CIS Microsoft Windows 11 Stand-alone Benchmark · Section 18.9

Windows 11 System: 57 Checks

Wartiva runs 57 checks for section 18.9, System, of the CIS Microsoft Windows 11 Stand-alone Benchmark. Each one lists what it finds, why it matters, and how to fix it.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →

All 57 checks on this page

Ensure The Sudo Command Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9

Finding: The sudo command is enabled.

Checks whether the sudo.exe command line elevation tool is disabled.

This rule fails when sudoEnabled is not DISABLED.

Rationale: Disabling sudo removes a command line elevation path that could be abused for local privilege escalation.

Impact: Users cannot use the sudo command to run elevated commands from the command line.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Configure the behavior of the sudo command and set it to Enabled: Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Sudo" /v Enabled /t REG_DWORD /d 0 /f
Risk
Vulnerability
MITRE ATT&CK tactic
Privilege Escalation (TA0004)

18.9.3 Audit Process Creation

Ensure Command Line Is Included In Process Creation Events

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.3

Finding: Command line information is not included in process creation events.

Checks whether the command line used to start each new process is recorded in the process-creation (4688) audit events.

This rule fails when processCreationIncludeCmdLineEnabled is not true.

Rationale: Capturing the full command line lets investigators see exactly what was executed, which is essential for detecting and reconstructing malicious activity.

Impact: Command-line arguments, which may occasionally contain sensitive data such as passwords, are written to the security event log for every new process.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Audit Process Creation\Include command line in process creation events and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Audit" /v ProcessCreationIncludeCmdLine_Enabled /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 8.8 Collect Command-Line Audit Logs
  • NIST SP 800-53 Rev. 5: AC-6 Least Privilege; AU-2 Event Logging
Risk
Vulnerability
MITRE ATT&CK tactic
Execution (TA0002)

18.9.4 Credentials Delegation

Ensure Encryption Oracle Remediation Forces Updated Clients

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.4

Finding: Encryption Oracle Remediation does not force updated clients.

Checks the CredSSP encryption oracle remediation level that governs whether unpatched clients or servers may establish CredSSP (e.g. RDP) sessions.

This rule fails when allowEncryptionOracle is not FORCE.

Rationale: Forcing updated clients blocks connections to or from hosts missing the CVE-2018-0886 CredSSP fix, closing an encryption-oracle remote code execution vector.

Impact: CredSSP clients and services cannot fall back to the vulnerable protocol version, so all remote hosts must be patched through at least May 2018.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Credentials Delegation\Encryption Oracle Remediation and set it to Enabled: Force Updated Clients.

From the command line:

reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\CredSSP\Parameters" /v AllowEncryptionOracle /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 10.5 Enable Anti-Exploitation Features
  • NIST SP 800-53 Rev. 5: SI-16 Memory Protection
Risk
Vulnerability
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Remote Host Delegation Of Non-Exportable Credentials Is Enabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.4

Finding: Remote host delegation of non-exportable credentials is not enabled.

Checks whether Restricted Admin and Remote Credential Guard sessions may delegate only non-exportable credentials to the remote host.

This rule fails when allowProtectedCreds is not true.

Rationale: Delegating non-exportable credentials keeps reusable secrets off the remote host, reducing credential theft during Remote Desktop sessions.

Impact: Remote Desktop connections can use Restricted Admin or Remote Credential Guard mode.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Credentials Delegation\Remote host allows delegation of non-exportable credentials and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\CredentialsDelegation" /v AllowProtectedCreds /t REG_DWORD /d 1 /f
Risk
Insecure Use of Secrets
MITRE ATT&CK tactic
Credential Access (TA0006)

18.9.5 Device Guard

Ensure Credential Guard Is Enabled With UEFI Lock

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.5

Finding: Credential Guard is not enabled with UEFI lock.

Checks whether Windows Defender Credential Guard is enabled and locked into UEFI firmware.

This rule fails when lsaCfgFlags is not ENABLED_WITH_UEFI_LOCK.

Rationale: Credential Guard isolates LSA secrets inside VBS so credential-theft tools cannot read them; the UEFI lock stops an attacker from disabling it remotely.

Impact: Domain credentials are protected by VBS isolation, and Credential Guard cannot be turned off without physical access to clear the UEFI variable.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Device Guard\Turn On Virtualization Based Security: Credential Guard Configuration and set it to Enabled with UEFI lock.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard" /v LsaCfgFlags /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 10.5 Enable Anti-Exploitation Features
  • NIST SP 800-53 Rev. 5: SI-16 Memory Protection
Risk
Insecure Use of Secrets
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure Kernel Mode Hardware Enforced Stack Protection Is In Enforcement Mode

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.5

Finding: Kernel-mode Hardware-enforced Stack Protection is not in enforcement mode.

