CIS Microsoft Windows 11 Stand-alone Benchmark · Section 5

Windows 11 System Services: 44 Checks

Wartiva runs 44 checks for section 5, System Services, of the CIS Microsoft Windows 11 Stand-alone Benchmark. Each one lists what it finds, why it matters, and how to fix it.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →

All 44 checks on this page

Ensure Bluetooth Audio Gateway Service Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: Bluetooth Audio Gateway Service is not disabled.

Checks that the service backing the audio-gateway role of the Bluetooth Hands-Free Profile is disabled.

This rule fails when the Bluetooth Audio Gateway Service service is present and its startType is not DISABLED.

Rationale: Bluetooth carries inherent wireless risks and its traffic is often weakly encrypted, so it should not be permitted on high-security workstations.

Impact: Bluetooth hands-free audio devices will not work with the computer.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Bluetooth Audio Gateway Service, and set its startup type to Disabled.

From the command line:

sc.exe config BTAGService start= disabled
Set-Service -Name BTAGService -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Bluetooth Support Service Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: Bluetooth Support Service is not disabled.

Checks that the service supporting discovery and pairing of remote Bluetooth devices is disabled.

This rule fails when the Bluetooth Support Service service is present and its startType is not DISABLED.

Rationale: Bluetooth carries inherent wireless risks and its traffic is often weakly encrypted, so it should not be permitted on high-security workstations.

Impact: Installed Bluetooth devices may stop working and new devices cannot be discovered or paired; some Windows components such as Devices and Printers may misbehave.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Bluetooth Support Service, and set its startup type to Disabled.

From the command line:

sc.exe config bthserv start= disabled
Set-Service -Name bthserv -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Computer Browser Service Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: Computer Browser is not disabled.

Checks that the legacy Computer Browser service, which maintains and serves a list of networked computers, is disabled or not installed.

This rule fails when the Computer Browser service is present and its startType is not DISABLED.

Rationale: This legacy service generates noisy master-browser election traffic and lets anyone enumerate online machines and shares, aiding attacker reconnaissance.

Impact: The network list of computers and their shares will no longer be maintained.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Computer Browser, and set its startup type to Disabled.

From the command line:

sc.exe config Browser start= disabled
Set-Service -Name Browser -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Discovery (TA0007)

Ensure Downloaded Maps Manager Service Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: Downloaded Maps Manager is not disabled.

Checks that the service giving applications access to downloaded maps is disabled.

This rule fails when the Downloaded Maps Manager service is present and its startType is not DISABLED.

Rationale: Mapping features can leak the device location and pull data from third parties, which is undesirable in high-security environments.

Impact: Applications will be unable to access downloaded map data.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Downloaded Maps Manager, and set its startup type to Disabled.

From the command line:

sc.exe config MapsBroker start= disabled
Set-Service -Name MapsBroker -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Execution (TA0002)

Ensure GameInput Service Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: GameInput Service is not disabled.

Checks that the service exposing keyboards, mice and game controllers through the GameInput API is disabled.

This rule fails when the GameInput Service service is present and its startType is not DISABLED.

Rationale: The GameInput API pipes input via Direct Memory Access to reduce latency, which increases the risk of keystrokes and other input being captured by an attacker.

Impact: Input devices will be unable to use the GameInput API.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select GameInput Service, and set its startup type to Disabled.

From the command line:

sc.exe config GameInputSvc start= disabled
Set-Service -Name GameInputSvc -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Geolocation Service Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: Geolocation Service is not disabled.

Checks that the service that tracks the system location and manages geofences is disabled.

This rule fails when the Geolocation Service service is present and its startType is not DISABLED.

Rationale: Revealing device location to software is generally undesirable and should not occur on high-security workstations.

Impact: Applications will be unable to obtain location data or geofence notifications.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Geolocation Service, and set its startup type to Disabled.

From the command line:

sc.exe config lfsvc start= disabled
Set-Service -Name lfsvc -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Discovery (TA0007)

Ensure IIS Admin Service Is Disabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: IIS Admin Service is not disabled.

Checks that the IIS Admin service, which administers the IIS metabase for SMTP and FTP, is disabled or not installed.

This rule fails when the IIS Admin Service service is present and its startType is not DISABLED.

Rationale: Running web-server components on a workstation greatly expands its attack surface and raises the chance of successful remote attack.

