Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →
All 57 checks on this page
- Ensure The Sudo Command Is Disabled
- 18.9.3 Audit Process Creation
- Ensure Command Line Is Included In Process Creation Events
- 18.9.4 Credentials Delegation
- Ensure Encryption Oracle Remediation Forces Updated Clients
- Ensure Remote Host Delegation Of Non-Exportable Credentials Is Enabled
- 18.9.5 Device Guard
- Ensure Credential Guard Is Enabled With UEFI Lock
- Ensure Kernel Mode Hardware Enforced Stack Protection Is In Enforcement Mode
- Ensure Secure Launch Is Enabled
- Ensure Virtualization Based Protection Of Code Integrity Uses UEFI Lock
- Ensure Virtualization Based Security Is Enabled
- Ensure Virtualization Based Security Platform Level Is Secure Boot Or Higher
- Ensure Virtualization Based Security Requires UEFI Memory Attributes Table
- 18.9.7 Device Installation
- Ensure Automatic Download Of Device Metadata From The Internet Is Prevented
- Ensure Device Setup Class Restrictions Apply To Already Installed Devices
- Ensure IEEE 1394 Device Setup Classes Are In The Prevented Device List
- Ensure Installation Of Devices Matching Configured Setup Classes Is Prevented
- 18.9.13 Early Launch Antimalware
- Ensure Boot Start Driver Initialization Allows Good Unknown And Critical Bad Drivers
- 18.9.17 Filesystem (formerly NTFS Filesystem)
- Ensure CLFS Logfile Authentication Is Enabled
- 18.9.19 Group Policy
- Ensure Continue Experiences On This Device Is Disabled
- 18.9.20 Internet Communication Management
- Ensure Access To The Store For Unknown File Types Is Turned Off
- Ensure Downloading Of Print Drivers Over HTTP Is Turned Off
- Ensure Handwriting Personalization Data Sharing Is Turned Off
- Ensure Handwriting Recognition Error Reporting Is Turned Off
- Ensure Internet Connection Wizard Cannot Connect To Microsoft.com
- Ensure Internet Download For Web Publishing And Ordering Wizards Is Turned Off
- Ensure Printing Over HTTP Is Turned Off
- Ensure Registration Referring To Microsoft.com Is Turned Off
- Ensure Search Companion Content File Updates Are Turned Off
- Ensure The Order Prints Picture Task Is Turned Off
- Ensure The Publish To Web Task For Files And Folders Is Turned Off
- Ensure The Windows Customer Experience Improvement Program Is Turned Off
- Ensure The Windows Messenger Customer Experience Improvement Program Is Turned Off
- Ensure Windows Error Reporting Is Turned Off
- 18.9.23 Kerberos
- Ensure Device Authentication Using Certificate Is Set To Automatic
- 18.9.24 Kernel DMA Protection
- Ensure External Devices Incompatible With Kernel DMA Protection Are Blocked
- 18.9.27 Local Security Authority
- Ensure Custom SSPs And APs Cannot Be Loaded Into LSASS
- Ensure LSASS Runs As A Protected Process With UEFI Lock
- 18.9.28 Locale Services
- Ensure Copying Of User Input Methods To The System Account For Sign In Is Disallowed
- 18.9.29 Logon
- Ensure App Notifications On The Lock Screen Are Turned Off
- Ensure Convenience PIN Sign In Is Disabled
- Ensure The Network Selection UI Is Not Displayed
- Ensure Users Are Blocked From Showing Account Details On Sign In
- 18.9.33 OS Policies
- Ensure Clipboard Synchronization Across Devices Is Disabled
- Ensure Upload Of User Activities Is Disabled
- 18.9.35 Power Management
- Ensure A Password Is Required When Waking On Battery
- Ensure A Password Is Required When Waking Plugged In
- Ensure Network Connectivity During Connected Standby On Battery Is Disabled
- Ensure Network Connectivity During Connected Standby Plugged In Is Disabled
- Ensure Standby States When Sleeping On Battery Are Disabled
- Ensure Standby States When Sleeping Plugged In Are Disabled
- 18.9.37 Remote Assistance
- Ensure Offer Remote Assistance Is Disabled
- Ensure Solicited Remote Assistance Is Disabled
- 18.9.38 Remote Procedure Call
- Ensure RPC Endpoint Mapper Client Authentication Is Enabled
- Ensure Unauthenticated RPC Clients Are Restricted
- 18.9.49 Troubleshooting and Diagnostics
- Ensure MSDT Interactive Communication With Support Provider Is Disabled
- Ensure PerfTrack Is Disabled
- 18.9.51 User Profiles
- Ensure The Advertising ID Is Turned Off
- 18.9.53 Windows Time Service
- Ensure The Windows NTP Client Is Enabled
Ensure The Sudo Command Is Disabled
Finding: The sudo command is enabled.
Checks whether the sudo.exe command line elevation tool is disabled.
This rule fails when sudoEnabled is not DISABLED.
Rationale: Disabling sudo removes a command line elevation path that could be abused for local privilege escalation.
Impact: Users cannot use the sudo command to run elevated commands from the command line.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Configure the behavior of the sudo command and set it to Enabled: Disabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Sudo" /v Enabled /t REG_DWORD /d 0 /f
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
18.9.3 Audit Process Creation
Ensure Command Line Is Included In Process Creation Events
Finding: Command line information is not included in process creation events.
Checks whether the command line used to start each new process is recorded in the process-creation (4688) audit events.
This rule fails when processCreationIncludeCmdLineEnabled is not true.
Rationale: Capturing the full command line lets investigators see exactly what was executed, which is essential for detecting and reconstructing malicious activity.
