Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →
All 53 checks on this page
- 2.3.1 Accounts
- Ensure Guest Account Status Is Disabled
- Ensure Local Account Use Of Blank Passwords Is Limited To Console Logon Only
- Ensure The Built-in Administrator Account Is Renamed
- Ensure The Built-in Guest Account Is Renamed
- 2.3.2 Audit
- Ensure Audit Policy Subcategory Settings Override Category Settings
- Ensure The System Does Not Shut Down When Unable To Log Security Audits
- 2.3.4 Devices
- Ensure Users Are Prevented From Installing Printer Drivers
- 2.3.7 Interactive logon
- Ensure A Logon Message Text For Users Attempting To Log On Is Configured
- Ensure A Logon Message Title For Users Attempting To Log On Is Configured
- Ensure CTRL+ALT+DEL Is Required For Logon
- Ensure Machine Inactivity Limit Is 900 Or Fewer Seconds And Not Zero
- Ensure Smart Card Removal Behavior Is Lock Workstation Or Higher
- Ensure The Last Signed-in User Is Not Displayed
- Ensure Users Are Prompted To Change Password Between 5 And 14 Days Before Expiration
- 2.3.8 Microsoft network client
- Ensure Microsoft Network Client Digitally Signs Communications Always
- Ensure Unencrypted Passwords Are Not Sent To Third-party SMB Servers
- 2.3.9 Microsoft network server
- Ensure Clients Are Disconnected When Logon Hours Expire
- Ensure Idle Time Before Suspending A Session Is 15 Or Fewer Minutes
- Ensure Microsoft Network Server Digitally Signs Communications Always
- Ensure Server SPN Target Name Validation Level Is Accept If Provided By Client Or Higher
- 2.3.10 Network access
- Ensure Anonymous Access To Named Pipes And Shares Is Restricted
- Ensure Anonymous Enumeration Of SAM Accounts And Shares Is Not Allowed
- Ensure Anonymous Enumeration Of SAM Accounts Is Not Allowed
- Ensure Clients Allowed To Make Remote Calls To SAM Are Restricted
- Ensure Everyone Permissions Do Not Apply To Anonymous Users
- Ensure No Named Pipes Can Be Accessed Anonymously
- Ensure No Shares Can Be Accessed Anonymously
- Ensure Remotely Accessible Registry Paths And Sub-paths Are Configured
- Ensure Remotely Accessible Registry Paths Are Configured
- Ensure Sharing And Security Model For Local Accounts Is Classic
- Ensure Storage Of Passwords And Credentials For Network Authentication Is Not Allowed
- 2.3.11 Network security
- Ensure Incoming NTLM Traffic Auditing Is Enabled For All Accounts
- Ensure Kerberos Encryption Types Are Limited To AES
- Ensure LAN Manager Authentication Level Refuses LM And NTLM
- Ensure LDAP Client Encryption Requirements Are Negotiate Sealing Or Higher
- Ensure LDAP Client Signing Requirements Are Negotiate Signing Or Higher
- Ensure Local System Uses Computer Identity For NTLM
- Ensure LocalSystem NULL Session Fallback Is Disabled
- Ensure Minimum NTLM Session Security For Clients Requires NTLMv2 And 128-bit Encryption
- Ensure Minimum NTLM Session Security For Servers Requires NTLMv2 And 128-bit Encryption
- Ensure Outgoing NTLM Traffic To Remote Servers Is Audited Or Denied
- Ensure PKU2U Authentication Requests Do Not Use Online Identities
- 2.3.14 System cryptography
- Ensure Strong Key Protection For User Keys Requires A Prompt Or Password
- 2.3.15 System objects
- Ensure Case Insensitivity Is Required For Non-Windows Subsystems
- Ensure Default Permissions Of Internal System Objects Are Strengthened
- 2.3.17 User Account Control
- Ensure Admin Approval Mode For The Built-in Administrator Account Is Enabled
- Ensure All Administrators Run In Admin Approval Mode
- Ensure Application Installations Are Detected And Prompt For Elevation
- Ensure File And Registry Write Failures Are Virtualized To Per-user Locations
- Ensure Only UIAccess Applications In Secure Locations Are Elevated
- Ensure The Elevation Prompt For Administrators Uses The Secure Desktop
- Ensure The Elevation Prompt For Standard Users Automatically Denies Elevation
- Ensure The Secure Desktop Is Used When Prompting For Elevation
2.3.1 Accounts
Ensure Guest Account Status Is Disabled
Finding: The Guest account is enabled.
Checks whether the built-in Guest account is enabled.
This rule fails when guestAccountStatus is true.
Rationale: The Guest account permits unauthenticated access and should be disabled.
Impact: Network users must authenticate before accessing shared resources.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Accounts: Guest account status to Disabled.
From the command line:
net user guest /active:no
- Framework mappings
- CIS Controls v8: 4.7 Manage Default Accounts on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: IA-5 Authenticator Management
- PCI DSS v4.0.1: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 2.3.1 Replace or confirm default wireless settings when installing access points
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Local Account Use Of Blank Passwords Is Limited To Console Logon Only
Finding: Local accounts with blank passwords can be used for network logon.
Checks whether local accounts with blank passwords are restricted to console logon.
This rule fails when limitBlankPasswordUse is false.
