---
title: CIS Windows 11 System Services: 44 Checks | Wartiva
description: Wartiva's 44 checks for section 5, System Services, of the CIS Microsoft Windows 11 Stand-alone Benchmark: what each one finds, why it matters, and how to fix it.
url: https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html
updated: 2026-10-07
---

CIS Microsoft Windows 11 Stand-alone Benchmark · Section 5

# Windows 11 System Services: 44 Checks

Wartiva runs 44 checks for section 5, System Services, of the CIS Microsoft Windows 11 Stand-alone Benchmark. Each one lists what it finds, why it matters, and how to fix it.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. [How Wartiva works →](https://wartiva.com/platform.html)

## [Ensure Bluetooth Audio Gateway Service Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#bluetooth-audio-gateway-service-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Bluetooth Audio Gateway Service is not disabled.

Checks that the service backing the audio-gateway role of the Bluetooth Hands-Free Profile is disabled.

This rule fails when the **Bluetooth Audio Gateway Service** service is present and its `startType` is not `DISABLED`.

**Rationale:** Bluetooth carries inherent wireless risks and its traffic is often weakly encrypted, so it should not be permitted on high-security workstations.

**Impact:** Bluetooth hands-free audio devices will not work with the computer.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Bluetooth Audio Gateway Service**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config BTAGService start= disabled
Set-Service -Name BTAGService -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

## [Ensure Bluetooth Support Service Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#bluetooth-support-service-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Bluetooth Support Service is not disabled.

Checks that the service supporting discovery and pairing of remote Bluetooth devices is disabled.

This rule fails when the **Bluetooth Support Service** service is present and its `startType` is not `DISABLED`.

**Rationale:** Bluetooth carries inherent wireless risks and its traffic is often weakly encrypted, so it should not be permitted on high-security workstations.

**Impact:** Installed Bluetooth devices may stop working and new devices cannot be discovered or paired; some Windows components such as Devices and Printers may misbehave.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Bluetooth Support Service**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config bthserv start= disabled
Set-Service -Name bthserv -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

## [Ensure Computer Browser Service Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#computer-browser-service-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Computer Browser is not disabled.

Checks that the legacy Computer Browser service, which maintains and serves a list of networked computers, is disabled or not installed.

This rule fails when the **Computer Browser** service is present and its `startType` is not `DISABLED`.

**Rationale:** This legacy service generates noisy master-browser election traffic and lets anyone enumerate online machines and shares, aiding attacker reconnaissance.

**Impact:** The network list of computers and their shares will no longer be maintained.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Computer Browser**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config Browser start= disabled
Set-Service -Name Browser -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Discovery ([TA0007](https://attack.mitre.org/tactics/TA0007/))

## [Ensure Downloaded Maps Manager Service Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#downloaded-maps-manager-service-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Downloaded Maps Manager is not disabled.

Checks that the service giving applications access to downloaded maps is disabled.

This rule fails when the **Downloaded Maps Manager** service is present and its `startType` is not `DISABLED`.

**Rationale:** Mapping features can leak the device location and pull data from third parties, which is undesirable in high-security environments.

**Impact:** Applications will be unable to access downloaded map data.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Downloaded Maps Manager**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config MapsBroker start= disabled
Set-Service -Name MapsBroker -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

## [Ensure GameInput Service Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#gameinput-service-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** GameInput Service is not disabled.

Checks that the service exposing keyboards, mice and game controllers through the GameInput API is disabled.

This rule fails when the **GameInput Service** service is present and its `startType` is not `DISABLED`.

**Rationale:** The GameInput API pipes input via Direct Memory Access to reduce latency, which increases the risk of keystrokes and other input being captured by an attacker.

**Impact:** Input devices will be unable to use the GameInput API.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **GameInput Service**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config GameInputSvc start= disabled
Set-Service -Name GameInputSvc -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

## [Ensure Geolocation Service Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#geolocation-service-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Geolocation Service is not disabled.

Checks that the service that tracks the system location and manages geofences is disabled.

This rule fails when the **Geolocation Service** service is present and its `startType` is not `DISABLED`.