Impact: Command-line arguments, which may occasionally contain sensitive data such as passwords, are written to the security event log for every new process.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Audit Process Creation\Include command line in process creation events and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Audit" /v ProcessCreationIncludeCmdLine_Enabled /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 8.8 Collect Command-Line Audit Logs
- NIST SP 800-53 Rev. 5: AC-6 Least Privilege; AU-2 Event Logging
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Execution (TA0002)
18.9.4 Credentials Delegation
Ensure Encryption Oracle Remediation Forces Updated Clients
Finding: Encryption Oracle Remediation does not force updated clients.
Checks the CredSSP encryption oracle remediation level that governs whether unpatched clients or servers may establish CredSSP (e.g. RDP) sessions.
This rule fails when allowEncryptionOracle is not FORCE.
Rationale: Forcing updated clients blocks connections to or from hosts missing the CVE-2018-0886 CredSSP fix, closing an encryption-oracle remote code execution vector.
Impact: CredSSP clients and services cannot fall back to the vulnerable protocol version, so all remote hosts must be patched through at least May 2018.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Credentials Delegation\Encryption Oracle Remediation and set it to Enabled: Force Updated Clients.
From the command line:
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\CredSSP\Parameters" /v AllowEncryptionOracle /t REG_DWORD /d 0 /f
- Framework mappings
- CIS Controls v8: 10.5 Enable Anti-Exploitation Features
- NIST SP 800-53 Rev. 5: SI-16 Memory Protection
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Remote Host Delegation Of Non-Exportable Credentials Is Enabled
Finding: Remote host delegation of non-exportable credentials is not enabled.
Checks whether Restricted Admin and Remote Credential Guard sessions may delegate only non-exportable credentials to the remote host.
This rule fails when allowProtectedCreds is not true.
Rationale: Delegating non-exportable credentials keeps reusable secrets off the remote host, reducing credential theft during Remote Desktop sessions.
Impact: Remote Desktop connections can use Restricted Admin or Remote Credential Guard mode.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Credentials Delegation\Remote host allows delegation of non-exportable credentials and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\CredentialsDelegation" /v AllowProtectedCreds /t REG_DWORD /d 1 /f
- Risk
- Insecure Use of Secrets
- MITRE ATT&CK tactic
- Credential Access (TA0006)
18.9.5 Device Guard
Ensure Credential Guard Is Enabled With UEFI Lock
Finding: Credential Guard is not enabled with UEFI lock.
Checks whether Windows Defender Credential Guard is enabled and locked into UEFI firmware.
This rule fails when lsaCfgFlags is not ENABLED_WITH_UEFI_LOCK.
Rationale: Credential Guard isolates LSA secrets inside VBS so credential-theft tools cannot read them; the UEFI lock stops an attacker from disabling it remotely.
Impact: Domain credentials are protected by VBS isolation, and Credential Guard cannot be turned off without physical access to clear the UEFI variable.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Device Guard\Turn On Virtualization Based Security: Credential Guard Configuration and set it to Enabled with UEFI lock.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard" /v LsaCfgFlags /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 10.5 Enable Anti-Exploitation Features
- NIST SP 800-53 Rev. 5: SI-16 Memory Protection
- Risk
- Insecure Use of Secrets
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Ensure Kernel Mode Hardware Enforced Stack Protection Is In Enforcement Mode
Finding: Kernel-mode Hardware-enforced Stack Protection is not in enforcement mode.
Checks whether the hardware-enforced kernel shadow stack is active and enforcing, blocking operations that violate call-stack integrity.
This rule fails when configureKernelShadowStacksLaunch is not ENABLED_ENFORCEMENT.
Rationale: Enforcement mode stops return-oriented programming (ROP) attacks against the kernel by rejecting corrupted return addresses rather than only logging them.
Impact: Requires compatible CPUs; incompatible kernel drivers may need updates before enforcement works cleanly.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Device Guard\Turn On Virtualization Based Security: Kernel-mode Hardware-enforced Stack Protection and set it to Enabled: Enabled in enforcement mode.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard" /v ConfigureKernelShadowStacksLaunch /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 10.5 Enable Anti-Exploitation Features
- NIST SP 800-53 Rev. 5: SI-16 Memory Protection
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure Secure Launch Is Enabled
Finding: System Guard Secure Launch is not enabled.
Checks whether System Guard Secure Launch (Dynamic Root of Trust for Measurement) is enabled to establish a hardware-rooted, measured boot.
This rule fails when configureSystemGuardLaunch is not ENABLED.
Rationale: Secure Launch re-establishes trust in the boot environment using the CPU, protecting against firmware-level and early-boot tampering.
Impact: On supported hardware the system performs a measured Secure Launch during boot.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Device Guard\Turn On Virtualization Based Security: Secure Launch Configuration and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard" /v ConfigureSystemGuardLaunch /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 10.5 Enable Anti-Exploitation Features
- NIST SP 800-53 Rev. 5: SI-16 Memory Protection
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure Virtualization Based Protection Of Code Integrity Uses UEFI Lock
Finding: Virtualization Based Protection of Code Integrity is not enabled with UEFI lock.
Checks whether Hypervisor-Protected Code Integrity (HVCI) is enabled and locked into UEFI firmware so it cannot be turned off remotely.
This rule fails when hypervisorEnforcedCodeIntegrity is not ENABLED_WITH_UEFI_LOCK.
Rationale: HVCI uses VBS to verify kernel-mode code integrity; the UEFI lock prevents an attacker from silently disabling it via policy.
Impact: Unsigned or improperly signed kernel drivers are blocked, and HVCI cannot be disabled without physical access to clear the UEFI variable.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Device Guard\Turn On Virtualization Based Security: Virtualization Based Protection of Code Integrity and set it to Enabled with UEFI lock.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard" /v HypervisorEnforcedCodeIntegrity /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 10.5 Enable Anti-Exploitation Features
- NIST SP 800-53 Rev. 5: SI-16 Memory Protection
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure Virtualization Based Security Is Enabled
Finding: Virtualization Based Security is not enabled.