Rationale: Blank passwords are a serious risk; remote use of blank-password accounts must be blocked.
Impact: None; this is the default behavior.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Accounts: Limit local account use of blank passwords to console logon only to Enabled.
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Lsa" /v LimitBlankPasswordUse /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 5.2 Use Unique Passwords
- NIST SP 800-53 Rev. 5: IA-5 Authenticator Management
- NIST SP 800-171 Rev. 2: 3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- CMMC 2.0 Level 2: IA.L2-3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- PCI DSS v4.0.1: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 8.3.5 Use unique initial passwords and force change on first use; 8.3.6 Enforce 12-character minimum password length with letters and numbers; 8.6.3 Rotate and harden passwords for application and system-level accounts
- Risk
- Insecure Use of Secrets
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Ensure The Built-in Administrator Account Is Renamed
Finding: The built-in administrator account still uses its default name.
Checks whether the built-in Administrator account has been renamed from its default name.
This rule fails when administratorAccount is Administrator.
Rationale: The default Administrator name is well known; renaming it slightly raises the bar for attackers.
Impact: Authorized users must know the new account name.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Accounts: Rename administrator account to a value other than Administrator.
From the command line:
Rename-LocalUser -Name "Administrator" -NewName "OrgAdmin"
- Framework mappings
- CIS Controls v8: 4.7 Manage Default Accounts on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: IA-5 Authenticator Management
- PCI DSS v4.0.1: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 2.3.1 Replace or confirm default wireless settings when installing access points
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Discovery (TA0007)
Ensure The Built-in Guest Account Is Renamed
Finding: The built-in guest account still uses its default name.
Checks whether the built-in Guest account has been renamed from its default name.
This rule fails when guestAccount is Guest.
Rationale: The default Guest name is well known; renaming it slightly raises the bar for attackers.
Impact: Little impact, as the Guest account is disabled by default.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Accounts: Rename guest account to a value other than Guest.
From the command line:
Rename-LocalUser -Name "Guest" -NewName "OrgGuest"
- Framework mappings
- CIS Controls v8: 4.7 Manage Default Accounts on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: IA-5 Authenticator Management
- PCI DSS v4.0.1: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 2.3.1 Replace or confirm default wireless settings when installing access points
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Discovery (TA0007)
2.3.2 Audit
Ensure Audit Policy Subcategory Settings Override Category Settings
Finding: Advanced audit subcategory settings do not override legacy category settings.
Checks whether fine-grained audit subcategory settings override the legacy audit categories.
This rule fails when sCENoApplyLegacyAuditPolicy is false.
Rationale: Subcategory auditing gives precise, manageable audit coverage that the broad categories cannot.
Impact: None; this is the default behavior.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings to Enabled.
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Lsa" /v SCENoApplyLegacyAuditPolicy /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 8.5 Collect Detailed Audit Logs
- NIST SP 800-53 Rev. 5: AU-3 Content of Audit Records; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation; SI-4 System Monitoring
- PCI DSS v4.0.1: 9.4.5 Keep a log-based inventory of electronic media holding cardholder data; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.5 Record account creation, privilege elevation, and other credential changes
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure The System Does Not Shut Down When Unable To Log Security Audits
Finding: The system is configured to shut down when it cannot log security audits.
Checks whether the system forces a shutdown when it cannot write to the Security log.
This rule fails when crashOnAuditFail is true.
Rationale: Forcing a shutdown on audit failure creates an avoidable denial-of-service and administrative burden.
Impact: None; this is the default behavior.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Audit: Shut down system immediately if unable to log security audits to Disabled.
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Lsa" /v CrashOnAuditFail /t REG_DWORD /d 0 /f
- Framework mappings
- CIS Controls v8: 8.3 Ensure Adequate Audit Log Storage
- NIST SP 800-53 Rev. 5: AU-4 Audit Log Storage Capacity; AU-5 Response to Audit Logging Process Failures
- Risk
- Reliability Impact
- MITRE ATT&CK tactic
- Impact (TA0040)
2.3.4 Devices
Ensure Users Are Prevented From Installing Printer Drivers
Finding: Non-administrators can install printer drivers.
Checks whether only administrators may install printer drivers when connecting to a shared printer.
This rule fails when addPrintDevices is false.
Rationale: Printer drivers run with high privilege; restricting installation limits a code-execution vector.
Impact: Only administrators can install a printer driver as part of connecting to a shared printer.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Devices: Prevent users from installing printer drivers to Enabled.
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Print\Providers\LanMan Print Services\Servers" /v AddPrinterDrivers /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts
- PCI DSS v4.0.1: 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Execution (TA0002)
2.3.7 Interactive logon
Ensure A Logon Message Text For Users Attempting To Log On Is Configured
Finding: No logon message text is configured.
Checks whether a legal-notice message text is displayed before logon.
This rule fails when legalNoticeText is empty.
Rationale: A logon banner warns unauthorized users and reinforces acceptable-use policy.
Impact: Users must acknowledge the notice before logging on.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Interactive logon: Message text for users attempting to log on to an organization-approved notice.
From the command line:
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v LegalNoticeText /t REG_SZ /d "This system is for authorized use only." /f
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure A Logon Message Title For Users Attempting To Log On Is Configured
Finding: No logon message title is configured.