Impact: IIS, including its Web, SMTP and FTP services, will not function.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select IIS Admin Service, and set its startup type to Disabled.

From the command line:

sc.exe config IISADMIN start= disabled
Set-Service -Name IISADMIN -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Infrared Monitor Service Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: Infrared monitor service is not disabled.

Checks that the service that detects in-range infrared devices and launches file transfer is disabled or not installed.

This rule fails when the Infrared monitor service service is present and its startType is not DISABLED.

Rationale: Infrared connections, especially automatic file transfer, can be a route for data compromise; more secure connection methods should be used.

Impact: Infrared file transfers will no longer work.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Infrared monitor service, and set its startup type to Disabled.

From the command line:

sc.exe config irmon start= disabled
Set-Service -Name irmon -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Microsoft FTP Service Is Disabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: Microsoft FTP Service is not disabled.

Checks that the service that makes the computer an FTP server is disabled or not installed.

This rule fails when the Microsoft FTP Service service is present and its startType is not DISABLED.

Rationale: Hosting an FTP server, particularly a non-secure one, on a workstation greatly increases its attack surface.

Impact: The computer will not operate as an FTP server.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Microsoft FTP Service, and set its startup type to Disabled.

From the command line:

sc.exe config FTPSVC start= disabled
Set-Service -Name FTPSVC -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Microsoft iSCSI Initiator Service Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: Microsoft iSCSI Initiator Service is not disabled.

Checks that the service managing iSCSI sessions to remote targets is disabled.

This rule fails when the Microsoft iSCSI Initiator Service service is present and its startType is not DISABLED.

Rationale: iSCSI relies on the weak CHAP authentication protocol, which exposes credentials unless traffic is isolated or encrypted; it is inappropriate for secured workstations.

Impact: The computer will be unable to log in to or access iSCSI targets directly.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Microsoft iSCSI Initiator Service, and set its startup type to Disabled.

From the command line:

sc.exe config MSiSCSI start= disabled
Set-Service -Name MSiSCSI -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Execution (TA0002)

Ensure OpenSSH SSH Server Is Disabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: OpenSSH SSH Server is not disabled.

Checks that the OpenSSH server service is disabled or not installed.

This rule fails when the OpenSSH SSH Server service is present and its startType is not DISABLED.

Rationale: Hosting an SSH server on a workstation greatly increases its attack surface and remote exposure.

Impact: The workstation will not be able to act as an SSH host.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select OpenSSH SSH Server, and set its startup type to Disabled.

From the command line:

sc.exe config sshd start= disabled
Set-Service -Name sshd -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Peer Name Resolution Protocol Service Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: Peer Name Resolution Protocol is not disabled.

Checks that the serverless PNRP peer name-resolution service is disabled or not installed.

This rule fails when the Peer Name Resolution Protocol service is present and its startType is not DISABLED.

Rationale: Distributed, serverless name resolution is less controllable than centralized name services maintained by authorized staff.

Impact: Some peer-to-peer and collaborative applications, such as Remote Assistance, may not work.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Peer Name Resolution Protocol, and set its startup type to Disabled.

From the command line:

sc.exe config PNRPsvc start= disabled
Set-Service -Name PNRPsvc -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Discovery (TA0007)

Ensure Peer Networking Grouping Service Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: Peer Networking Grouping is not disabled.

Checks that the peer-to-peer grouping service is disabled or not installed.

This rule fails when the Peer Networking Grouping service is present and its startType is not DISABLED.

Rationale: Distributed, serverless peer name resolution is less controllable than centralized name services maintained by authorized staff.

Impact: Some applications, such as HomeGroup, may not work.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Peer Networking Grouping, and set its startup type to Disabled.

From the command line:

sc.exe config p2psvc start= disabled
Set-Service -Name p2psvc -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Discovery (TA0007)

Ensure Peer Networking Identity Manager Service Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: Peer Networking Identity Manager is not disabled.

Checks that the identity service for PNRP and peer-to-peer grouping is disabled or not installed.

This rule fails when the Peer Networking Identity Manager service is present and its startType is not DISABLED.

Rationale: Distributed, serverless peer name resolution is less controllable than centralized name services maintained by authorized staff.