Checks whether Virtualization Based Security (VBS), which uses the hypervisor to isolate critical OS components, is turned on.
This rule fails when enableVirtualizationBasedSecurity is not true.
Rationale: VBS is the foundation for Credential Guard, HVCI, and other protections that isolate secrets and kernel code from a compromised OS.
Impact: VBS is enabled on hardware that supports it; compatible virtualization and Secure Boot are required.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Device Guard\Turn On Virtualization Based Security and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard" /v EnableVirtualizationBasedSecurity /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 10.5 Enable Anti-Exploitation Features
- NIST SP 800-53 Rev. 5: SI-16 Memory Protection
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure Virtualization Based Security Platform Level Is Secure Boot Or Higher
Finding: Virtualization Based Security platform security level is below Secure Boot.
Checks that the VBS platform security level requires at least Secure Boot (optionally Secure Boot with DMA protection).
This rule fails when requirePlatformSecurityFeatures is neither SECURE_BOOT nor SECURE_BOOT_AND_DMA_PROTECTION.
Rationale: Requiring Secure Boot ensures VBS is anchored to a verified boot chain; adding DMA protection further blocks memory attacks from malicious peripherals.
Impact: VBS requires Secure Boot, and optionally hardware DMA protection, to be present.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Device Guard\Turn On Virtualization Based Security: Select Platform Security Level and set it to Enabled: Secure Boot or higher.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard" /v RequirePlatformSecurityFeatures /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 10.5 Enable Anti-Exploitation Features
- NIST SP 800-53 Rev. 5: SI-16 Memory Protection
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure Virtualization Based Security Requires UEFI Memory Attributes Table
Finding: Virtualization Based Security does not require the UEFI Memory Attributes Table.
Checks whether VBS requires firmware to provide a UEFI Memory Attributes Table (MAT).
This rule fails when hvcimatRequired is not true.
Rationale: Requiring the MAT ensures firmware memory is described correctly to the hypervisor, strengthening the memory-integrity guarantees VBS relies on.
Impact: VBS is only enabled on firmware that supplies a UEFI Memory Attributes Table.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Device Guard\Turn On Virtualization Based Security: Require UEFI Memory Attributes Table and set it to True (checked).
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard" /v HVCIMATRequired /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 10.5 Enable Anti-Exploitation Features
- NIST SP 800-53 Rev. 5: SI-16 Memory Protection
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
18.9.7 Device Installation
Ensure Automatic Download Of Device Metadata From The Internet Is Prevented
Finding: Automatic download of device metadata from the internet is not prevented.
Checks whether Windows is blocked from retrieving device metadata for installed devices from the internet.
This rule fails when preventDeviceMetadataFromNetwork is not true.
Rationale: Preventing automatic metadata downloads avoids unnecessary outbound connections and reduces data shared with external services.
Impact: Device metadata is not fetched from the internet; devices still function with locally available metadata.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Device Installation\Prevent automatic download of applications associated with device metadata and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceMetadata" /v PreventDeviceMetadataFromNetwork /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 2.5 Allowlist Authorized Software; 10.5 Enable Anti-Exploitation Features
- NIST SP 800-53 Rev. 5: CM-7 Least Functionality; CM-10 Software Usage Restrictions; SI-16 Memory Protection
- NIST SP 800-171 Rev. 2: 3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; 3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
- CMMC 2.0 Level 2: CM.L2-3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; SC.L2-3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
Ensure Device Setup Class Restrictions Apply To Already Installed Devices
Finding: Device setup class restrictions do not apply to already installed devices.
Checks whether the device setup class installation restrictions also apply to matching devices that were installed before the policy took effect.
This rule fails when denyDeviceClassesRetroactive is not true.
Rationale: Applying the restriction retroactively removes access to already-installed devices in the blocked classes, closing a gap an attacker could otherwise use.
Impact: Matching devices already present on the system are also blocked, not just newly connected ones.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Device Installation\Device Installation Restrictions\Prevent installation of devices using drivers that match these device setup classes: Also apply to matching devices that are already installed. and set it to True (checked).
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceInstall\Restrictions" /v DenyDeviceClassesRetroactive /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 10.5 Enable Anti-Exploitation Features
- NIST SP 800-53 Rev. 5: SI-16 Memory Protection
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure IEEE 1394 Device Setup Classes Are In The Prevented Device List
Finding: IEEE 1394 device setup classes are missing from the prevented device list.
Checks that the four IEEE 1394 (FireWire) device setup class GUIDs are present in the list of device classes Windows is prevented from installing.
This rule fails when any of the four IEEE 1394 device setup class GUIDs is absent from denyDeviceClassesList.
Rationale: IEEE 1394 controllers can perform Direct Memory Access; blocking their drivers helps protect a BitLocker-protected host from DMA attacks that could recover encryption keys from memory.
Impact: IEEE 1394 (FireWire) drives and devices can no longer be installed on the host.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Device Installation\Device Installation Restrictions\Prevent installation of devices using drivers that match these device setup classes and set it to Enabled, then add the four IEEE 1394 device setup class GUIDs.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceInstall\Restrictions\DenyDeviceClasses" /v 1 /t REG_SZ /d "{d48179be-ec20-11d1-b6b8-00c04fa372a7}" /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceInstall\Restrictions\DenyDeviceClasses" /v 2 /t REG_SZ /d "{7ebefbc0-3200-11d2-b4c2-00a0C9697d07}" /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceInstall\Restrictions\DenyDeviceClasses" /v 3 /t REG_SZ /d "{c06ff265-ae09-48f0-812c-16753d7cba83}" /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceInstall\Restrictions\DenyDeviceClasses" /v 4 /t REG_SZ /d "{6bdd1fc1-810f-11d0-bec7-08002be2092f}" /f
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Installation Of Devices Matching Configured Setup Classes Is Prevented
Finding: Installation of devices matching the configured setup classes is not prevented.