Checks whether a title is set for the pre-logon legal-notice dialog.
This rule fails when legalNoticeCaption is empty.
Rationale: A titled logon banner reinforces the warning shown to users before they sign in.
Impact: Users must acknowledge the titled notice before logging on.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Interactive logon: Message title for users attempting to log on to an organization-approved title.
From the command line:
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v LegalNoticeCaption /t REG_SZ /d "Authorized Use Only" /f
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure CTRL+ALT+DEL Is Required For Logon
Finding: CTRL+ALT+DEL is not required before logon.
Checks whether users must press CTRL+ALT+DEL before signing in.
This rule fails when cad is true (the requirement is disabled).
Rationale: Requiring the secure attention sequence establishes a trusted path and defeats logon-spoofing malware.
Impact: Users must press CTRL+ALT+DEL before logon unless using a smart card.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Interactive logon: Do not require CTRL+ALT+DEL to Disabled.
From the command line:
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v DisableCAD /t REG_DWORD /d 0 /f
- Risk
- Insecure Use of Secrets
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Ensure Machine Inactivity Limit Is 900 Or Fewer Seconds And Not Zero
Finding: Machine inactivity limit is 0 or exceeds 900 seconds.
Checks the idle time after which the session is automatically locked.
This rule fails when inactivityTimeout is 0 or greater than 900000000000 ns (900 seconds).
Rationale: Locking an idle session prevents a passer-by from hijacking an unattended, logged-on computer.
Impact: The screen locks automatically after the configured idle period.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Interactive logon: Machine inactivity limit to 900 or fewer seconds, but not 0.
From the command line:
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v InactivityTimeoutSecs /t REG_DWORD /d 900 /f
- Framework mappings
- CIS Controls v8: 4.3 Configure Automatic Session Locking on Enterprise Assets
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-11 Device Lock; AC-12 Session Termination
- NIST SP 800-171 Rev. 2: 3.1.10 Use session lock with pattern-hiding displays to prevent access and viewing of data after period of inactivity
- CMMC 2.0 Level 2: AC.L2-3.1.10 Use session lock with pattern-hiding displays to prevent access and viewing of data after period of inactivity
- PCI DSS v4.0.1: 8.2.8 Require re-authentication after 15 minutes of session inactivity
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Smart Card Removal Behavior Is Lock Workstation Or Higher
Finding: Smart card removal takes no protective action.
Checks the action taken when a user's smart card is removed.
This rule fails when scRemoveOption is not one of LOCK_WORKSTATION, FORCE_LOGOFF, or DISCONNECT_IF_REMOTE_DESKTOP_SERVICES_SESSION.
Rationale: Locking or logging off on card removal protects the session when the user walks away with their card.
Impact: The session locks (or logs off/disconnects) when the smart card is removed.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Interactive logon: Smart card removal behavior to Lock Workstation (or higher).
From the command line:
reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v ScRemoveOption /t REG_SZ /d "1" /f
- Framework mappings
- CIS Controls v8: 4.3 Configure Automatic Session Locking on Enterprise Assets
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-11 Device Lock; AC-12 Session Termination
- NIST SP 800-171 Rev. 2: 3.1.10 Use session lock with pattern-hiding displays to prevent access and viewing of data after period of inactivity
- CMMC 2.0 Level 2: AC.L2-3.1.10 Use session lock with pattern-hiding displays to prevent access and viewing of data after period of inactivity
- PCI DSS v4.0.1: 8.2.8 Require re-authentication after 15 minutes of session inactivity
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure The Last Signed-in User Is Not Displayed
Finding: The last signed-in user name is displayed at logon.
Checks whether the name of the last signed-in user is hidden on the logon screen.
This rule fails when displayLastUserName is true.
Rationale: Hiding the last user name denies an onlooker half of a valid credential pair.
Impact: The last signed-in user name is no longer shown at logon.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Interactive logon: Don't display last signed-in to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v DontDisplayLastUserName /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process
- NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Discovery (TA0007)
Ensure Users Are Prompted To Change Password Between 5 And 14 Days Before Expiration
Finding: Password-expiration warning is not between 5 and 14 days.
Checks how many days before expiry a user is warned to change their password.
This rule fails when passwordExpiryWarning is less than 5 or greater than 14.
Rationale: An adequate warning window lets users change passwords in time and avoid a lockout.
Impact: Users see a change-password prompt during the warning window before expiry.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Interactive logon: Prompt user to change password before expiration to between 5 and 14 days.
From the command line:
reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v PasswordExpiryWarning /t REG_DWORD /d 14 /f
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Credential Access (TA0006)
2.3.8 Microsoft network client
Ensure Microsoft Network Client Digitally Signs Communications Always
Finding: The SMB client does not require packet signing.
Checks whether the SMB client requires signing on all communications.
This rule fails when requireSecuritySignature is false.
Rationale: Mandatory SMB signing defeats session-hijacking and tampering on the network path.
Impact: The client will not communicate with a server that refuses SMB signing.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Microsoft network client: Digitally sign communications (always) to Enabled.