Checks whether the hardware-enforced kernel shadow stack is active and enforcing, blocking operations that violate call-stack integrity.

This rule fails when configureKernelShadowStacksLaunch is not ENABLED_ENFORCEMENT.

Rationale: Enforcement mode stops return-oriented programming (ROP) attacks against the kernel by rejecting corrupted return addresses rather than only logging them.

Impact: Requires compatible CPUs; incompatible kernel drivers may need updates before enforcement works cleanly.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Device Guard\Turn On Virtualization Based Security: Kernel-mode Hardware-enforced Stack Protection and set it to Enabled: Enabled in enforcement mode.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard" /v ConfigureKernelShadowStacksLaunch /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 10.5 Enable Anti-Exploitation Features
  • NIST SP 800-53 Rev. 5: SI-16 Memory Protection
Risk
Vulnerability
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure Secure Launch Is Enabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.5

Finding: System Guard Secure Launch is not enabled.

Checks whether System Guard Secure Launch (Dynamic Root of Trust for Measurement) is enabled to establish a hardware-rooted, measured boot.

This rule fails when configureSystemGuardLaunch is not ENABLED.

Rationale: Secure Launch re-establishes trust in the boot environment using the CPU, protecting against firmware-level and early-boot tampering.

Impact: On supported hardware the system performs a measured Secure Launch during boot.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Device Guard\Turn On Virtualization Based Security: Secure Launch Configuration and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard" /v ConfigureSystemGuardLaunch /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 10.5 Enable Anti-Exploitation Features
  • NIST SP 800-53 Rev. 5: SI-16 Memory Protection
Risk
Vulnerability
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure Virtualization Based Protection Of Code Integrity Uses UEFI Lock

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.5

Finding: Virtualization Based Protection of Code Integrity is not enabled with UEFI lock.

Checks whether Hypervisor-Protected Code Integrity (HVCI) is enabled and locked into UEFI firmware so it cannot be turned off remotely.

This rule fails when hypervisorEnforcedCodeIntegrity is not ENABLED_WITH_UEFI_LOCK.

Rationale: HVCI uses VBS to verify kernel-mode code integrity; the UEFI lock prevents an attacker from silently disabling it via policy.

Impact: Unsigned or improperly signed kernel drivers are blocked, and HVCI cannot be disabled without physical access to clear the UEFI variable.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Device Guard\Turn On Virtualization Based Security: Virtualization Based Protection of Code Integrity and set it to Enabled with UEFI lock.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard" /v HypervisorEnforcedCodeIntegrity /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 10.5 Enable Anti-Exploitation Features
  • NIST SP 800-53 Rev. 5: SI-16 Memory Protection
Risk
Vulnerability
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure Virtualization Based Security Is Enabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.5

Finding: Virtualization Based Security is not enabled.

Checks whether Virtualization Based Security (VBS), which uses the hypervisor to isolate critical OS components, is turned on.

This rule fails when enableVirtualizationBasedSecurity is not true.

Rationale: VBS is the foundation for Credential Guard, HVCI, and other protections that isolate secrets and kernel code from a compromised OS.

Impact: VBS is enabled on hardware that supports it; compatible virtualization and Secure Boot are required.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Device Guard\Turn On Virtualization Based Security and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard" /v EnableVirtualizationBasedSecurity /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 10.5 Enable Anti-Exploitation Features
  • NIST SP 800-53 Rev. 5: SI-16 Memory Protection
Risk
Vulnerability
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure Virtualization Based Security Platform Level Is Secure Boot Or Higher

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.5

Finding: Virtualization Based Security platform security level is below Secure Boot.

Checks that the VBS platform security level requires at least Secure Boot (optionally Secure Boot with DMA protection).

This rule fails when requirePlatformSecurityFeatures is neither SECURE_BOOT nor SECURE_BOOT_AND_DMA_PROTECTION.

Rationale: Requiring Secure Boot ensures VBS is anchored to a verified boot chain; adding DMA protection further blocks memory attacks from malicious peripherals.

Impact: VBS requires Secure Boot, and optionally hardware DMA protection, to be present.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Device Guard\Turn On Virtualization Based Security: Select Platform Security Level and set it to Enabled: Secure Boot or higher.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard" /v RequirePlatformSecurityFeatures /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 10.5 Enable Anti-Exploitation Features
  • NIST SP 800-53 Rev. 5: SI-16 Memory Protection
Risk
Vulnerability
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure Virtualization Based Security Requires UEFI Memory Attributes Table

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.5

Finding: Virtualization Based Security does not require the UEFI Memory Attributes Table.