**Rationale:** Revealing device location to software is generally undesirable and should not occur on high-security workstations.

**Impact:** Applications will be unable to obtain location data or geofence notifications.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Geolocation Service**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config lfsvc start= disabled
Set-Service -Name lfsvc -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Discovery ([TA0007](https://attack.mitre.org/tactics/TA0007/))

## [Ensure IIS Admin Service Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#iis-admin-service-is-disabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** IIS Admin Service is not disabled.

Checks that the IIS Admin service, which administers the IIS metabase for SMTP and FTP, is disabled or not installed.

This rule fails when the **IIS Admin Service** service is present and its `startType` is not `DISABLED`.

**Rationale:** Running web-server components on a workstation greatly expands its attack surface and raises the chance of successful remote attack.

**Impact:** IIS, including its Web, SMTP and FTP services, will not function.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **IIS Admin Service**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config IISADMIN start= disabled
Set-Service -Name IISADMIN -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## [Ensure Infrared Monitor Service Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#infrared-monitor-service-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Infrared monitor service is not disabled.

Checks that the service that detects in-range infrared devices and launches file transfer is disabled or not installed.

This rule fails when the **Infrared monitor service** service is present and its `startType` is not `DISABLED`.

**Rationale:** Infrared connections, especially automatic file transfer, can be a route for data compromise; more secure connection methods should be used.

**Impact:** Infrared file transfers will no longer work.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Infrared monitor service**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config irmon start= disabled
Set-Service -Name irmon -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

## [Ensure Link-Layer Topology Discovery Mapper Service Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#link-layer-topology-discovery-mapper-service-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Link-Layer Topology Discovery Mapper is not disabled.

Checks that the service that builds a network map of PCs and devices is disabled.

This rule fails when the **Link-Layer Topology Discovery Mapper** service is present and its `startType` is not `DISABLED`.

**Rationale:** The topology-discovery feature can be abused to enumerate and connect to network devices; disabling it prevents responses to discovery requests.

**Impact:** The Windows Network Map will not function correctly.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Link-Layer Topology Discovery Mapper**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config lltdsvc start= disabled
Set-Service -Name lltdsvc -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Discovery ([TA0007](https://attack.mitre.org/tactics/TA0007/))

## [Ensure Microsoft FTP Service Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#microsoft-ftp-service-is-disabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Microsoft FTP Service is not disabled.

Checks that the service that makes the computer an FTP server is disabled or not installed.

This rule fails when the **Microsoft FTP Service** service is present and its `startType` is not `DISABLED`.

**Rationale:** Hosting an FTP server, particularly a non-secure one, on a workstation greatly increases its attack surface.

**Impact:** The computer will not operate as an FTP server.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Microsoft FTP Service**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config FTPSVC start= disabled
Set-Service -Name FTPSVC -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## [Ensure Microsoft iSCSI Initiator Service Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#microsoft-iscsi-initiator-service-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Microsoft iSCSI Initiator Service is not disabled.

Checks that the service managing iSCSI sessions to remote targets is disabled.

This rule fails when the **Microsoft iSCSI Initiator Service** service is present and its `startType` is not `DISABLED`.

**Rationale:** iSCSI relies on the weak CHAP authentication protocol, which exposes credentials unless traffic is isolated or encrypted; it is inappropriate for secured workstations.

**Impact:** The computer will be unable to log in to or access iSCSI targets directly.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Microsoft iSCSI Initiator Service**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config MSiSCSI start= disabled
Set-Service -Name MSiSCSI -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

## [Ensure OpenSSH SSH Server Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#openssh-ssh-server-is-disabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** OpenSSH SSH Server is not disabled.

Checks that the OpenSSH server service is disabled or not installed.

This rule fails when the **OpenSSH SSH Server** service is present and its `startType` is not `DISABLED`.

**Rationale:** Hosting an SSH server on a workstation greatly increases its attack surface and remote exposure.

**Impact:** The workstation will not be able to act as an SSH host.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **OpenSSH SSH Server**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config sshd start= disabled
Set-Service -Name sshd -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## [Ensure Peer Name Resolution Protocol Service Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#peer-name-resolution-protocol-service-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Peer Name Resolution Protocol is not disabled.