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v RequireSecuritySignature /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 3.10 Encrypt Sensitive Data in Transit
- NIST SP 800-53 Rev. 5: AC-17 Remote Access; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
- NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- PCI DSS v4.0.1: 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Unencrypted Passwords Are Not Sent To Third-party SMB Servers
Finding: The SMB client may send plaintext passwords to third-party servers.
Checks whether the SMB client is allowed to send plaintext passwords to third-party servers.
This rule fails when enablePlainTextPassword is true.
Rationale: Sending plaintext passwords over the network exposes credentials to anyone capturing traffic.
Impact: None; this is the default behavior.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Microsoft network client: Send unencrypted password to third-party SMB servers to Disabled.
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v EnablePlainTextPassword /t REG_DWORD /d 0 /f
- Framework mappings
- CIS Controls v8: 3.10 Encrypt Sensitive Data in Transit
- NIST SP 800-53 Rev. 5: AC-17 Remote Access; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
- NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- PCI DSS v4.0.1: 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography
- Risk
- Insecure Use of Secrets
- MITRE ATT&CK tactic
- Credential Access (TA0006)
2.3.9 Microsoft network server
Ensure Clients Are Disconnected When Logon Hours Expire
Finding: Clients are not disconnected when logon hours expire.
Checks whether SMB clients are disconnected once their account's logon hours end.
This rule fails when enableforcedlogoff is false.
Rationale: Enforcing logon hours prevents access to network resources outside permitted times.
Impact: None; if logon hours are not used this setting has no effect.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Microsoft network server: Disconnect clients when logon hours expire to Enabled.
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" /v EnableForcedLogoff /t REG_DWORD /d 1 /f
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Persistence (TA0003)
Ensure Idle Time Before Suspending A Session Is 15 Or Fewer Minutes
Finding: Idle SMB sessions are suspended after more than 15 minutes.
Checks the idle time an SMB session may remain before it is suspended.
This rule fails when autoDisconnect is greater than 900000000000 ns (15 minutes).
Rationale: Suspending idle sessions frees server resources and limits abuse of lingering null sessions.
Impact: Little impact; SMB sessions resume automatically when the client is active again.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Microsoft network server: Amount of idle time required before suspending session to 15 or fewer minutes.
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" /v AutoDisconnect /t REG_DWORD /d 15 /f
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Impact (TA0040)
Ensure Microsoft Network Server Digitally Signs Communications Always
Finding: The SMB server does not require packet signing.
Checks whether the SMB server requires signing on all communications.
This rule fails when requireSecuritySignature is false.
Rationale: Mandatory server-side SMB signing defeats session-hijacking and tampering on the network path.
Impact: The server will not communicate with a client that refuses SMB signing.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Microsoft network server: Digitally sign communications (always) to Enabled.
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" /v RequireSecuritySignature /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 3.10 Encrypt Sensitive Data in Transit
- NIST SP 800-53 Rev. 5: AC-17 Remote Access; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
- NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- PCI DSS v4.0.1: 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Server SPN Target Name Validation Level Is Accept If Provided By Client Or Higher
Finding: The SMB server does not validate the SPN provided by clients.
Checks the level of service principal name validation performed on SMB connections.
This rule fails when smbServerNameHardeningLevel is OFF.
Rationale: Validating the SPN counters computer-identity spoofing used to reach network resources.
Impact: Requires care in mixed environments, as it affects server SMB behavior.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Microsoft network server: Server SPN target name validation level to Accept if provided by client (or higher).
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" /v SMBServerNameHardeningLevel /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process
- NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Initial Access (TA0001)
2.3.10 Network access
Ensure Anonymous Enumeration Of SAM Accounts Is Not Allowed
Finding: Anonymous users can enumerate SAM accounts.
Checks whether anonymous users are blocked from enumerating SAM accounts.
This rule fails when restrictAnonymousSAM is false.
Rationale: Anonymous account enumeration feeds password-guessing and social-engineering attacks.
Impact: None; this is the default behavior.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Network access: Do not allow anonymous enumeration of SAM accounts to Enabled.
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Lsa" /v RestrictAnonymousSAM /t REG_DWORD /d 1 /f
- Risk
- External Exposure
- MITRE ATT&CK tactic
- Discovery (TA0007)
Ensure Clients Allowed To Make Remote Calls To SAM Are Restricted
Finding: Remote calls to SAM are not restricted to administrators.
Checks whether remote RPC access to the SAM database is limited to administrators.
This rule fails when restrictRemoteSAM is not the SDDL O:BAG:BAD:(A;;RC;;;BA).
Rationale: Restricting remote SAM calls stops anonymous or non-admin enumeration of local accounts.
Impact: None; this is the default behavior.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Network access: Restrict clients allowed to make remote calls to SAM to Administrators: Remote Access: Allow.
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Lsa" /v RestrictRemoteSAM /t REG_SZ /d "O:BAG:BAD:(A;;RC;;;BA)" /f
- Risk
- External Exposure
- MITRE ATT&CK tactic
- Discovery (TA0007)
Ensure Everyone Permissions Do Not Apply To Anonymous Users
Finding: Everyone permissions are applied to anonymous users.
Checks whether anonymous connections inherit the permissions granted to the Everyone group.
This rule fails when everyoneIncludesAnonymous is true.
Rationale: Extending Everyone permissions to anonymous users broadens anonymous access to resources.