Impact: PNRP and peer grouping, and applications such as HomeGroup and Remote Assistance, may not work.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Peer Networking Identity Manager, and set its startup type to Disabled.

From the command line:

sc.exe config p2pimsvc start= disabled
Set-Service -Name p2pimsvc -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Discovery (TA0007)

Ensure PNRP Machine Name Publication Service Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: PNRP Machine Name Publication Service is not disabled.

Checks that the service that publishes the machine name via PNRP is disabled or not installed.

This rule fails when the PNRP Machine Name Publication Service service is present and its startType is not DISABLED.

Rationale: Distributed, serverless peer name resolution is less controllable than centralized name services maintained by authorized staff.

Impact: Some peer-to-peer and collaborative applications, such as Remote Assistance, may not work.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select PNRP Machine Name Publication Service, and set its startup type to Disabled.

From the command line:

sc.exe config PNRPAutoReg start= disabled
Set-Service -Name PNRPAutoReg -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Discovery (TA0007)

Ensure Problem Reports And Solutions Control Panel Support Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: Problem Reports and Solutions Control Panel Support is not disabled.

Checks that the service supporting the Problem Reports and Solutions control panel is disabled.

This rule fails when the Problem Reports and Solutions Control Panel Support service is present and its startType is not DISABLED.

Rationale: This service reports issues to and from Microsoft; blocking it reduces the risk of exposing sensitive corporate information.

Impact: Viewing and sending system-level problem reports and solutions to Microsoft may stop working.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Problem Reports and Solutions Control Panel Support, and set its startup type to Disabled.

From the command line:

sc.exe config wercplsupport start= disabled
Set-Service -Name wercplsupport -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Remote Access Auto Connection Manager Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: Remote Access Auto Connection Manager is not disabled.

Checks that the service that auto-dials a remote connection when a program references a remote name or address is disabled.

This rule fails when the Remote Access Auto Connection Manager service is present and its startType is not DISABLED.

Rationale: Automatic demand-dial connections should be user-initiated, not started automatically by the system, in a high-security environment.

Impact: Dial-on-demand will no longer operate; remote dial-in and VPN connections must be started manually.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Remote Access Auto Connection Manager, and set its startup type to Disabled.

From the command line:

sc.exe config RasAuto start= disabled
Set-Service -Name RasAuto -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Remote Desktop Configuration Service Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: Remote Desktop Configuration is not disabled.

Checks that the Remote Desktop Configuration service, which handles RDP configuration and session maintenance in SYSTEM context, is disabled.

This rule fails when the Remote Desktop Configuration service is present and its startType is not DISABLED.

Rationale: Remote Desktop access increases risk; high-security environments should permit only local console access.

Impact: Users will be unable to use Remote Assistance.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Remote Desktop Configuration, and set its startup type to Disabled.

From the command line:

sc.exe config SessionEnv start= disabled
Set-Service -Name SessionEnv -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Remote Desktop Services Is Disabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: Remote Desktop Services is not disabled.

Checks that Remote Desktop Services, which lets users connect interactively to the computer, is disabled.

This rule fails when the Remote Desktop Services service is present and its startType is not DISABLED.

Rationale: Remote Desktop access is a significant remote-attack surface; high-security environments should permit only local console access.

Impact: Remote Desktop Services will not be available on the computer.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Remote Desktop Services, and set its startup type to Disabled.

From the command line:

sc.exe config TermService start= disabled
Set-Service -Name TermService -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Remote Desktop Services UserMode Port Redirector Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: Remote Desktop Services UserMode Port Redirector is not disabled.

Checks that the service redirecting printers, drives and ports within RDP sessions is disabled.

This rule fails when the Remote Desktop Services UserMode Port Redirector service is present and its startType is not DISABLED.

Rationale: Preventing redirection of COM, LPT and Plug-and-Play ports reduces avenues for data exfiltration and malicious code transfer inside RDP sessions.

Impact: Printers, drives and ports will not be redirected inside RDP sessions.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Remote Desktop Services UserMode Port Redirector, and set its startup type to Disabled.

From the command line:

sc.exe config UmRdpService start= disabled
Set-Service -Name UmRdpService -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Remote Procedure Call (RPC) Locator Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: Remote Procedure Call (RPC) Locator is not disabled.

Checks that the legacy RPC Locator service, retained only for application compatibility, is disabled.