Checks that the serverless PNRP peer name-resolution service is disabled or not installed.

This rule fails when the **Peer Name Resolution Protocol** service is present and its `startType` is not `DISABLED`.

**Rationale:** Distributed, serverless name resolution is less controllable than centralized name services maintained by authorized staff.

**Impact:** Some peer-to-peer and collaborative applications, such as Remote Assistance, may not work.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Peer Name Resolution Protocol**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config PNRPsvc start= disabled
Set-Service -Name PNRPsvc -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Discovery ([TA0007](https://attack.mitre.org/tactics/TA0007/))

## [Ensure Peer Networking Grouping Service Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#peer-networking-grouping-service-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Peer Networking Grouping is not disabled.

Checks that the peer-to-peer grouping service is disabled or not installed.

This rule fails when the **Peer Networking Grouping** service is present and its `startType` is not `DISABLED`.

**Rationale:** Distributed, serverless peer name resolution is less controllable than centralized name services maintained by authorized staff.

**Impact:** Some applications, such as HomeGroup, may not work.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Peer Networking Grouping**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config p2psvc start= disabled
Set-Service -Name p2psvc -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Discovery ([TA0007](https://attack.mitre.org/tactics/TA0007/))

## [Ensure Peer Networking Identity Manager Service Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#peer-networking-identity-manager-service-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Peer Networking Identity Manager is not disabled.

Checks that the identity service for PNRP and peer-to-peer grouping is disabled or not installed.

This rule fails when the **Peer Networking Identity Manager** service is present and its `startType` is not `DISABLED`.

**Rationale:** Distributed, serverless peer name resolution is less controllable than centralized name services maintained by authorized staff.

**Impact:** PNRP and peer grouping, and applications such as HomeGroup and Remote Assistance, may not work.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Peer Networking Identity Manager**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config p2pimsvc start= disabled
Set-Service -Name p2pimsvc -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Discovery ([TA0007](https://attack.mitre.org/tactics/TA0007/))

## [Ensure PNRP Machine Name Publication Service Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#pnrp-machine-name-publication-service-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** PNRP Machine Name Publication Service is not disabled.

Checks that the service that publishes the machine name via PNRP is disabled or not installed.

This rule fails when the **PNRP Machine Name Publication Service** service is present and its `startType` is not `DISABLED`.

**Rationale:** Distributed, serverless peer name resolution is less controllable than centralized name services maintained by authorized staff.

**Impact:** Some peer-to-peer and collaborative applications, such as Remote Assistance, may not work.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **PNRP Machine Name Publication Service**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config PNRPAutoReg start= disabled
Set-Service -Name PNRPAutoReg -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Discovery ([TA0007](https://attack.mitre.org/tactics/TA0007/))

## [Ensure Print Spooler Service Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#print-spooler-service-is-disabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Print Spooler is not disabled.

Checks that the Print Spooler service, which queues print jobs and drives printers, is disabled.

This rule fails when the **Print Spooler** service is present and its `startType` is not `DISABLED`.

**Rationale:** Disabling the Print Spooler mitigates the PrintNightmare vulnerability (CVE-2021-34527) and other attacks that target the service.

**Impact:** Users will be unable to print, including printing to file formats such as PDF that use the spooler.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Print Spooler**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config Spooler start= disabled
Set-Service -Name Spooler -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

## [Ensure Problem Reports And Solutions Control Panel Support Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#problem-reports-and-solutions-control-panel-support-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Problem Reports and Solutions Control Panel Support is not disabled.

Checks that the service supporting the Problem Reports and Solutions control panel is disabled.

This rule fails when the **Problem Reports and Solutions Control Panel Support** service is present and its `startType` is not `DISABLED`.

**Rationale:** This service reports issues to and from Microsoft; blocking it reduces the risk of exposing sensitive corporate information.