Impact: None; this is the default behavior.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Network access: Let Everyone permissions apply to anonymous users to Disabled.
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Lsa" /v EveryoneIncludesAnonymous /t REG_DWORD /d 0 /f
- Risk
- External Exposure
- MITRE ATT&CK tactic
- Discovery (TA0007)
Ensure No Named Pipes Can Be Accessed Anonymously
Finding: One or more named pipes are accessible anonymously.
Checks whether any named pipes are configured for anonymous access.
This rule fails when nullSessionPipes contains any entry.
Rationale: Every anonymously accessible named pipe widens the attack surface of the system.
Impact: Applications that rely on anonymous named-pipe access may be affected.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Network access: Named Pipes that can be accessed anonymously to (blank).
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Services\LanManServer\Parameters" /v NullSessionPipes /t REG_MULTI_SZ /d "" /f
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Discovery (TA0007)
Ensure Remotely Accessible Registry Paths And Sub-paths Are Configured
Finding: Remotely accessible registry paths and sub-paths do not match the recommended set.
Checks that the set of remotely accessible registry paths and sub-paths matches the CIS list.
This rule fails when allowedPaths does not equal the recommended set of registry paths and sub-paths.
Rationale: Limiting network-reachable registry paths keeps sensitive configuration data from anonymous readers.
Impact: None; this is the default behavior.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Network access: Remotely accessible registry paths and sub-paths to the CIS-recommended list of paths.
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Control\SecurePipeServers\Winreg\AllowedPaths" /v Machine /t REG_MULTI_SZ /d "System\CurrentControlSet\Control\Print\Printers\0System\CurrentControlSet\Services\Eventlog\0Software\Microsoft\OLAP Server\0Software\Microsoft\Windows NT\CurrentVersion\Print\0Software\Microsoft\Windows NT\CurrentVersion\Windows\0System\CurrentControlSet\Control\ContentIndex\0System\CurrentControlSet\Control\Terminal Server\0System\CurrentControlSet\Control\Terminal Server\UserConfig\0System\CurrentControlSet\Control\Terminal Server\DefaultUserConfiguration\0Software\Microsoft\Windows NT\CurrentVersion\Perflib\0System\CurrentControlSet\Services\SysmonLog" /f
- Risk
- External Exposure
- MITRE ATT&CK tactic
- Discovery (TA0007)
Ensure Remotely Accessible Registry Paths Are Configured
Finding: Remotely accessible registry paths do not match the recommended set.
Checks that the set of remotely accessible registry paths matches the CIS-recommended list.
This rule fails when allowedExactPaths does not equal the recommended set of registry paths.
Rationale: Limiting network-reachable registry paths keeps sensitive configuration data from anonymous readers.
Impact: None; this is the default behavior.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Network access: Remotely accessible registry paths to the CIS-recommended list of paths.
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Control\SecurePipeServers\Winreg\AllowedExactPaths" /v Machine /t REG_MULTI_SZ /d "System\CurrentControlSet\Control\ProductOptions\0System\CurrentControlSet\Control\Server Applications\0Software\Microsoft\Windows NT\CurrentVersion" /f
- Risk
- External Exposure
- MITRE ATT&CK tactic
- Discovery (TA0007)
Ensure Sharing And Security Model For Local Accounts Is Classic
Finding: Local accounts authenticate over the network as Guest.
Checks whether local accounts authenticate as themselves (Classic) rather than as Guest.
This rule fails when forceGuest is not LOCAL_USERS_AUTHENTICATE_AS_THEMSELVES.
Rationale: The Classic model gives precise access control; the Guest-only model collapses all logons to guest rights.
Impact: None; this is the default for domain-joined computers.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Network access: Sharing and security model for local accounts to Classic - local users authenticate as themselves.
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Lsa" /v ForceGuest /t REG_DWORD /d 0 /f
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Storage Of Passwords And Credentials For Network Authentication Is Not Allowed
Finding: Passwords and credentials are cached for network authentication.
Checks whether Credential Manager is prevented from storing network credentials.
This rule fails when disableDomainCreds is false.
Rationale: Cached credentials can be harvested by malware or an attacker with access to the machine.
Impact: Credential Manager will not store network passwords; users re-enter them as needed.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Network access: Do not allow storage of passwords and credentials for network authentication to Enabled.
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Lsa" /v DisableDomainCreds /t REG_DWORD /d 1 /f
- Risk
- Insecure Use of Secrets
- MITRE ATT&CK tactic
- Credential Access (TA0006)
2.3.11 Network security
Ensure Incoming NTLM Traffic Auditing Is Enabled For All Accounts
Finding: Incoming NTLM traffic is not audited for all accounts.
Checks whether incoming NTLM authentication traffic is audited for all accounts.
This rule fails when auditReceivingNTLMTraffic is not AUDIT_ALL_ACCOUNTS.
Rationale: Auditing NTLM traffic surfaces systems still using this legacy protocol so they can be remediated.
Impact: The operational event log records incoming NTLM authentication traffic.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Network security: Restrict NTLM: Audit Incoming NTLM Traffic to Enable auditing for all accounts.