This rule fails when the Remote Procedure Call (RPC) Locator service is present and its startType is not DISABLED.

Rationale: This legacy service serves no purpose beyond compatibility for very old software and should be disabled unless such an application requires it.

Impact: No impact unless an old, legacy application requires the service.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Remote Procedure Call (RPC) Locator, and set its startup type to Disabled.

From the command line:

sc.exe config RpcLocator start= disabled
Set-Service -Name RpcLocator -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Remote Registry Service Is Disabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: Remote Registry is not disabled.

Checks that the service allowing remote users to view and modify the registry is disabled.

This rule fails when the Remote Registry service is present and its startType is not DISABLED.

Rationale: Exposing the registry to remote access is a significant security risk on a secured workstation.

Impact: The registry can be viewed and changed only by local users; some remote management and vulnerability-scanning tools that rely on it will be affected.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Remote Registry, and set its startup type to Disabled.

From the command line:

sc.exe config RemoteRegistry start= disabled
Set-Service -Name RemoteRegistry -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Routing And Remote Access Service Is Disabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: Routing and Remote Access is not disabled.

Checks that the Routing and Remote Access service, which provides router and remote-access functionality, is disabled.

This rule fails when the Routing and Remote Access service is present and its startType is not DISABLED.

Rationale: Turning a workstation into a router or remote-access server is not an appropriate use in an enterprise-managed environment and expands remote exposure.

Impact: The computer cannot be configured as a Windows router between different connections.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Routing and Remote Access, and set its startup type to Disabled.

From the command line:

sc.exe config RemoteAccess start= disabled
Set-Service -Name RemoteAccess -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Server Service Is Disabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: Server is not disabled.

Checks that the Server service, which provides file, print and named-pipe sharing over the network, is disabled.

This rule fails when the Server service is present and its startType is not DISABLED.

Rationale: A secure workstation should be a client, not a server; sharing its resources for remote access notably increases the attack surface.

Impact: File, print and named-pipe sharing from this machine will be unavailable; some remote management and scanning tools that rely on it will be affected.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Server, and set its startup type to Disabled.

From the command line:

sc.exe config LanmanServer start= disabled
Set-Service -Name LanmanServer -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Simple TCP/IP Services Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: Simple TCP/IP Services is not disabled.

Checks that Simple TCP/IP Services (Character Generator, Daytime, Discard, Echo, Quote of the Day) is disabled or not installed.

This rule fails when the Simple TCP/IP Services service is present and its startType is not DISABLED.

Rationale: These legacy services have little purpose in a modern enterprise and increase network exposure and attack risk.

Impact: The Simple TCP/IP services will not be available.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Simple TCP/IP Services, and set its startup type to Disabled.

From the command line:

sc.exe config simptcp start= disabled
Set-Service -Name simptcp -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure SNMP Service Is Disabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: SNMP Service is not disabled.

Checks that the SNMP service, which processes inbound SNMP requests, is disabled or not installed.

This rule fails when the SNMP Service service is present and its startType is not DISABLED.

Rationale: Services that accept inbound network connections expand the attack surface; secure workstations should be managed locally.

Impact: The computer will be unable to process SNMP requests.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select SNMP Service, and set its startup type to Disabled.

From the command line:

sc.exe config SNMP start= disabled
Set-Service -Name SNMP -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Discovery (TA0007)

Ensure Special Administration Console Helper Is Disabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: Special Administration Console Helper is not disabled.

Checks that the service allowing administrators remote command-prompt access via Emergency Management Services is disabled or not installed.

This rule fails when the Special Administration Console Helper service is present and its startType is not DISABLED.

Rationale: A remotely accessible command prompt that permits remote management tasks is a significant security risk.

Impact: Users will not have a remote command prompt through Emergency Management Services.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Special Administration Console Helper, and set its startup type to Disabled.

From the command line:

sc.exe config sacsvr start= disabled
Set-Service -Name sacsvr -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure SSDP Discovery Service Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: SSDP Discovery is not disabled.

Checks that the SSDP Discovery service, which finds and advertises SSDP/UPnP devices, is disabled.

This rule fails when the SSDP Discovery service is present and its startType is not DISABLED.

Rationale: UPnP allows automatic discovery and attachment to network devices, which secured workstations should not advertise or perform.