Checks whether VBS requires firmware to provide a UEFI Memory Attributes Table (MAT).

This rule fails when hvcimatRequired is not true.

Rationale: Requiring the MAT ensures firmware memory is described correctly to the hypervisor, strengthening the memory-integrity guarantees VBS relies on.

Impact: VBS is only enabled on firmware that supplies a UEFI Memory Attributes Table.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Device Guard\Turn On Virtualization Based Security: Require UEFI Memory Attributes Table and set it to True (checked).

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard" /v HVCIMATRequired /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 10.5 Enable Anti-Exploitation Features
  • NIST SP 800-53 Rev. 5: SI-16 Memory Protection
Risk
Vulnerability
MITRE ATT&CK tactic
Defense Evasion (TA0005)

18.9.7 Device Installation

Ensure Automatic Download Of Device Metadata From The Internet Is Prevented

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.7

Finding: Automatic download of device metadata from the internet is not prevented.

Checks whether Windows is blocked from retrieving device metadata for installed devices from the internet.

This rule fails when preventDeviceMetadataFromNetwork is not true.

Rationale: Preventing automatic metadata downloads avoids unnecessary outbound connections and reduces data shared with external services.

Impact: Device metadata is not fetched from the internet; devices still function with locally available metadata.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Device Installation\Prevent automatic download of applications associated with device metadata and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceMetadata" /v PreventDeviceMetadataFromNetwork /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 2.5 Allowlist Authorized Software; 10.5 Enable Anti-Exploitation Features
  • NIST SP 800-53 Rev. 5: CM-7 Least Functionality; CM-10 Software Usage Restrictions; SI-16 Memory Protection
  • NIST SP 800-171 Rev. 2: 3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; 3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
  • CMMC 2.0 Level 2: CM.L2-3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; SC.L2-3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Device Setup Class Restrictions Apply To Already Installed Devices

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.7.1

Finding: Device setup class restrictions do not apply to already installed devices.

Checks whether the device setup class installation restrictions also apply to matching devices that were installed before the policy took effect.

This rule fails when denyDeviceClassesRetroactive is not true.

Rationale: Applying the restriction retroactively removes access to already-installed devices in the blocked classes, closing a gap an attacker could otherwise use.

Impact: Matching devices already present on the system are also blocked, not just newly connected ones.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Device Installation\Device Installation Restrictions\Prevent installation of devices using drivers that match these device setup classes: Also apply to matching devices that are already installed. and set it to True (checked).

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceInstall\Restrictions" /v DenyDeviceClassesRetroactive /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 10.5 Enable Anti-Exploitation Features
  • NIST SP 800-53 Rev. 5: SI-16 Memory Protection
Risk
Vulnerability
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure IEEE 1394 Device Setup Classes Are In The Prevented Device List

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.7.1

Finding: IEEE 1394 device setup classes are missing from the prevented device list.

Checks that the four IEEE 1394 (FireWire) device setup class GUIDs are present in the list of device classes Windows is prevented from installing.

This rule fails when any of the four IEEE 1394 device setup class GUIDs is absent from denyDeviceClassesList.

Rationale: IEEE 1394 controllers can perform Direct Memory Access; blocking their drivers helps protect a BitLocker-protected host from DMA attacks that could recover encryption keys from memory.

Impact: IEEE 1394 (FireWire) drives and devices can no longer be installed on the host.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Device Installation\Device Installation Restrictions\Prevent installation of devices using drivers that match these device setup classes and set it to Enabled, then add the four IEEE 1394 device setup class GUIDs.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceInstall\Restrictions\DenyDeviceClasses" /v 1 /t REG_SZ /d "{d48179be-ec20-11d1-b6b8-00c04fa372a7}" /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceInstall\Restrictions\DenyDeviceClasses" /v 2 /t REG_SZ /d "{7ebefbc0-3200-11d2-b4c2-00a0C9697d07}" /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceInstall\Restrictions\DenyDeviceClasses" /v 3 /t REG_SZ /d "{c06ff265-ae09-48f0-812c-16753d7cba83}" /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceInstall\Restrictions\DenyDeviceClasses" /v 4 /t REG_SZ /d "{6bdd1fc1-810f-11d0-bec7-08002be2092f}" /f
Risk
Vulnerability
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Installation Of Devices Matching Configured Setup Classes Is Prevented

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.7.1

Finding: Installation of devices matching the configured setup classes is not prevented.

Checks whether Windows is prevented from installing drivers for the device setup classes listed in the deny list.

This rule fails when denyDeviceClasses is not true.

Rationale: Blocking driver installation for specified device classes reduces the attack surface from untrusted or DMA-capable hardware such as IEEE 1394 controllers.