**Impact:** Viewing and sending system-level problem reports and solutions to Microsoft may stop working.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Problem Reports and Solutions Control Panel Support**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config wercplsupport start= disabled
Set-Service -Name wercplsupport -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

## [Ensure Remote Access Auto Connection Manager Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#remote-access-auto-connection-manager-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Remote Access Auto Connection Manager is not disabled.

Checks that the service that auto-dials a remote connection when a program references a remote name or address is disabled.

This rule fails when the **Remote Access Auto Connection Manager** service is present and its `startType` is not `DISABLED`.

**Rationale:** Automatic demand-dial connections should be user-initiated, not started automatically by the system, in a high-security environment.

**Impact:** Dial-on-demand will no longer operate; remote dial-in and VPN connections must be started manually.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Remote Access Auto Connection Manager**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config RasAuto start= disabled
Set-Service -Name RasAuto -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

## [Ensure Remote Desktop Configuration Service Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#remote-desktop-configuration-service-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Remote Desktop Configuration is not disabled.

Checks that the Remote Desktop Configuration service, which handles RDP configuration and session maintenance in SYSTEM context, is disabled.

This rule fails when the **Remote Desktop Configuration** service is present and its `startType` is not `DISABLED`.

**Rationale:** Remote Desktop access increases risk; high-security environments should permit only local console access.

**Impact:** Users will be unable to use Remote Assistance.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Remote Desktop Configuration**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config SessionEnv start= disabled
Set-Service -Name SessionEnv -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## [Ensure Remote Desktop Services Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#remote-desktop-services-is-disabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Remote Desktop Services is not disabled.

Checks that Remote Desktop Services, which lets users connect interactively to the computer, is disabled.

This rule fails when the **Remote Desktop Services** service is present and its `startType` is not `DISABLED`.

**Rationale:** Remote Desktop access is a significant remote-attack surface; high-security environments should permit only local console access.

**Impact:** Remote Desktop Services will not be available on the computer.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Remote Desktop Services**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config TermService start= disabled
Set-Service -Name TermService -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## [Ensure Remote Desktop Services UserMode Port Redirector Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#remote-desktop-services-usermode-port-redirector-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Remote Desktop Services UserMode Port Redirector is not disabled.

Checks that the service redirecting printers, drives and ports within RDP sessions is disabled.

This rule fails when the **Remote Desktop Services UserMode Port Redirector** service is present and its `startType` is not `DISABLED`.

**Rationale:** Preventing redirection of COM, LPT and Plug-and-Play ports reduces avenues for data exfiltration and malicious code transfer inside RDP sessions.

**Impact:** Printers, drives and ports will not be redirected inside RDP sessions.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Remote Desktop Services UserMode Port Redirector**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config UmRdpService start= disabled
Set-Service -Name UmRdpService -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## [Ensure Remote Procedure Call (RPC) Locator Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#remote-procedure-call-rpc-locator-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Remote Procedure Call (RPC) Locator is not disabled.

Checks that the legacy RPC Locator service, retained only for application compatibility, is disabled.

This rule fails when the **Remote Procedure Call (RPC) Locator** service is present and its `startType` is not `DISABLED`.

**Rationale:** This legacy service serves no purpose beyond compatibility for very old software and should be disabled unless such an application requires it.

**Impact:** No impact unless an old, legacy application requires the service.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Remote Procedure Call (RPC) Locator**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config RpcLocator start= disabled
Set-Service -Name RpcLocator -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

## [Ensure Remote Registry Service Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#remote-registry-service-is-disabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Remote Registry is not disabled.

Checks that the service allowing remote users to view and modify the registry is disabled.

This rule fails when the **Remote Registry** service is present and its `startType` is not `DISABLED`.

**Rationale:** Exposing the registry to remote access is a significant security risk on a secured workstation.

**Impact:** The registry can be viewed and changed only by local users; some remote management and vulnerability-scanning tools that rely on it will be affected.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Remote Registry**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config RemoteRegistry start= disabled
Set-Service -Name RemoteRegistry -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## [Ensure Routing And Remote Access Service Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#routing-and-remote-access-service-is-disabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Routing and Remote Access is not disabled.