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0" /v AuditReceivingNTLMTraffic /t REG_DWORD /d 2 /f
- Framework mappings
- CIS Controls v8: 8.5 Collect Detailed Audit Logs
- NIST SP 800-53 Rev. 5: AU-3 Content of Audit Records; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation; SI-4 System Monitoring
- PCI DSS v4.0.1: 9.4.5 Keep a log-based inventory of electronic media holding cardholder data; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.5 Record account creation, privilege elevation, and other credential changes
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure Kerberos Encryption Types Are Limited To AES
Finding: Weak Kerberos encryption types are allowed.
Checks that Kerberos permits the AES cipher suites and excludes the weak DES and RC4 suites.
This rule fails when the allowed set omits an AES type or still permits DES_CBC_CRC, DES_CBC_MD5, or RC4_HMAC_MD5.
Rationale: Weak DES/RC4 Kerberos ciphers are far easier to break than AES and must not be permitted.
Impact: Disallowed encryption types may affect compatibility with older clients or services.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Network security: Configure encryption types allowed for Kerberos to AES128_HMAC_SHA1, AES256_HMAC_SHA1, Future encryption types.
From the command line:
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Kerberos\Parameters" /v SupportedEncryptionTypes /t REG_DWORD /d 2147483640 /f
- Framework mappings
- CIS Controls v8: 3.10 Encrypt Sensitive Data in Transit
- NIST SP 800-53 Rev. 5: AC-17 Remote Access; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
- NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- PCI DSS v4.0.1: 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography
- Risk
- Insecure Use of Secrets
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Ensure LAN Manager Authentication Level Refuses LM And NTLM
Finding: LAN Manager authentication level accepts LM or NTLM responses.
Checks whether only NTLMv2 responses are sent and LM and NTLM are refused.
This rule fails when lmCompatibilityLevel is not SEND_NTLMV2_RESPONSE_ONLY_REFUSE_LM_AND_NTLM.
Rationale: LM and NTLMv1 responses are cryptographically weak and easily cracked; only NTLMv2 should be used.
Impact: Clients use NTLMv2 only; very old clients that cannot use NTLMv2 will fail to authenticate.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Network security: LAN Manager authentication level to Send NTLMv2 response only. Refuse LM & NTLM.
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Lsa" /v LmCompatibilityLevel /t REG_DWORD /d 5 /f
- Framework mappings
- CIS Controls v8: 3.10 Encrypt Sensitive Data in Transit
- NIST SP 800-53 Rev. 5: AC-17 Remote Access; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
- NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- PCI DSS v4.0.1: 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography
- Risk
- Insecure Use of Secrets
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Ensure LDAP Client Encryption Requirements Are Negotiate Sealing Or Higher
Finding: LDAP client traffic may be sent without encryption.
Checks whether the LDAP client requests at least negotiated sealing (encryption) for BIND requests.
This rule fails when lDAPClientConfidentiality is NONE.
Rationale: Unencrypted LDAP traffic is exposed to man-in-the-middle capture and modification.
Impact: None; this is the default behavior, provided the server also supports sealing.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Network security: LDAP client encryption requirements to Negotiate sealing (or higher).
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Services\LDAP" /v LDAPClientConfidentiality /t REG_DWORD /d 1 /f
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure LDAP Client Signing Requirements Are Negotiate Signing Or Higher
Finding: LDAP client traffic may be sent without signing.
Checks whether the LDAP client requests at least negotiated signing for BIND requests.
This rule fails when lDAPClientIntegrity is NONE.
Rationale: Unsigned LDAP traffic can be intercepted and tampered with in a man-in-the-middle attack.
Impact: None; this is the default behavior, provided the server also supports signing.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Network security: LDAP client signing requirements to Negotiate signing (or higher).
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Services\LDAP" /v LDAPClientIntegrity /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 3.10 Encrypt Sensitive Data in Transit
- NIST SP 800-53 Rev. 5: AC-17 Remote Access; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
- NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- PCI DSS v4.0.1: 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Local System Uses Computer Identity For NTLM
Finding: Local System does not use the computer identity for NTLM.
Checks whether Local System services use the computer identity when negotiating NTLM.
This rule fails when useMachineId is false.
Rationale: Using the computer identity avoids anonymous fallback for Local System NTLM authentication.
Impact: Local System services use the computer identity when reverting to NTLM.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Network security: Allow Local System to use computer identity for NTLM to Enabled.
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Lsa" /v UseMachineId /t REG_DWORD /d 1 /f
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure LocalSystem NULL Session Fallback Is Disabled
Finding: LocalSystem NULL session fallback is allowed.
Checks whether NTLM is allowed to fall back to a NULL session for LocalSystem.
This rule fails when allowNullSessionFallBack is true.
Rationale: NULL sessions are unauthenticated and inherently less secure; fallback should be blocked.
Impact: None; applications requiring NULL sessions for LocalSystem will not work.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Network security: Allow LocalSystem NULL session fallback to Disabled.
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Lsa\pku2u" /v AllowNullSessionFallback /t REG_DWORD /d 0 /f
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Minimum NTLM Session Security For Clients Requires NTLMv2 And 128-bit Encryption
Finding: Minimum NTLM client session security does not require NTLMv2 and 128-bit encryption.
Checks whether NTLM client connections require both NTLMv2 session security and 128-bit encryption.
This rule fails when nTLMMinClientSec does not require both NTLMv2 session security and 128-bit encryption.