Impact: Windows will not install or update drivers for devices whose setup class GUID is in the deny list.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Device Installation\Device Installation Restrictions\Prevent installation of devices using drivers that match these device setup classes and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceInstall\Restrictions" /v DenyDeviceClasses /t REG_DWORD /d 1 /f
Risk
Vulnerability
MITRE ATT&CK tactic
Initial Access (TA0001)

18.9.13 Early Launch Antimalware

Ensure Boot Start Driver Initialization Allows Good Unknown And Critical Bad Drivers

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.13

Finding: Boot-start driver initialization policy is not set to good, unknown and bad but critical.

Checks which boot-start drivers Early Launch Antimalware permits to initialize based on their classification.

This rule fails when driverLoadPolicy is not GOOD_PLUS_UNKNOWN_PLUS_BAD_CRITICAL.

Rationale: Allowing good, unknown, and only boot-critical bad drivers blocks known-malicious non-critical boot drivers while keeping the system bootable.

Impact: Non-critical drivers classified as bad by ELAM are prevented from loading at boot.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Early Launch Antimalware\Boot-Start Driver Initialization Policy and set it to Enabled: Good, unknown and bad but critical.

From the command line:

reg add "HKLM\SYSTEM\CurrentControlSet\Policies\EarlyLaunch" /v DriverLoadPolicy /t REG_DWORD /d 3 /f
Framework mappings
  • CIS Controls v8: 10.5 Enable Anti-Exploitation Features
  • NIST SP 800-53 Rev. 5: SI-16 Memory Protection
Risk
Vulnerability
MITRE ATT&CK tactic
Persistence (TA0003)

18.9.17 Filesystem (formerly NTFS Filesystem)

Ensure CLFS Logfile Authentication Is Enabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.17

Finding: CLFS logfile authentication is not enabled.

Checks whether the Common Log File System validates the authenticity of log files before processing them.

This rule fails when clfsAuthenticationChecking is not true.

Rationale: Authenticating CLFS logfiles blocks a class of parsing vulnerabilities in the CLFS driver that attackers have used for local privilege escalation.

Impact: CLFS rejects log files that fail authentication checks.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Filesystem\Enable / disable CLFS logfile authentication and set it to Enabled.

From the command line:

reg add "HKLM\SYSTEM\CurrentControlSet\Policies" /v ClfsAuthenticationChecking /t REG_DWORD /d 1 /f
Risk
Vulnerability
MITRE ATT&CK tactic
Privilege Escalation (TA0004)

18.9.19 Group Policy

Ensure Continue Experiences On This Device Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.19

Finding: Continue experiences on this device is enabled.

Checks whether the Connected Devices Platform, which lets Windows share activities across a user's devices, is turned off.

This rule fails when enableCdp is not false.

Rationale: Disabling cross-device continuation limits the sharing of user activity data between devices and cloud services.

Impact: Users can no longer resume activities from this device on another device.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Group Policy\Continue experiences on this device and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v EnableCdp /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

18.9.20 Internet Communication Management

Ensure Access To The Store For Unknown File Types Is Turned Off

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.20.1

Finding: Access to the Store for unknown file types is not turned off.

Checks whether the 'Look for an app in the Store' option is disabled when a user opens a file with an unknown extension.

This rule fails when noUseStoreOpenWith is not true.

Rationale: Preventing Store lookups for unknown file types stops users from being steered to install arbitrary apps to open unrecognized files.

Impact: Users are not offered the Microsoft Store when opening files with unknown extensions.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off access to the Store and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Explorer" /v NoUseStoreOpenWith /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 2.5 Allowlist Authorized Software
  • NIST SP 800-53 Rev. 5: CM-7 Least Functionality; CM-10 Software Usage Restrictions
  • NIST SP 800-171 Rev. 2: 3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; 3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
  • CMMC 2.0 Level 2: CM.L2-3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; SC.L2-3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality
Risk
External Attack Surface
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Downloading Of Print Drivers Over HTTP Is Turned Off

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.20.1

Finding: Downloading of print drivers over HTTP is not turned off.

Checks whether Windows is blocked from downloading print drivers over HTTP.

This rule fails when disableWebPnPDownload is not true.

Rationale: Blocking HTTP print-driver downloads prevents fetching and installing driver code from untrusted internet sources.

Impact: Print drivers must be obtained from local or managed sources rather than over HTTP.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off downloading of print drivers over HTTP and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers" /v DisableWebPnPDownload /t REG_DWORD /d 1 /f
Risk
External Attack Surface
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Handwriting Personalization Data Sharing Is Turned Off

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.20.1

Finding: Handwriting personalization data sharing is not turned off.

Checks whether the automatic sharing of handwriting recognition personalization data with Microsoft is turned off.

