTTP Services is prevented from authenticating over a loopback interface (at minimum) via the DisableProxyAuthenticationSchemes bitmask.

This rule fails when disableProxyAuthenticationSchemes is less than 256.

Rationale: Limiting the sign-in interface to known, trusted services stops malicious actors from impersonating them over a loopback proxy.

Impact: Windows will not authenticate over a loopback interface (value 256); value 287 additionally disables all authentication protocols.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Center for Internet Security (CIS) > Additional Benchmark Settings > Disable HTTP proxy features: Disable proxy authentication and set it to Enabled: Disable authentication over loopback interfaces or higher.

From the command line:

reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings" /v DisableProxyAuthenticationSchemes /t REG_DWORD /d 256 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Principal
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure Web Proxy Auto-Discovery (WPAD) Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.11

Finding: Web Proxy Auto-Discovery (WPAD) is enabled.

Checks whether the Web Proxy Auto-Discovery protocol (WPAD) is disabled for the Windows HTTP Services (WinHTTP) API.

This rule fails when disableWpad is not true.

Rationale: WPAD can be abused to feed a malicious proxy configuration to the host, enabling man-in-the-middle attacks; proxies should be configured explicitly instead.

Impact: All proxies must be configured manually; WPAD detection is stopped for WinHTTP proxy calls.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Center for Internet Security (CIS) > Additional Benchmark Settings > Disable HTTP proxy features: Disable WPAD and set it to Enabled: Checked.

From the command line:

reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttp" /v DisableWpad /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Exposure
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)