Impact: SSDP-based devices will not be discovered.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select SSDP Discovery, and set its startup type to Disabled.

From the command line:

sc.exe config SSDPSRV start= disabled
Set-Service -Name SSDPSRV -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Discovery (TA0007)

Ensure UPnP Device Host Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: UPnP Device Host is not disabled.

Checks that the UPnP Device Host service, which hosts UPnP devices on the computer, is disabled.

This rule fails when the UPnP Device Host service is present and its startType is not DISABLED.

Rationale: UPnP allows automatic discovery and attachment to network devices, which secured workstations should not advertise or perform.

Impact: Hosted UPnP devices will stop working and no new hosted devices can be added.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select UPnP Device Host, and set its startup type to Disabled.

From the command line:

sc.exe config upnphost start= disabled
Set-Service -Name upnphost -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Web Management Service Is Disabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: Web Management Service is not disabled.

Checks that the Web Management Service, which enables remote and delegated IIS management, is disabled or not installed.

This rule fails when the Web Management Service service is present and its startType is not DISABLED.

Rationale: Remote web administration of IIS on a workstation greatly increases its attack surface and chance of successful remote attack.

Impact: Remote web-based management of IIS will be unavailable.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Web Management Service, and set its startup type to Disabled.

From the command line:

sc.exe config WMSvc start= disabled
Set-Service -Name WMSvc -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Windows Error Reporting Service Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: Windows Error Reporting Service is not disabled.

Checks that the Windows Error Reporting service, which reports program failures and delivers solutions, is disabled.

This rule fails when the Windows Error Reporting Service service is present and its startType is not DISABLED.

Rationale: Reporting errors directly to Microsoft offers no benefit to the enterprise and risks unknowingly exposing sensitive data.

Impact: Error reporting and the display of diagnostic and repair results may not work correctly.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Windows Error Reporting Service, and set its startup type to Disabled.

From the command line:

sc.exe config WerSvc start= disabled
Set-Service -Name WerSvc -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Windows Event Collector Service Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: Windows Event Collector is not disabled.

Checks that the Windows Event Collector service, which manages WS-Management event subscriptions from remote sources, is disabled.

This rule fails when the Windows Event Collector service is present and its startType is not DISABLED.

Rationale: Remote connections to secure workstations should be minimized, with management performed locally.

Impact: Event subscriptions cannot be created and forwarded events cannot be accepted; some remote management and audit tools depend on this service.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Windows Event Collector, and set its startup type to Disabled.

From the command line:

sc.exe config Wecsvc start= disabled
Set-Service -Name Wecsvc -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Windows Media Player Network Sharing Service Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: Windows Media Player Network Sharing Service is not disabled.

Checks that the service sharing Windows Media Player libraries over UPnP is disabled or not installed.

This rule fails when the Windows Media Player Network Sharing Service service is present and its startType is not DISABLED.

Rationale: Network sharing of media libraries has no place in an enterprise-managed environment.

Impact: Media Player libraries will not be shared over the network to other devices.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Windows Media Player Network Sharing Service, and set its startup type to Disabled.

From the command line:

sc.exe config WMPNetworkSvc start= disabled
Set-Service -Name WMPNetworkSvc -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Windows Mobile Hotspot Service Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: Windows Mobile Hotspot Service is not disabled.

Checks that the service that shares a cellular data connection with other devices is disabled.

This rule fails when the Windows Mobile Hotspot Service service is present and its startType is not DISABLED.

Rationale: Running a mobile hotspot from a managed computer can expose the internal network to wardrivers and other attackers.

Impact: The Windows Mobile Hotspot feature will be unavailable.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Windows Mobile Hotspot Service, and set its startup type to Disabled.

From the command line:

sc.exe config icssvc start= disabled
Set-Service -Name icssvc -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Windows Push Notifications System Service Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: Windows Push Notifications System Service is not disabled.

Checks that the service hosting the push-notification platform and its connection to the WNS server is disabled.

This rule fails when the Windows Push Notifications System Service service is present and its startType is not DISABLED.

Rationale: Push notifications receive third-party updates from the cloud; external systems should not be able to affect secure workstations.

Impact: Live Tiles and other features will not receive live updates.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Windows Push Notifications System Service, and set its startup type to Disabled.