This rule fails when preventHandwritingDataSharing is not true.

Rationale: Stopping this upload keeps potentially sensitive handwriting samples from leaving the host.

Impact: Handwriting personalization data is no longer collected and sent to Microsoft.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off handwriting personalization data sharing and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\TabletPC" /v PreventHandwritingDataSharing /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Handwriting Recognition Error Reporting Is Turned Off

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.20.1

Finding: Handwriting recognition error reporting is not turned off.

Checks whether handwriting recognition error reports are prevented from being sent to Microsoft.

This rule fails when preventHandwritingErrorReports is not true.

Rationale: Suppressing these reports avoids transmitting recognized text and ink samples that may contain sensitive information.

Impact: Handwriting recognition error reports are not generated or uploaded.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off handwriting recognition error reporting and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\HandwritingErrorReports" /v PreventHandwritingErrorReports /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Internet Connection Wizard Cannot Connect To Microsoft.com

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.20.1

Finding: Internet Connection Wizard can connect to Microsoft.com.

Checks whether the Internet Connection Wizard is blocked from contacting Microsoft.com to download a list of ISPs.

This rule fails when exitOnMSICW is not true.

Rationale: Blocking this connection reduces unnecessary outbound traffic to external Microsoft services during connection setup.

Impact: The Internet Connection Wizard no longer downloads referral content from Microsoft.com.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off Internet Connection Wizard if URL connection is referring to Microsoft.com and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Internet Connection Wizard" /v ExitOnMSICW /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Internet Download For Web Publishing And Ordering Wizards Is Turned Off

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.20.1

Finding: Internet download for web publishing and online ordering wizards is not turned off.

Checks whether Windows is prevented from downloading a provider list for web publishing and online ordering wizards.

This rule fails when noWebServices is not true.

Rationale: Preventing these downloads limits outbound connections to third-party web-service providers.

Impact: Users cannot use the internet-based provider lists in the publishing and ordering wizards.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off Internet download for Web publishing and online ordering wizards and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoWebServices /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Printing Over HTTP Is Turned Off

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.20.1

Finding: Printing over HTTP is not turned off.

Checks whether the client's ability to print to printers over HTTP is turned off.

This rule fails when disableHTTPPrinting is not true.

Rationale: Disabling HTTP printing stops the host from sending print jobs to internet-hosted printers over an unencrypted channel.

Impact: The client can no longer print to HTTP-based printers on the internet.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off printing over HTTP and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers" /v DisableHTTPPrinting /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Registration Referring To Microsoft.com Is Turned Off

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.20.1

Finding: Registration referring to Microsoft.com is not turned off.

Checks whether the Windows Registration Wizard is blocked from connecting to Microsoft.com.

This rule fails when noRegistration is not true.

Rationale: Blocking online registration avoids sending user and system details to external Microsoft registration services.

Impact: Users cannot register the product online through the wizard.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off Registration if URL connection is referring to Microsoft.com and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Registration Wizard Control" /v NoRegistration /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Search Companion Content File Updates Are Turned Off

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.20.1

Finding: Search Companion content file updates are not turned off.

Checks whether the Search Companion is prevented from automatically downloading content file updates.

This rule fails when disableContentFileUpdates is not true.

Rationale: Preventing automatic content downloads reduces unsolicited outbound connections to Microsoft services.

Impact: Search Companion does not download updated content files over the internet.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off Search Companion content file updates and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\SearchCompanion" /v DisableContentFileUpdates /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure The Order Prints Picture Task Is Turned Off

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.20.1

Finding: The Order Prints picture task is not turned off.

Checks whether the 'Order Prints Online' task, which uploads pictures to online print providers, is removed.

This rule fails when noOnlinePrintsWizard is not true.

Rationale: Removing the online prints task prevents users from uploading local images to third-party internet services.

Impact: The 'Order Prints Online' option no longer appears in picture folders and tasks.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off the "Order Prints" picture task and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoOnlinePrintsWizard /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure The Publish To Web Task For Files And Folders Is Turned Off

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.20.1

Finding: The Publish to Web task for files and folders is not turned off.

Checks whether the 'Publish to Web' task for files and folders is removed from File Explorer.

This rule fails when noPublishingWizard is not true.

Rationale: Removing this task prevents users from uploading local files and folders to internet hosting services.

Impact: The 'Publish to Web' option is no longer available for files and folders.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off the "Publish to Web" task for files and folders and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoPublishingWizard /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure The Windows Customer Experience Improvement Program Is Turned Off

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.20.1

Finding: The Windows Customer Experience Improvement Program is not turned off.

Checks whether Windows is prevented from participating in the Customer Experience Improvement Program.

This rule fails when ceipEnable is not false.