Checks that the Routing and Remote Access service, which provides router and remote-access functionality, is disabled.

This rule fails when the **Routing and Remote Access** service is present and its `startType` is not `DISABLED`.

**Rationale:** Turning a workstation into a router or remote-access server is not an appropriate use in an enterprise-managed environment and expands remote exposure.

**Impact:** The computer cannot be configured as a Windows router between different connections.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Routing and Remote Access**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config RemoteAccess start= disabled
Set-Service -Name RemoteAccess -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## [Ensure Server Service Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#server-service-is-disabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Server is not disabled.

Checks that the Server service, which provides file, print and named-pipe sharing over the network, is disabled.

This rule fails when the **Server** service is present and its `startType` is not `DISABLED`.

**Rationale:** A secure workstation should be a client, not a server; sharing its resources for remote access notably increases the attack surface.

**Impact:** File, print and named-pipe sharing from this machine will be unavailable; some remote management and scanning tools that rely on it will be affected.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Server**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config LanmanServer start= disabled
Set-Service -Name LanmanServer -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## [Ensure Simple TCP/IP Services Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#simple-tcp-ip-services-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Simple TCP/IP Services is not disabled.

Checks that Simple TCP/IP Services (Character Generator, Daytime, Discard, Echo, Quote of the Day) is disabled or not installed.

This rule fails when the **Simple TCP/IP Services** service is present and its `startType` is not `DISABLED`.

**Rationale:** These legacy services have little purpose in a modern enterprise and increase network exposure and attack risk.

**Impact:** The Simple TCP/IP services will not be available.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Simple TCP/IP Services**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config simptcp start= disabled
Set-Service -Name simptcp -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## [Ensure SNMP Service Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#snmp-service-is-disabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** SNMP Service is not disabled.

Checks that the SNMP service, which processes inbound SNMP requests, is disabled or not installed.

This rule fails when the **SNMP Service** service is present and its `startType` is not `DISABLED`.

**Rationale:** Services that accept inbound network connections expand the attack surface; secure workstations should be managed locally.

**Impact:** The computer will be unable to process SNMP requests.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **SNMP Service**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config SNMP start= disabled
Set-Service -Name SNMP -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Discovery ([TA0007](https://attack.mitre.org/tactics/TA0007/))

## [Ensure Special Administration Console Helper Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#special-administration-console-helper-is-disabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Special Administration Console Helper is not disabled.

Checks that the service allowing administrators remote command-prompt access via Emergency Management Services is disabled or not installed.

This rule fails when the **Special Administration Console Helper** service is present and its `startType` is not `DISABLED`.

**Rationale:** A remotely accessible command prompt that permits remote management tasks is a significant security risk.

**Impact:** Users will not have a remote command prompt through Emergency Management Services.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Special Administration Console Helper**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config sacsvr start= disabled
Set-Service -Name sacsvr -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## [Ensure SSDP Discovery Service Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#ssdp-discovery-service-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** SSDP Discovery is not disabled.

Checks that the SSDP Discovery service, which finds and advertises SSDP/UPnP devices, is disabled.

This rule fails when the **SSDP Discovery** service is present and its `startType` is not `DISABLED`.

**Rationale:** UPnP allows automatic discovery and attachment to network devices, which secured workstations should not advertise or perform.

**Impact:** SSDP-based devices will not be discovered.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **SSDP Discovery**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config SSDPSRV start= disabled
Set-Service -Name SSDPSRV -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Discovery ([TA0007](https://attack.mitre.org/tactics/TA0007/))

## [Ensure UPnP Device Host Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#upnp-device-host-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** UPnP Device Host is not disabled.

Checks that the UPnP Device Host service, which hosts UPnP devices on the computer, is disabled.

This rule fails when the **UPnP Device Host** service is present and its `startType` is not `DISABLED`.

**Rationale:** UPnP allows automatic discovery and attachment to network devices, which secured workstations should not advertise or perform.