Checks whether Windows is prevented from installing drivers for the device setup classes listed in the deny list.
This rule fails when denyDeviceClasses is not true.
Rationale: Blocking driver installation for specified device classes reduces the attack surface from untrusted or DMA-capable hardware such as IEEE 1394 controllers.
Impact: Windows will not install or update drivers for devices whose setup class GUID is in the deny list.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Device Installation\Device Installation Restrictions\Prevent installation of devices using drivers that match these device setup classes and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceInstall\Restrictions" /v DenyDeviceClasses /t REG_DWORD /d 1 /f
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Initial Access (TA0001)
18.9.13 Early Launch Antimalware
Ensure Boot Start Driver Initialization Allows Good Unknown And Critical Bad Drivers
Finding: Boot-start driver initialization policy is not set to good, unknown and bad but critical.
Checks which boot-start drivers Early Launch Antimalware permits to initialize based on their classification.
This rule fails when driverLoadPolicy is not GOOD_PLUS_UNKNOWN_PLUS_BAD_CRITICAL.
Rationale: Allowing good, unknown, and only boot-critical bad drivers blocks known-malicious non-critical boot drivers while keeping the system bootable.
Impact: Non-critical drivers classified as bad by ELAM are prevented from loading at boot.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Early Launch Antimalware\Boot-Start Driver Initialization Policy and set it to Enabled: Good, unknown and bad but critical.
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Policies\EarlyLaunch" /v DriverLoadPolicy /t REG_DWORD /d 3 /f
- Framework mappings
- CIS Controls v8: 10.5 Enable Anti-Exploitation Features
- NIST SP 800-53 Rev. 5: SI-16 Memory Protection
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Persistence (TA0003)
18.9.17 Filesystem (formerly NTFS Filesystem)
Ensure CLFS Logfile Authentication Is Enabled
Finding: CLFS logfile authentication is not enabled.
Checks whether the Common Log File System validates the authenticity of log files before processing them.
This rule fails when clfsAuthenticationChecking is not true.
Rationale: Authenticating CLFS logfiles blocks a class of parsing vulnerabilities in the CLFS driver that attackers have used for local privilege escalation.
Impact: CLFS rejects log files that fail authentication checks.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Filesystem\Enable / disable CLFS logfile authentication and set it to Enabled.
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Policies" /v ClfsAuthenticationChecking /t REG_DWORD /d 1 /f
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
18.9.19 Group Policy
Ensure Continue Experiences On This Device Is Disabled
Finding: Continue experiences on this device is enabled.
Checks whether the Connected Devices Platform, which lets Windows share activities across a user's devices, is turned off.
This rule fails when enableCdp is not false.
Rationale: Disabling cross-device continuation limits the sharing of user activity data between devices and cloud services.
Impact: Users can no longer resume activities from this device on another device.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Group Policy\Continue experiences on this device and set it to Disabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v EnableCdp /t REG_DWORD /d 0 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
18.9.20 Internet Communication Management
Ensure Access To The Store For Unknown File Types Is Turned Off
Finding: Access to the Store for unknown file types is not turned off.
Checks whether the 'Look for an app in the Store' option is disabled when a user opens a file with an unknown extension.
This rule fails when noUseStoreOpenWith is not true.
Rationale: Preventing Store lookups for unknown file types stops users from being steered to install arbitrary apps to open unrecognized files.
Impact: Users are not offered the Microsoft Store when opening files with unknown extensions.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off access to the Store and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Explorer" /v NoUseStoreOpenWith /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 2.5 Allowlist Authorized Software
- NIST SP 800-53 Rev. 5: CM-7 Least Functionality; CM-10 Software Usage Restrictions
- NIST SP 800-171 Rev. 2: 3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; 3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
- CMMC 2.0 Level 2: CM.L2-3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; SC.L2-3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Execution (TA0002)
Ensure Downloading Of Print Drivers Over HTTP Is Turned Off
Finding: Downloading of print drivers over HTTP is not turned off.
Checks whether Windows is blocked from downloading print drivers over HTTP.
This rule fails when disableWebPnPDownload is not true.
Rationale: Blocking HTTP print-driver downloads prevents fetching and installing driver code from untrusted internet sources.
Impact: Print drivers must be obtained from local or managed sources rather than over HTTP.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off downloading of print drivers over HTTP and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers" /v DisableWebPnPDownload /t REG_DWORD /d 1 /f
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Execution (TA0002)
Ensure Handwriting Personalization Data Sharing Is Turned Off
Finding: Handwriting personalization data sharing is not turned off.
Checks whether the automatic sharing of handwriting recognition personalization data with Microsoft is turned off.
This rule fails when preventHandwritingDataSharing is not true.
Rationale: Stopping this upload keeps potentially sensitive handwriting samples from leaving the host.
Impact: Handwriting personalization data is no longer collected and sent to Microsoft.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off handwriting personalization data sharing and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\TabletPC" /v PreventHandwritingDataSharing /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
Ensure Handwriting Recognition Error Reporting Is Turned Off
Finding: Handwriting recognition error reporting is not turned off.
Checks whether handwriting recognition error reports are prevented from being sent to Microsoft.
This rule fails when preventHandwritingErrorReports is not true.
Rationale: Suppressing these reports avoids transmitting recognized text and ink samples that may contain sensitive information.
Impact: Handwriting recognition error reports are not generated or uploaded.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off handwriting recognition error reporting and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\HandwritingErrorReports" /v PreventHandwritingErrorReports /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
Ensure Internet Connection Wizard Cannot Connect To Microsoft.com
Finding: Internet Connection Wizard can connect to Microsoft.com.