Rationale: Opting out stops Windows usage and configuration data from being collected and sent to Microsoft.

Impact: Windows no longer collects or transmits Customer Experience Improvement data.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off Windows Customer Experience Improvement Program and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\SQMClient\Windows" /v CEIPEnable /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure The Windows Messenger Customer Experience Improvement Program Is Turned Off

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.20.1

Finding: The Windows Messenger Customer Experience Improvement Program is not turned off.

Checks whether Windows Messenger is prevented from participating in the Customer Experience Improvement Program.

This rule fails when ceip is not false.

Rationale: Opting out stops usage data from being collected and sent to Microsoft by Windows Messenger.

Impact: Windows Messenger no longer collects or transmits Customer Experience Improvement data.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off the Windows Messenger Customer Experience Improvement Program and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Messenger\Client" /v CEIP /t REG_DWORD /d 2 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Windows Error Reporting Is Turned Off

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.20.1

Finding: Windows Error Reporting is not turned off.

Checks whether Windows Error Reporting is disabled so crash and error reports are not sent to Microsoft.

This rule fails when windowsErrorReportingDisabled is not true.

Rationale: Error reports can contain memory snapshots and other sensitive data; disabling reporting keeps that information on the host.

Impact: Application and system error data is no longer transmitted to Microsoft.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off Windows Error Reporting and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Windows Error Reporting" /v Disabled /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

18.9.23 Kerberos

Ensure Device Authentication Using Certificate Is Set To Automatic

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.23

Finding: Device authentication using certificate is not set to automatic.

Checks whether the device attempts Kerberos PKINIT certificate authentication, falling back to password authentication when a supporting domain controller is unavailable.

This rule fails when devicePKInitEnabled is not true or devicePKInitBehavior is not AUTOMATIC.

Rationale: Certificate-based device authentication is stronger than username and password; the automatic mode uses it whenever possible without breaking connectivity.

Impact: None; this matches the default behavior when the supporting infrastructure is present.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Kerberos\Support device authentication using certificate and set it to Enabled: Automatic.

From the command line:

reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\kerberos\parameters" /v DevicePKInitEnabled /t REG_DWORD /d 1 /f
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\kerberos\parameters" /v DevicePKInitBehavior /t REG_DWORD /d 0 /f
Risk
Unprotected Principal
MITRE ATT&CK tactic
Credential Access (TA0006)

18.9.24 Kernel DMA Protection

Ensure External Devices Incompatible With Kernel DMA Protection Are Blocked

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.24

Finding: External devices incompatible with Kernel DMA Protection are not blocked.

Checks the enumeration policy for external DMA-capable devices that are not compatible with Kernel DMA Protection.

This rule fails when deviceEnumerationPolicy is not BLOCK_ALL.

Rationale: Blocking incompatible external DMA devices prevents malicious peripherals from reading system memory, which could expose credentials or encryption keys.

Impact: External Thunderbolt/PCIe devices lacking DMA-remapping support are not enumerated, even while a user is signed in.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Kernel DMA Protection\Enumeration policy for external devices incompatible with Kernel DMA Protection and set it to Enabled: Block All.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Kernel DMA Protection" /v DeviceEnumerationPolicy /t REG_DWORD /d 0 /f
Risk
Unprotected Data
MITRE ATT&CK tactic
Credential Access (TA0006)

18.9.27 Local Security Authority

Ensure Custom SSPs And APs Cannot Be Loaded Into LSASS

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.27

Finding: Custom SSPs and APs can be loaded into LSASS.

Checks whether custom Security Support Providers and Authentication Packages are blocked from being loaded into the LSASS process.

This rule fails when allowCustomSSPsAPs is not false.

Rationale: Blocking custom SSPs/APs prevents attackers from injecting credential-harvesting modules into LSASS.

Impact: Third-party authentication modules that rely on loading into LSASS will not load.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Local Security Authority\Allow Custom SSPs and APs to be loaded into LSASS and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v AllowCustomSSPsAPs /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 10.5 Enable Anti-Exploitation Features
  • NIST SP 800-53 Rev. 5: SI-16 Memory Protection
Risk
Insecure Use of Secrets
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure LSASS Runs As A Protected Process With UEFI Lock

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.27

Finding: LSASS does not run as a protected process with UEFI lock.

Checks whether LSASS runs as a Protected Process Light with the configuration locked into UEFI firmware.

This rule fails when runAsPPL is not ENABLED_WITH_UEFI_LOCK.

Rationale: Running LSASS as a protected process blocks non-protected code (such as Mimikatz) from reading its memory; the UEFI lock prevents remote disabling.