**Impact:** Hosted UPnP devices will stop working and no new hosted devices can be added.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **UPnP Device Host**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config upnphost start= disabled
Set-Service -Name upnphost -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## [Ensure Web Management Service Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#web-management-service-is-disabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Web Management Service is not disabled.

Checks that the Web Management Service, which enables remote and delegated IIS management, is disabled or not installed.

This rule fails when the **Web Management Service** service is present and its `startType` is not `DISABLED`.

**Rationale:** Remote web administration of IIS on a workstation greatly increases its attack surface and chance of successful remote attack.

**Impact:** Remote web-based management of IIS will be unavailable.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Web Management Service**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config WMSvc start= disabled
Set-Service -Name WMSvc -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## [Ensure Windows Error Reporting Service Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#windows-error-reporting-service-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Windows Error Reporting Service is not disabled.

Checks that the Windows Error Reporting service, which reports program failures and delivers solutions, is disabled.

This rule fails when the **Windows Error Reporting Service** service is present and its `startType` is not `DISABLED`.

**Rationale:** Reporting errors directly to Microsoft offers no benefit to the enterprise and risks unknowingly exposing sensitive data.

**Impact:** Error reporting and the display of diagnostic and repair results may not work correctly.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Windows Error Reporting Service**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config WerSvc start= disabled
Set-Service -Name WerSvc -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

## [Ensure Windows Event Collector Service Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#windows-event-collector-service-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Windows Event Collector is not disabled.

Checks that the Windows Event Collector service, which manages WS-Management event subscriptions from remote sources, is disabled.

This rule fails when the **Windows Event Collector** service is present and its `startType` is not `DISABLED`.

**Rationale:** Remote connections to secure workstations should be minimized, with management performed locally.

**Impact:** Event subscriptions cannot be created and forwarded events cannot be accepted; some remote management and audit tools depend on this service.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Windows Event Collector**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config Wecsvc start= disabled
Set-Service -Name Wecsvc -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## [Ensure Windows Media Player Network Sharing Service Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#windows-media-player-network-sharing-service-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Windows Media Player Network Sharing Service is not disabled.

Checks that the service sharing Windows Media Player libraries over UPnP is disabled or not installed.

This rule fails when the **Windows Media Player Network Sharing Service** service is present and its `startType` is not `DISABLED`.

**Rationale:** Network sharing of media libraries has no place in an enterprise-managed environment.

**Impact:** Media Player libraries will not be shared over the network to other devices.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Windows Media Player Network Sharing Service**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config WMPNetworkSvc start= disabled
Set-Service -Name WMPNetworkSvc -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

## [Ensure Windows Mobile Hotspot Service Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#windows-mobile-hotspot-service-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Windows Mobile Hotspot Service is not disabled.

Checks that the service that shares a cellular data connection with other devices is disabled.

This rule fails when the **Windows Mobile Hotspot Service** service is present and its `startType` is not `DISABLED`.

**Rationale:** Running a mobile hotspot from a managed computer can expose the internal network to wardrivers and other attackers.

**Impact:** The Windows Mobile Hotspot feature will be unavailable.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Windows Mobile Hotspot Service**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config icssvc start= disabled
Set-Service -Name icssvc -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## [Ensure Windows Push Notifications System Service Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#windows-push-notifications-system-service-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Windows Push Notifications System Service is not disabled.

Checks that the service hosting the push-notification platform and its connection to the WNS server is disabled.

This rule fails when the **Windows Push Notifications System Service** service is present and its `startType` is not `DISABLED`.

**Rationale:** Push notifications receive third-party updates from the cloud; external systems should not be able to affect secure workstations.

**Impact:** Live Tiles and other features will not receive live updates.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Windows Push Notifications System Service**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config WpnService start= disabled
Set-Service -Name WpnService -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

## [Ensure Windows PushToInstall Service Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#windows-pushtoinstall-service-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Windows PushToInstall Service is not disabled.

Checks that the service managing apps pushed to the device from the Microsoft Store on other devices or the web is disabled.

This rule fails when the **Windows PushToInstall Service** service is present and its `startType` is not `DISABLED`.