Checks whether the Internet Connection Wizard is blocked from contacting Microsoft.com to download a list of ISPs.
This rule fails when exitOnMSICW is not true.
Rationale: Blocking this connection reduces unnecessary outbound traffic to external Microsoft services during connection setup.
Impact: The Internet Connection Wizard no longer downloads referral content from Microsoft.com.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off Internet Connection Wizard if URL connection is referring to Microsoft.com and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Internet Connection Wizard" /v ExitOnMSICW /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
Ensure Internet Download For Web Publishing And Ordering Wizards Is Turned Off
Finding: Internet download for web publishing and online ordering wizards is not turned off.
Checks whether Windows is prevented from downloading a provider list for web publishing and online ordering wizards.
This rule fails when noWebServices is not true.
Rationale: Preventing these downloads limits outbound connections to third-party web-service providers.
Impact: Users cannot use the internet-based provider lists in the publishing and ordering wizards.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off Internet download for Web publishing and online ordering wizards and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoWebServices /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
Ensure Printing Over HTTP Is Turned Off
Finding: Printing over HTTP is not turned off.
Checks whether the client's ability to print to printers over HTTP is turned off.
This rule fails when disableHTTPPrinting is not true.
Rationale: Disabling HTTP printing stops the host from sending print jobs to internet-hosted printers over an unencrypted channel.
Impact: The client can no longer print to HTTP-based printers on the internet.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off printing over HTTP and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers" /v DisableHTTPPrinting /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
Ensure Registration Referring To Microsoft.com Is Turned Off
Finding: Registration referring to Microsoft.com is not turned off.
Checks whether the Windows Registration Wizard is blocked from connecting to Microsoft.com.
This rule fails when noRegistration is not true.
Rationale: Blocking online registration avoids sending user and system details to external Microsoft registration services.
Impact: Users cannot register the product online through the wizard.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off Registration if URL connection is referring to Microsoft.com and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Registration Wizard Control" /v NoRegistration /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
Ensure Search Companion Content File Updates Are Turned Off
Finding: Search Companion content file updates are not turned off.
Checks whether the Search Companion is prevented from automatically downloading content file updates.
This rule fails when disableContentFileUpdates is not true.
Rationale: Preventing automatic content downloads reduces unsolicited outbound connections to Microsoft services.
Impact: Search Companion does not download updated content files over the internet.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off Search Companion content file updates and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\SearchCompanion" /v DisableContentFileUpdates /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
Ensure The Order Prints Picture Task Is Turned Off
Finding: The Order Prints picture task is not turned off.
Checks whether the 'Order Prints Online' task, which uploads pictures to online print providers, is removed.
This rule fails when noOnlinePrintsWizard is not true.
Rationale: Removing the online prints task prevents users from uploading local images to third-party internet services.
Impact: The 'Order Prints Online' option no longer appears in picture folders and tasks.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off the "Order Prints" picture task and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoOnlinePrintsWizard /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
Ensure The Publish To Web Task For Files And Folders Is Turned Off
Finding: The Publish to Web task for files and folders is not turned off.
Checks whether the 'Publish to Web' task for files and folders is removed from File Explorer.
This rule fails when noPublishingWizard is not true.
Rationale: Removing this task prevents users from uploading local files and folders to internet hosting services.
Impact: The 'Publish to Web' option is no longer available for files and folders.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off the "Publish to Web" task for files and folders and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoPublishingWizard /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
Ensure The Windows Customer Experience Improvement Program Is Turned Off
Finding: The Windows Customer Experience Improvement Program is not turned off.
Checks whether Windows is prevented from participating in the Customer Experience Improvement Program.
This rule fails when ceipEnable is not false.
Rationale: Opting out stops Windows usage and configuration data from being collected and sent to Microsoft.
Impact: Windows no longer collects or transmits Customer Experience Improvement data.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off Windows Customer Experience Improvement Program and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\SQMClient\Windows" /v CEIPEnable /t REG_DWORD /d 0 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
Ensure The Windows Messenger Customer Experience Improvement Program Is Turned Off
Finding: The Windows Messenger Customer Experience Improvement Program is not turned off.
Checks whether Windows Messenger is prevented from participating in the Customer Experience Improvement Program.
This rule fails when ceip is not false.
Rationale: Opting out stops usage data from being collected and sent to Microsoft by Windows Messenger.
Impact: Windows Messenger no longer collects or transmits Customer Experience Improvement data.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off the Windows Messenger Customer Experience Improvement Program and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Messenger\Client" /v CEIP /t REG_DWORD /d 2 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
Ensure Windows Error Reporting Is Turned Off
Finding: Windows Error Reporting is not turned off.
Checks whether Windows Error Reporting is disabled so crash and error reports are not sent to Microsoft.
This rule fails when windowsErrorReportingDisabled is not true.
Rationale: Error reports can contain memory snapshots and other sensitive data; disabling reporting keeps that information on the host.
Impact: Application and system error data is no longer transmitted to Microsoft.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off Windows Error Reporting and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Windows Error Reporting" /v Disabled /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
18.9.23 Kerberos
Ensure Device Authentication Using Certificate Is Set To Automatic
Finding: Device authentication using certificate is not set to automatic.
Checks whether the device attempts Kerberos PKINIT certificate authentication, falling back to password authentication when a supporting domain controller is unavailable.
This rule fails when devicePKInitEnabled is not true or devicePKInitBehavior is not AUTOMATIC.
Rationale: Certificate-based device authentication is stronger than username and password; the automatic mode uses it whenever possible without breaking connectivity.
Impact: None; this matches the default behavior when the supporting infrastructure is present.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Kerberos\Support device authentication using certificate and set it to Enabled: Automatic.