Impact: Unsigned or non-protected plug-ins cannot load into LSASS, and the protection cannot be removed without physical access to clear the UEFI variable.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Local Security Authority\Configures LSASS to run as a protected process and set it to Enabled: Enabled with UEFI Lock.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v RunAsPPL /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 10.5 Enable Anti-Exploitation Features
  • NIST SP 800-53 Rev. 5: SI-16 Memory Protection
Risk
Insecure Use of Secrets
MITRE ATT&CK tactic
Credential Access (TA0006)

18.9.28 Locale Services

Ensure Copying Of User Input Methods To The System Account For Sign In Is Disallowed

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.28

Finding: Copying of user input methods to the system account for sign-in is allowed.

Checks whether user-configured input methods are prevented from being copied to the system account used at the sign-in screen.

This rule fails when blockUserInputMethodsForSignIn is not true.

Rationale: Blocking this copy keeps user-specific input method configurations from influencing the system account context at sign-in.

Impact: The system account uses only the system default input methods at the sign-in screen.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Locale Services\Disallow copying of user input methods to the system account for sign-in and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\ControlPanel\International" /v BlockUserInputMethodsForSignIn /t REG_DWORD /d 1 /f
Risk
Vulnerability
MITRE ATT&CK tactic
Execution (TA0002)

18.9.29 Logon

Ensure App Notifications On The Lock Screen Are Turned Off

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.29

Finding: App notifications on the lock screen are not turned off.

Checks whether application notifications are prevented from appearing on the lock screen.

This rule fails when disableLockScreenAppNotifications is not true.

Rationale: Suppressing lock-screen notifications keeps potentially sensitive content from being shown on an unattended device.

Impact: Apps can no longer display notifications on the lock screen.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Logon\Turn off app notifications on the lock screen and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v DisableLockScreenAppNotifications /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Convenience PIN Sign In Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.29

Finding: Convenience PIN sign-in is enabled.

Checks whether domain users are prevented from signing in with a convenience PIN.

This rule fails when allowDomainPINLogon is not false.

Rationale: A convenience PIN is drawn from a small character set and is generally weaker than a password, so disabling it preserves stronger authentication.

Impact: Domain users must sign in with their password rather than a convenience PIN.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Logon\Turn on convenience PIN sign-in and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v AllowDomainPINLogon /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Principal
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure The Network Selection UI Is Not Displayed

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.29

Finding: The network selection UI is displayed on the logon screen.

Checks whether the network selection UI is hidden from users on the lock/logon screen.

This rule fails when dontDisplayNetworkSelectionUI is not true.

Rationale: Hiding network selection prevents an unauthenticated person from changing network connectivity from the lock screen.

Impact: Users cannot change the device's network connection from the sign-in screen.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Logon\Do not display network selection UI and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v DontDisplayNetworkSelectionUI /t REG_DWORD /d 1 /f
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Users Are Blocked From Showing Account Details On Sign In

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.29

Finding: Users are not blocked from showing account details on sign-in.

Checks whether users are prevented from displaying account details, such as email address, on the sign-in screen.

This rule fails when blockUserFromShowingAccountDetailsOnSignin is not true.

Rationale: Hiding account details reduces the information an onlooker can gather from an unattended lock screen.

Impact: Account details are not shown on the sign-in screen.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Logon\Block user from showing account details on sign-in and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v BlockUserFromShowingAccountDetailsOnSignin /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process
  • NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
  • NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
  • CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
  • PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components
Risk
Unprotected Data
MITRE ATT&CK tactic
Discovery (TA0007)

18.9.33 OS Policies

Ensure Clipboard Synchronization Across Devices Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.33

Finding: Clipboard synchronization across devices is enabled.

Checks whether clipboard contents are prevented from being synchronized across a user's devices through the cloud.

This rule fails when allowCrossDeviceClipboard is not false.

Rationale: Disabling cross-device clipboard keeps potentially sensitive copied data from being uploaded to and shared through cloud services.

Impact: Clipboard contents are not shared between this device and the user's other devices.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\OS Policies\Allow Clipboard synchronization across devices and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v AllowCrossDeviceClipboard /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Upload Of User Activities Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.33

Finding: Upload of User Activities is enabled.

Checks whether the Activity Feed is prevented from uploading published user activities to the cloud.

This rule fails when uploadUserActivities is not false.

Rationale: Blocking activity uploads limits the user-behavior data shared with Microsoft cloud services.

Impact: User activities are not uploaded, so cross-device timeline continuation is unavailable.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\OS Policies\Allow upload of User Activities and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v UploadUserActivities /t REG_DWORD /d 0 /f
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

18.9.35 Power Management

Ensure A Password Is Required When Waking On Battery

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.35.6

Finding: A password is not required when the computer wakes on battery.