From the command line:

sc.exe config WpnService start= disabled
Set-Service -Name WpnService -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Windows PushToInstall Service Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: Windows PushToInstall Service is not disabled.

Checks that the service managing apps pushed to the device from the Microsoft Store on other devices or the web is disabled.

This rule fails when the Windows PushToInstall Service service is present and its startType is not DISABLED.

Rationale: Application installation should be managed centrally by IT staff, not initiated remotely by end users.

Impact: Users will be unable to push apps to this device from the Microsoft Store on other devices or the web.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Windows PushToInstall Service, and set its startup type to Disabled.

From the command line:

sc.exe config PushToInstall start= disabled
Set-Service -Name PushToInstall -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Windows Remote Management (WS-Management) Is Disabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: Windows Remote Management (WS-Management) is not disabled.

Checks that the WinRM service, which listens on the network for WS-Management requests, is disabled.

This rule fails when the Windows Remote Management (WS-Management) service is present and its startType is not DISABLED.

Rationale: Services that accept inbound network connections expand the attack surface; secure workstations should be managed locally.

Impact: Remote management of the system through WinRM will be lost; some remote management tools depend on this service.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Windows Remote Management (WS-Management), and set its startup type to Disabled.

From the command line:

sc.exe config WinRM start= disabled
Set-Service -Name WinRM -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure World Wide Web Publishing Service Is Disabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: World Wide Web Publishing Service is not disabled.

Checks that the World Wide Web Publishing service, which provides IIS web connectivity, is disabled or not installed.

This rule fails when the World Wide Web Publishing Service service is present and its startType is not DISABLED.

Rationale: Hosting a website from a workstation greatly increases its attack surface and chance of successful remote attack.

Impact: IIS web services will not function.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select World Wide Web Publishing Service, and set its startup type to Disabled.

From the command line:

sc.exe config W3SVC start= disabled
Set-Service -Name W3SVC -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Xbox Accessory Management Service Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: Xbox Accessory Management Service is not disabled.

Checks that the service managing connected Xbox accessories is disabled.

This rule fails when the Xbox Accessory Management Service service is present and its startType is not DISABLED.

Rationale: Xbox Live is a gaming service with no place in an enterprise-managed environment.

Impact: Connected Xbox accessories may not function.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Xbox Accessory Management Service, and set its startup type to Disabled.

From the command line:

sc.exe config XboxGipSvc start= disabled
Set-Service -Name XboxGipSvc -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Xbox Live Auth Manager Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: Xbox Live Auth Manager is not disabled.

Checks that the service providing authentication and authorization for Xbox Live is disabled.

This rule fails when the Xbox Live Auth Manager service is present and its startType is not DISABLED.

Rationale: Xbox Live is a gaming service with no place in an enterprise-managed environment.

Impact: Connections to Xbox Live may fail, along with applications that use the service.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Xbox Live Auth Manager, and set its startup type to Disabled.

From the command line:

sc.exe config XblAuthManager start= disabled
Set-Service -Name XblAuthManager -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Xbox Live Game Save Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: Xbox Live Game Save is not disabled.

Checks that the service that syncs save data for Xbox Live save-enabled games is disabled.

This rule fails when the Xbox Live Game Save service is present and its startType is not DISABLED.

Rationale: Xbox Live is a gaming service with no place in an enterprise-managed environment.

Impact: Game save data will not upload to or download from Xbox Live.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Xbox Live Game Save, and set its startup type to Disabled.

From the command line:

sc.exe config XblGameSave start= disabled
Set-Service -Name XblGameSave -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Xbox Live Networking Service Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

Finding: Xbox Live Networking Service is not disabled.

Checks that the service supporting the Windows.Networking.XboxLive API is disabled.

This rule fails when the Xbox Live Networking Service service is present and its startType is not DISABLED.

Rationale: Xbox Live is a gaming service with no place in an enterprise-managed environment.

Impact: Connections to Xbox Live may fail, along with applications that use the service.

Remediation

Open Computer Configuration\Policies\Windows Settings\Security Settings\System Services in the Group Policy editor (or services.msc), select Xbox Live Networking Service, and set its startup type to Disabled.

From the command line:

sc.exe config XboxNetApiSvc start= disabled
Set-Service -Name XboxNetApiSvc -StartupType Disabled
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Execution (TA0002)