From the command line:
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\kerberos\parameters" /v DevicePKInitEnabled /t REG_DWORD /d 1 /f
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\kerberos\parameters" /v DevicePKInitBehavior /t REG_DWORD /d 0 /f
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Credential Access (TA0006)
18.9.24 Kernel DMA Protection
Ensure External Devices Incompatible With Kernel DMA Protection Are Blocked
Finding: External devices incompatible with Kernel DMA Protection are not blocked.
Checks the enumeration policy for external DMA-capable devices that are not compatible with Kernel DMA Protection.
This rule fails when deviceEnumerationPolicy is not BLOCK_ALL.
Rationale: Blocking incompatible external DMA devices prevents malicious peripherals from reading system memory, which could expose credentials or encryption keys.
Impact: External Thunderbolt/PCIe devices lacking DMA-remapping support are not enumerated, even while a user is signed in.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Kernel DMA Protection\Enumeration policy for external devices incompatible with Kernel DMA Protection and set it to Enabled: Block All.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Kernel DMA Protection" /v DeviceEnumerationPolicy /t REG_DWORD /d 0 /f
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Credential Access (TA0006)
18.9.27 Local Security Authority
Ensure Custom SSPs And APs Cannot Be Loaded Into LSASS
Finding: Custom SSPs and APs can be loaded into LSASS.
Checks whether custom Security Support Providers and Authentication Packages are blocked from being loaded into the LSASS process.
This rule fails when allowCustomSSPsAPs is not false.
Rationale: Blocking custom SSPs/APs prevents attackers from injecting credential-harvesting modules into LSASS.
Impact: Third-party authentication modules that rely on loading into LSASS will not load.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Local Security Authority\Allow Custom SSPs and APs to be loaded into LSASS and set it to Disabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v AllowCustomSSPsAPs /t REG_DWORD /d 0 /f
- Framework mappings
- CIS Controls v8: 10.5 Enable Anti-Exploitation Features
- NIST SP 800-53 Rev. 5: SI-16 Memory Protection
- Risk
- Insecure Use of Secrets
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Ensure LSASS Runs As A Protected Process With UEFI Lock
Finding: LSASS does not run as a protected process with UEFI lock.
Checks whether LSASS runs as a Protected Process Light with the configuration locked into UEFI firmware.
This rule fails when runAsPPL is not ENABLED_WITH_UEFI_LOCK.
Rationale: Running LSASS as a protected process blocks non-protected code (such as Mimikatz) from reading its memory; the UEFI lock prevents remote disabling.
Impact: Unsigned or non-protected plug-ins cannot load into LSASS, and the protection cannot be removed without physical access to clear the UEFI variable.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Local Security Authority\Configures LSASS to run as a protected process and set it to Enabled: Enabled with UEFI Lock.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v RunAsPPL /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 10.5 Enable Anti-Exploitation Features
- NIST SP 800-53 Rev. 5: SI-16 Memory Protection
- Risk
- Insecure Use of Secrets
- MITRE ATT&CK tactic
- Credential Access (TA0006)
18.9.28 Locale Services
Ensure Copying Of User Input Methods To The System Account For Sign In Is Disallowed
Finding: Copying of user input methods to the system account for sign-in is allowed.
Checks whether user-configured input methods are prevented from being copied to the system account used at the sign-in screen.
This rule fails when blockUserInputMethodsForSignIn is not true.
Rationale: Blocking this copy keeps user-specific input method configurations from influencing the system account context at sign-in.
Impact: The system account uses only the system default input methods at the sign-in screen.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Locale Services\Disallow copying of user input methods to the system account for sign-in and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\ControlPanel\International" /v BlockUserInputMethodsForSignIn /t REG_DWORD /d 1 /f
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Execution (TA0002)
18.9.29 Logon
Ensure App Notifications On The Lock Screen Are Turned Off
Finding: App notifications on the lock screen are not turned off.
Checks whether application notifications are prevented from appearing on the lock screen.
This rule fails when disableLockScreenAppNotifications is not true.
Rationale: Suppressing lock-screen notifications keeps potentially sensitive content from being shown on an unattended device.
Impact: Apps can no longer display notifications on the lock screen.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Logon\Turn off app notifications on the lock screen and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v DisableLockScreenAppNotifications /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
Ensure Convenience PIN Sign In Is Disabled
Finding: Convenience PIN sign-in is enabled.
Checks whether domain users are prevented from signing in with a convenience PIN.
This rule fails when allowDomainPINLogon is not false.
Rationale: A convenience PIN is drawn from a small character set and is generally weaker than a password, so disabling it preserves stronger authentication.
Impact: Domain users must sign in with their password rather than a convenience PIN.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Logon\Turn on convenience PIN sign-in and set it to Disabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v AllowDomainPINLogon /t REG_DWORD /d 0 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Ensure The Network Selection UI Is Not Displayed
Finding: The network selection UI is displayed on the logon screen.
Checks whether the network selection UI is hidden from users on the lock/logon screen.
This rule fails when dontDisplayNetworkSelectionUI is not true.
Rationale: Hiding network selection prevents an unauthenticated person from changing network connectivity from the lock screen.
Impact: Users cannot change the device's network connection from the sign-in screen.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Logon\Do not display network selection UI and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v DontDisplayNetworkSelectionUI /t REG_DWORD /d 1 /f
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Users Are Blocked From Showing Account Details On Sign In
Finding: Users are not blocked from showing account details on sign-in.
Checks whether users are prevented from displaying account details, such as email address, on the sign-in screen.
This rule fails when blockUserFromShowingAccountDetailsOnSignin is not true.
Rationale: Hiding account details reduces the information an onlooker can gather from an unattended lock screen.