**Rationale:** Application installation should be managed centrally by IT staff, not initiated remotely by end users.

**Impact:** Users will be unable to push apps to this device from the Microsoft Store on other devices or the web.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Windows PushToInstall Service**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config PushToInstall start= disabled
Set-Service -Name PushToInstall -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

## [Ensure Windows Remote Management (WS-Management) Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#windows-remote-management-ws-management-is-disabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Windows Remote Management (WS-Management) is not disabled.

Checks that the WinRM service, which listens on the network for WS-Management requests, is disabled.

This rule fails when the **Windows Remote Management (WS-Management)** service is present and its `startType` is not `DISABLED`.

**Rationale:** Services that accept inbound network connections expand the attack surface; secure workstations should be managed locally.

**Impact:** Remote management of the system through WinRM will be lost; some remote management tools depend on this service.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Windows Remote Management (WS-Management)**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config WinRM start= disabled
Set-Service -Name WinRM -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## [Ensure World Wide Web Publishing Service Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#world-wide-web-publishing-service-is-disabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** World Wide Web Publishing Service is not disabled.

Checks that the World Wide Web Publishing service, which provides IIS web connectivity, is disabled or not installed.

This rule fails when the **World Wide Web Publishing Service** service is present and its `startType` is not `DISABLED`.

**Rationale:** Hosting a website from a workstation greatly increases its attack surface and chance of successful remote attack.

**Impact:** IIS web services will not function.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **World Wide Web Publishing Service**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config W3SVC start= disabled
Set-Service -Name W3SVC -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## [Ensure Xbox Accessory Management Service Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#xbox-accessory-management-service-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Xbox Accessory Management Service is not disabled.

Checks that the service managing connected Xbox accessories is disabled.

This rule fails when the **Xbox Accessory Management Service** service is present and its `startType` is not `DISABLED`.

**Rationale:** Xbox Live is a gaming service with no place in an enterprise-managed environment.

**Impact:** Connected Xbox accessories may not function.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Xbox Accessory Management Service**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config XboxGipSvc start= disabled
Set-Service -Name XboxGipSvc -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

## [Ensure Xbox Live Auth Manager Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#xbox-live-auth-manager-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Xbox Live Auth Manager is not disabled.

Checks that the service providing authentication and authorization for Xbox Live is disabled.

This rule fails when the **Xbox Live Auth Manager** service is present and its `startType` is not `DISABLED`.

**Rationale:** Xbox Live is a gaming service with no place in an enterprise-managed environment.

**Impact:** Connections to Xbox Live may fail, along with applications that use the service.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Xbox Live Auth Manager**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config XblAuthManager start= disabled
Set-Service -Name XblAuthManager -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

## [Ensure Xbox Live Game Save Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#xbox-live-game-save-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Xbox Live Game Save is not disabled.

Checks that the service that syncs save data for Xbox Live save-enabled games is disabled.

This rule fails when the **Xbox Live Game Save** service is present and its `startType` is not `DISABLED`.

**Rationale:** Xbox Live is a gaming service with no place in an enterprise-managed environment.

**Impact:** Game save data will not upload to or download from Xbox Live.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Xbox Live Game Save**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config XblGameSave start= disabled
Set-Service -Name XblGameSave -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

## [Ensure Xbox Live Networking Service Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system-services.html#xbox-live-networking-service-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 5

**Finding:** Xbox Live Networking Service is not disabled.

Checks that the service supporting the Windows.Networking.XboxLive API is disabled.

This rule fails when the **Xbox Live Networking Service** service is present and its `startType` is not `DISABLED`.

**Rationale:** Xbox Live is a gaming service with no place in an enterprise-managed environment.

**Impact:** Connections to Xbox Live may fail, along with applications that use the service.

### Remediation

Open **Computer Configuration\Policies\Windows Settings\Security Settings\System Services** in the Group Policy editor (or **services.msc**), select **Xbox Live Networking Service**, and set its startup type to **Disabled**.

From the command line:

```powershell
sc.exe config XboxNetApiSvc start= disabled
Set-Service -Name XboxNetApiSvc -StartupType Disabled
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