Rationale: Requiring both protections keeps NTLM client traffic from being exposed or tampered with.
Impact: NTLM client connections fail unless both NTLMv2 and 128-bit encryption are negotiated.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Network security: Minimum session security for NTLM SSP based (including secure RPC) clients to require both NTLMv2 session security and 128-bit encryption.
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0" /v NTLMMinClientSec /t REG_DWORD /d 537395200 /f
- Framework mappings
- CIS Controls v8: 3.10 Encrypt Sensitive Data in Transit
- NIST SP 800-53 Rev. 5: AC-17 Remote Access; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
- NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- PCI DSS v4.0.1: 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography
- Risk
- Insecure Use of Secrets
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Minimum NTLM Session Security For Servers Requires NTLMv2 And 128-bit Encryption
Finding: Minimum NTLM server session security does not require NTLMv2 and 128-bit encryption.
Checks whether NTLM server connections require both NTLMv2 session security and 128-bit encryption.
This rule fails when nTLMMinServerSec does not require both NTLMv2 session security and 128-bit encryption.
Rationale: Requiring both protections keeps NTLM server traffic from being exposed or tampered with.
Impact: NTLM server connections fail unless both NTLMv2 and 128-bit encryption are negotiated.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Network security: Minimum session security for NTLM SSP based (including secure RPC) servers to require both NTLMv2 session security and 128-bit encryption.
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0" /v NTLMMinServerSec /t REG_DWORD /d 537395200 /f
- Framework mappings
- CIS Controls v8: 3.10 Encrypt Sensitive Data in Transit
- NIST SP 800-53 Rev. 5: AC-17 Remote Access; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
- NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- PCI DSS v4.0.1: 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography
- Risk
- Insecure Use of Secrets
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Outgoing NTLM Traffic To Remote Servers Is Audited Or Denied
Finding: Outgoing NTLM traffic to remote servers is neither audited nor denied.
Checks whether outgoing NTLM authentication to remote servers is at least audited.
This rule fails when restrictSendingNTLMTraffic is ALLOW_ALL.
Rationale: Auditing or denying outgoing NTLM identifies and reduces reliance on this legacy protocol.
Impact: The operational event log records outgoing NTLM authentication traffic.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Network security: Restrict NTLM: Outgoing NTLM traffic to remote servers to Audit all (or Deny all).
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0" /v RestrictSendingNTLMTraffic /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 8.5 Collect Detailed Audit Logs
- NIST SP 800-53 Rev. 5: AU-3 Content of Audit Records; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation; SI-4 System Monitoring
- PCI DSS v4.0.1: 9.4.5 Keep a log-based inventory of electronic media holding cardholder data; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.5 Record account creation, privilege elevation, and other credential changes
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure PKU2U Authentication Requests Do Not Use Online Identities
Finding: PKU2U authentication with online identities is allowed.
Checks whether peer-to-peer PKU2U authentication using online identities is blocked.
This rule fails when allowOnlineID is true.
Rationale: PKU2U is a peer authentication protocol; authentication should be managed centrally in managed networks.
Impact: None; this is the default for domain-joined computers.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set Network Security: Allow PKU2U authentication requests to this computer to use online identities to Disabled.
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Lsa\pku2u" /v AllowOnlineID /t REG_DWORD /d 0 /f
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process
- NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Initial Access (TA0001)
2.3.14 System cryptography
Ensure Strong Key Protection For User Keys Requires A Prompt Or Password
Finding: User keys stored on the computer are not protected by a prompt or password.
Checks whether using a stored private key requires a prompt or password.
This rule fails when forceKeyProtection is USER_INPUT_NOT_REQUIRED_WHEN_KEYS_ARE_STORED_AND_USED.
Rationale: Requiring interaction to use a stored key stops a compromised session from silently abusing it.
Impact: Users are prompted (or must enter a password) the first time they use a stored key.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set System cryptography: Force strong key protection for user keys stored on the computer to User is prompted when the key is first used (or higher).
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Cryptography" /v ForceKeyProtection /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 3.11 Encrypt Sensitive Data at Rest
- NIST SP 800-53 Rev. 5: AU-9 Protection of Audit Information; IA-5 Authenticator Management; SC-28 Protection of Information at Rest
- NIST SP 800-171 Rev. 2: 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital; 3.13.16 Protect the confidentiality of CUI at rest
- CMMC 2.0 Level 2: MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital; SC.L2-3.13.16 Protect the confidentiality of CUI at rest
- PCI DSS v4.0.1: 3.1.1 Stored account data policies and procedures kept documented, current, and applied; 3.3.2 Encrypt sensitive authentication data stored before authorization completes; 3.3.3 Issuers limit and protect any stored sensitive authentication data; 3.5.1.2 Restrict disk- or partition-level PAN encryption to removable media or paired controls; 3.5.1.3 Manage disk-level encryption access independently of operating system authentication; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography
- Risk
- Insecure Use of Secrets
- MITRE ATT&CK tactic
- Credential Access (TA0006)
2.3.15 System objects
Ensure Case Insensitivity Is Required For Non-Windows Subsystems
Finding: Case insensitivity is not enforced for non-Windows subsystems.
Checks whether case insensitivity is enforced for all subsystems.
This rule fails when obCaseInsensitive is false.