Impact: Account details are not shown on the sign-in screen.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Logon\Block user from showing account details on sign-in and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v BlockUserFromShowingAccountDetailsOnSignin /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process
- NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Discovery (TA0007)
18.9.33 OS Policies
Ensure Clipboard Synchronization Across Devices Is Disabled
Finding: Clipboard synchronization across devices is enabled.
Checks whether clipboard contents are prevented from being synchronized across a user's devices through the cloud.
This rule fails when allowCrossDeviceClipboard is not false.
Rationale: Disabling cross-device clipboard keeps potentially sensitive copied data from being uploaded to and shared through cloud services.
Impact: Clipboard contents are not shared between this device and the user's other devices.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\OS Policies\Allow Clipboard synchronization across devices and set it to Disabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v AllowCrossDeviceClipboard /t REG_DWORD /d 0 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
Ensure Upload Of User Activities Is Disabled
Finding: Upload of User Activities is enabled.
Checks whether the Activity Feed is prevented from uploading published user activities to the cloud.
This rule fails when uploadUserActivities is not false.
Rationale: Blocking activity uploads limits the user-behavior data shared with Microsoft cloud services.
Impact: User activities are not uploaded, so cross-device timeline continuation is unavailable.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\OS Policies\Allow upload of User Activities and set it to Disabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v UploadUserActivities /t REG_DWORD /d 0 /f
18.9.35 Power Management
Ensure A Password Is Required When Waking On Battery
Finding: A password is not required when the computer wakes on battery.
Checks whether the user is prompted for a password when the device wakes from sleep on battery.
This rule fails when requirePasswordOnWakeOnBattery is not true.
Rationale: Requiring a password on wake prevents someone with physical access from using an unattended device without authenticating.
Impact: Users must re-enter their password when the device wakes from sleep on battery.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Power Management\Sleep Settings\Require a password when a computer wakes (on battery) and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Power\PowerSettings\0e796bdb-100d-47d6-a2d5-f7d2daa51f51" /v DCSettingIndex /t REG_DWORD /d 1 /f
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure A Password Is Required When Waking Plugged In
Finding: A password is not required when the computer wakes while plugged in.
Checks whether the user is prompted for a password when the device wakes from sleep while plugged in.
This rule fails when requirePasswordOnWakeWhenPluggedIn is not true.
Rationale: Requiring a password on wake prevents someone with physical access from using an unattended device without authenticating.
Impact: Users must re-enter their password when the device wakes from sleep while plugged in.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Power Management\Sleep Settings\Require a password when a computer wakes (plugged in) and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Power\PowerSettings\0e796bdb-100d-47d6-a2d5-f7d2daa51f51" /v ACSettingIndex /t REG_DWORD /d 1 /f
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Network Connectivity During Connected Standby On Battery Is Disabled
Finding: Network connectivity during connected-standby on battery is allowed.
Checks whether network connectivity is prevented while the device is in connected standby running on battery.
This rule fails when allowNetworkConDuringStandbyOnBattery is not false.
Rationale: Disabling standby network connectivity reduces the window in which a sleeping, unattended device is reachable over the network.
Impact: The device does not maintain network connectivity during connected standby on battery.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Power Management\Sleep Settings\Allow network connectivity during connected-standby (on battery) and set it to Disabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Power\PowerSettings\f15576e8-98b7-4186-b944-eafa664402d9" /v DCSettingIndex /t REG_DWORD /d 0 /f
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Network Connectivity During Connected Standby Plugged In Is Disabled
Finding: Network connectivity during connected-standby plugged in is allowed.
Checks whether network connectivity is prevented while the device is in connected standby while plugged in.
This rule fails when allowNetworkConDuringStandbyPluggedIn is not false.
Rationale: Disabling standby network connectivity reduces the window in which a sleeping, unattended device is reachable over the network.
Impact: The device does not maintain network connectivity during connected standby when plugged in.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Power Management\Sleep Settings\Allow network connectivity during connected-standby (plugged in) and set it to Disabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Power\PowerSettings\f15576e8-98b7-4186-b944-eafa664402d9" /v ACSettingIndex /t REG_DWORD /d 0 /f
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Standby States When Sleeping On Battery Are Disabled
Finding: Standby states (S1-S3) when sleeping on battery are allowed.
Checks whether S1-S3 standby sleep states are prevented while the device is on battery.
This rule fails when allowStandbyStatesWhenSleeping is not false.
Rationale: Blocking standby sleep states keeps encryption keys and other secrets out of easily attacked powered memory when the device is left unattended.
Impact: On battery the device uses hibernate or shutdown instead of S1-S3 standby.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Power Management\Sleep Settings\Allow standby states (S1-S3) when sleeping (on battery) and set it to Disabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Power\PowerSettings\abfc2519-3608-4c2a-94ea-171b0ed546ab" /v DCSettingIndex /t REG_DWORD /d 0 /f
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process
- NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Ensure Standby States When Sleeping Plugged In Are Disabled
Finding: Standby states (S1-S3) when sleeping plugged in are allowed.
Checks whether S1-S3 standby sleep states are prevented while the device is plugged in.
This rule fails when allowStandbyStatesWhenPluggedIn is not false.
Rationale: Blocking standby sleep states keeps encryption keys and other secrets out of easily attacked powered memory when the device is left unattended.
Impact: When plugged in the device uses hibernate or shutdown instead of S1-S3 standby.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Power Management\Sleep Settings\Allow standby states (S1-S3) when sleeping (plugged in) and set it to Disabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Power\PowerSettings\abfc2519-3608-4c2a-94ea-171b0ed546ab" /v ACSettingIndex /t REG_DWORD /d 0 /f
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process
- NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Credential Access (TA0006)
18.9.37 Remote Assistance
Ensure Offer Remote Assistance Is Disabled
Finding: Offer Remote Assistance is enabled.
Checks whether unsolicited (offered) Remote Assistance connections to this computer are prevented.
