---
title: CIS Windows 11 Custom Settings: 2 Checks | Wartiva
description: Wartiva's 2 checks for section 18.11, Custom Settings, of the CIS Microsoft Windows 11 Stand-alone Benchmark: what each one finds, why it matters, and how to fix it.
url: https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/custom-settings.html
updated: 2026-10-07
---

CIS Microsoft Windows 11 Stand-alone Benchmark · Section 18.11

# Windows 11 Custom Settings: 2 Checks

Wartiva runs 2 checks for section 18.11, Custom Settings, of the CIS Microsoft Windows 11 Stand-alone Benchmark. Each one lists what it finds, why it matters, and how to fix it.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. [How Wartiva works →](https://wartiva.com/platform.html)

## [Ensure HTTP Proxy Authentication Over Loopback Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/custom-settings.html#http-proxy-authentication-over-loopback-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.11

**Finding:** HTTP proxy authentication over loopback is allowed.

Checks whether Windows HTTP Services is prevented from authenticating over a loopback interface (at minimum) via the DisableProxyAuthenticationSchemes bitmask.

This rule fails when `disableProxyAuthenticationSchemes` is less than `256`.

**Rationale:** Limiting the sign-in interface to known, trusted services stops malicious actors from impersonating them over a loopback proxy.

**Impact:** Windows will not authenticate over a loopback interface (value 256); value 287 additionally disables all authentication protocols.

### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Center for Internet Security (CIS) > Additional Benchmark Settings > Disable HTTP proxy features: Disable proxy authentication** and set it to **Enabled: Disable authentication over loopback interfaces** or higher.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings" /v DisableProxyAuthenticationSchemes /t REG_DWORD /d 256 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Principal

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

## [Ensure Web Proxy Auto-Discovery (WPAD) Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/custom-settings.html#web-proxy-auto-discovery-wpad-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.11

**Finding:** Web Proxy Auto-Discovery (WPAD) is enabled.

Checks whether the Web Proxy Auto-Discovery protocol (WPAD) is disabled for the Windows HTTP Services (WinHTTP) API.

This rule fails when `disableWpad` is not `true`.

**Rationale:** WPAD can be abused to feed a malicious proxy configuration to the host, enabling man-in-the-middle attacks; proxies should be configured explicitly instead.

**Impact:** All proxies must be configured manually; WPAD detection is stopped for WinHTTP proxy calls.

### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Center for Internet Security (CIS) > Additional Benchmark Settings > Disable HTTP proxy features: Disable WPAD** and set it to **Enabled: Checked**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttp" /v DisableWpad /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Exposure

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