Rationale: Without this, a case-sensitive subsystem could reference an object under a differently cased name.
Impact: None; this is the default behavior.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set System objects: Require case insensitivity for non-Windows subsystems to Enabled.
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Kernel" /v ObCaseInsensitive /t REG_DWORD /d 1 /f
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure Default Permissions Of Internal System Objects Are Strengthened
Finding: Default permissions of internal system objects are not strengthened.
Checks whether the default DACL for internal system objects is strengthened.
This rule fails when protectionMode is false.
Rationale: Stronger default permissions on shared system objects prevent tampering by non-privileged users.
Impact: None; this is the default behavior.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set System objects: Strengthen default permissions of internal system objects (e.g. Symbolic Links) to Enabled.
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Kernel" /v ProtectionMode /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process
- NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
2.3.17 User Account Control
Ensure Admin Approval Mode For The Built-in Administrator Account Is Enabled
Finding: Admin Approval Mode is disabled for the built-in Administrator account.
Checks whether the built-in Administrator account runs in Admin Approval Mode.
This rule fails when filterAdministratorToken is false.
Rationale: Admin Approval Mode ensures even the built-in Administrator is prompted before elevating.
Impact: The built-in Administrator receives elevation prompts.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set User Account Control: Admin Approval Mode for the Built-in Administrator account to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v FilterAdministratorToken /t REG_DWORD /d 1 /f
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure All Administrators Run In Admin Approval Mode
Finding: Admin Approval Mode is disabled for all administrators.
Checks whether User Account Control is enabled for all administrators.
This rule fails when enableLUA is false.
Rationale: This is the master UAC switch; disabling it removes every UAC-dependent protection.
Impact: Users and administrators work with UAC prompts.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set User Account Control: Run all administrators in Admin Approval Mode to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v EnableLUA /t REG_DWORD /d 1 /fRequires a restart to take effect.
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure Application Installations Are Detected And Prompt For Elevation
Finding: Application installations are not detected for elevation.
Checks whether installer detection prompts for elevation when an install is attempted.
This rule fails when enableInstallerDetection is false.
Rationale: Detecting installers forces a consent prompt, blocking silent installs of malicious software.
Impact: Users are prompted for administrator credentials when an installer needs elevation.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set User Account Control: Detect application installations and prompt for elevation to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v EnableInstallerDetection /t REG_DWORD /d 1 /f
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure File And Registry Write Failures Are Virtualized To Per-user Locations
Finding: Legacy application write failures are not virtualized to per-user locations.
Checks whether legacy application write failures are redirected to per-user locations.
This rule fails when enableVirtualization is false.
Rationale: Virtualization confines legacy apps to permitted locations instead of protected system areas.
Impact: None; this is the default behavior.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set User Account Control: Virtualize file and registry write failures to per-user locations to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v EnableVirtualization /t REG_DWORD /d 1 /f
- Risk
- Insecure Application
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure Only UIAccess Applications In Secure Locations Are Elevated
Finding: UIAccess applications outside secure locations may be elevated.
Checks whether only UIAccess applications in secure file-system locations may be elevated.
This rule fails when enableSecureUIAPaths is false.
Rationale: Requiring a secure location prevents planted UIAccess apps from bypassing UI privilege isolation.
Impact: None; this is the default behavior.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set User Account Control: Only elevate UIAccess applications that are installed in secure locations to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v EnableSecureUIAPaths /t REG_DWORD /d 1 /f
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure The Elevation Prompt For Administrators Uses The Secure Desktop
Finding: The administrator elevation prompt does not use the secure desktop.
Checks whether administrator elevation prompts are shown on the secure desktop.
This rule fails when consentPromptBehaviorAdmin is not a secure-desktop prompt value.
Rationale: Prompting on the secure desktop prevents malware from spoofing or automating the consent dialog.
Impact: Administrators are prompted for consent (or credentials) on the secure desktop when elevating.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode to Prompt for consent on the secure desktop (or higher).
From the command line:
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v ConsentPromptBehaviorAdmin /t REG_DWORD /d 2 /f
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure The Elevation Prompt For Standard Users Automatically Denies Elevation
Finding: Standard users are able to elevate rather than being denied.
Checks whether elevation requests from standard users are automatically denied.
This rule fails when consentPromptBehaviorUser is not AUTOMATICALLY_DENY_ELEVATION_REQUESTS.
Rationale: Denying standard-user elevation stops unprivileged accounts from gaining administrative rights.
Impact: Standard users see an access-denied message instead of an elevation prompt.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set User Account Control: Behavior of the elevation prompt for standard users to Automatically deny elevation requests.
From the command line:
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v ConsentPromptBehaviorUser /t REG_DWORD /d 0 /f
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure The Secure Desktop Is Used When Prompting For Elevation
Finding: Elevation prompts are not shown on the secure desktop.
Checks whether elevation prompts switch to the secure desktop.
This rule fails when promptOnSecureDesktop is false.
Rationale: The secure desktop cannot be spoofed by malware trying to capture credentials.
Impact: None; this is the default behavior.
Remediation
Open Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options and set User Account Control: Switch to the secure desktop when prompting for elevation to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v PromptOnSecureDesktop /t REG_DWORD /d 1 /f
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)