This rule fails when fAllowUnsolicited is not false.
Rationale: Disabling offered Remote Assistance stops helpers from initiating remote control sessions without an explicit user request, closing a remote-access avenue.
Impact: Support staff cannot offer Remote Assistance; users must solicit help through other means if solicited assistance is also disabled.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Remote Assistance\Configure Offer Remote Assistance and set it to Disabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v fAllowUnsolicited /t REG_DWORD /d 0 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Exposure
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Solicited Remote Assistance Is Disabled
Finding: Solicited Remote Assistance is enabled.
Checks whether users are prevented from requesting (soliciting) Remote Assistance from this computer.
This rule fails when fAllowToGetHelp is not false.
Rationale: Disabling solicited Remote Assistance removes a remote-control channel that an attacker could abuse to take over a session.
Impact: Users can no longer send Remote Assistance invitations from this computer.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Remote Assistance\Configure Solicited Remote Assistance and set it to Disabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v fAllowToGetHelp /t REG_DWORD /d 0 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Exposure
- MITRE ATT&CK tactic
- Initial Access (TA0001)
18.9.38 Remote Procedure Call
Ensure RPC Endpoint Mapper Client Authentication Is Enabled
Finding: RPC Endpoint Mapper Client Authentication is not enabled.
Checks whether RPC clients authenticate to the Endpoint Mapper service when resolving RPC endpoints.
This rule fails when enableAuthEpResolution is not true.
Rationale: Requiring authentication to the Endpoint Mapper limits anonymous querying of RPC services available on the host.
Impact: RPC clients that cannot authenticate to the Endpoint Mapper may fail to resolve endpoints.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Remote Procedure Call\Enable RPC Endpoint Mapper Client Authentication and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Rpc" /v EnableAuthEpResolution /t REG_DWORD /d 1 /f
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Unauthenticated RPC Clients Are Restricted
Finding: Unauthenticated RPC clients are not restricted.
Checks whether the RPC runtime rejects unauthenticated remote RPC client connections.
This rule fails when restrictRemoteClients is not AUTHENTICATED.
Rationale: Restricting unauthenticated clients blocks anonymous access to RPC-exposed services, reducing the remote attack surface.
Impact: Remote RPC calls must be authenticated (except certain named-pipe calls), which may affect legacy applications that rely on anonymous RPC.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Remote Procedure Call\Restrict Unauthenticated RPC clients and set it to Enabled: Authenticated.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Rpc" /v RestrictRemoteClients /t REG_DWORD /d 1 /f
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
18.9.49 Troubleshooting and Diagnostics
Ensure MSDT Interactive Communication With Support Provider Is Disabled
Finding: MSDT interactive communication with the support provider is enabled.
Checks whether the Microsoft Support Diagnostic Tool is prevented from communicating interactively with a remote support provider.
This rule fails when disableQueryRemoteServer is not false.
Rationale: Disabling MSDT interactive communication stops potentially sensitive diagnostic data from being collected and sent to a third-party support provider.
Impact: MSDT cannot run in support mode, so no diagnostic data is collected or sent to a support provider.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Troubleshooting and Diagnostics\Microsoft Support Diagnostic Tool\Microsoft Support Diagnostic Tool: Turn on MSDT interactive communication with support provider and set it to Disabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\ScriptedDiagnosticsProvider\Policy" /v DisableQueryRemoteServer /t REG_DWORD /d 0 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
Ensure PerfTrack Is Disabled
Finding: PerfTrack is enabled.
Checks whether the Windows Performance PerfTrack diagnostic scenario, which collects performance data, is disabled.
This rule fails when scenarioExecutionEnabled is not false.
Rationale: Disabling PerfTrack stops the collection and reporting of performance telemetry from the host.
Impact: Windows no longer collects PerfTrack performance data.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Troubleshooting and Diagnostics\Windows Performance PerfTrack\Enable/Disable PerfTrack and set it to Disabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WDI\{9c5a40da-b965-4fc3-8781-88dd50a6299d}" /v ScenarioExecutionEnabled /t REG_DWORD /d 0 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
18.9.51 User Profiles
Ensure The Advertising ID Is Turned Off
Finding: The advertising ID is not turned off.
Checks whether the per-user advertising ID, which apps use to build cross-app usage profiles, is turned off.
This rule fails when disabledByGroupPolicy is not true.
Rationale: Disabling the advertising ID limits the tracking of user behavior across applications for targeted advertising.
Impact: Apps can no longer use the advertising ID to deliver personalized advertising.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\User Profiles\Turn off the advertising ID and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\AdvertisingInfo" /v DisabledByGroupPolicy /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
18.9.53 Windows Time Service
Ensure The Windows NTP Client Is Enabled
Finding: The Windows NTP client is disabled.
Checks whether the Windows NTP client is enabled so the host synchronizes its clock with a time source.
This rule fails when ntpClientEnabled is not true.
Rationale: Accurate time is essential for Kerberos authentication, certificate validation, and reliable security log correlation across systems.
Impact: The host synchronizes its clock using the configured NTP time source.
Remediation
Open Computer Configuration\Policies\Administrative Templates\System\Windows Time Service\Time Providers\Enable Windows NTP Client and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\W32Time\TimeProviders\NtpClient" /v Enabled /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 8.4 Standardize Time Synchronization
- NIST SP 800-53 Rev. 5: AU-8 Time Stamps; AU-12 Audit Record Generation
- NIST SP 800-171 Rev. 2: 3.3.7 Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records
- CMMC 2.0 Level 2: AU.L2-3.3.7 Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records
- PCI DSS v4.0.1: 10.6.1 Deploy time-sync technology to align all system clocks; 10.6.2 Use designated central time servers for correct, consistent time; 10.6.3 Restrict who can reach time data and log time setting changes
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)