Checks whether the user is prompted for a password when the device wakes from sleep on battery.

This rule fails when requirePasswordOnWakeOnBattery is not true.

Rationale: Requiring a password on wake prevents someone with physical access from using an unattended device without authenticating.

Impact: Users must re-enter their password when the device wakes from sleep on battery.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Power Management\Sleep Settings\Require a password when a computer wakes (on battery) and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Power\PowerSettings\0e796bdb-100d-47d6-a2d5-f7d2daa51f51" /v DCSettingIndex /t REG_DWORD /d 1 /f
Risk
Unprotected Principal
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure A Password Is Required When Waking Plugged In

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.35.6

Finding: A password is not required when the computer wakes while plugged in.

Checks whether the user is prompted for a password when the device wakes from sleep while plugged in.

This rule fails when requirePasswordOnWakeWhenPluggedIn is not true.

Rationale: Requiring a password on wake prevents someone with physical access from using an unattended device without authenticating.

Impact: Users must re-enter their password when the device wakes from sleep while plugged in.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Power Management\Sleep Settings\Require a password when a computer wakes (plugged in) and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Power\PowerSettings\0e796bdb-100d-47d6-a2d5-f7d2daa51f51" /v ACSettingIndex /t REG_DWORD /d 1 /f
Risk
Unprotected Principal
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Network Connectivity During Connected Standby On Battery Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.35.6

Finding: Network connectivity during connected-standby on battery is allowed.

Checks whether network connectivity is prevented while the device is in connected standby running on battery.

This rule fails when allowNetworkConDuringStandbyOnBattery is not false.

Rationale: Disabling standby network connectivity reduces the window in which a sleeping, unattended device is reachable over the network.

Impact: The device does not maintain network connectivity during connected standby on battery.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Power Management\Sleep Settings\Allow network connectivity during connected-standby (on battery) and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Power\PowerSettings\f15576e8-98b7-4186-b944-eafa664402d9" /v DCSettingIndex /t REG_DWORD /d 0 /f
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Network Connectivity During Connected Standby Plugged In Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.35.6

Finding: Network connectivity during connected-standby plugged in is allowed.

Checks whether network connectivity is prevented while the device is in connected standby while plugged in.

This rule fails when allowNetworkConDuringStandbyPluggedIn is not false.

Rationale: Disabling standby network connectivity reduces the window in which a sleeping, unattended device is reachable over the network.

Impact: The device does not maintain network connectivity during connected standby when plugged in.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Power Management\Sleep Settings\Allow network connectivity during connected-standby (plugged in) and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Power\PowerSettings\f15576e8-98b7-4186-b944-eafa664402d9" /v ACSettingIndex /t REG_DWORD /d 0 /f
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Standby States When Sleeping On Battery Are Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.35.6

Finding: Standby states (S1-S3) when sleeping on battery are allowed.

Checks whether S1-S3 standby sleep states are prevented while the device is on battery.

This rule fails when allowStandbyStatesWhenSleeping is not false.

Rationale: Blocking standby sleep states keeps encryption keys and other secrets out of easily attacked powered memory when the device is left unattended.

Impact: On battery the device uses hibernate or shutdown instead of S1-S3 standby.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Power Management\Sleep Settings\Allow standby states (S1-S3) when sleeping (on battery) and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Power\PowerSettings\abfc2519-3608-4c2a-94ea-171b0ed546ab" /v DCSettingIndex /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process
  • NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
  • NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
  • CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
  • PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components
Risk
Unprotected Data
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure Standby States When Sleeping Plugged In Are Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.35.6

Finding: Standby states (S1-S3) when sleeping plugged in are allowed.

Checks whether S1-S3 standby sleep states are prevented while the device is plugged in.

This rule fails when allowStandbyStatesWhenPluggedIn is not false.

Rationale: Blocking standby sleep states keeps encryption keys and other secrets out of easily attacked powered memory when the device is left unattended.

Impact: When plugged in the device uses hibernate or shutdown instead of S1-S3 standby.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Power Management\Sleep Settings\Allow standby states (S1-S3) when sleeping (plugged in) and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Power\PowerSettings\abfc2519-3608-4c2a-94ea-171b0ed546ab" /v ACSettingIndex /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process
  • NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
  • NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
  • CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
  • PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components
Risk
Unprotected Data
MITRE ATT&CK tactic
Credential Access (TA0006)

18.9.37 Remote Assistance

Ensure Offer Remote Assistance Is Disabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.37

Finding: Offer Remote Assistance is enabled.

Checks whether unsolicited (offered) Remote Assistance connections to this computer are prevented.

This rule fails when fAllowUnsolicited is not false.

Rationale: Disabling offered Remote Assistance stops helpers from initiating remote control sessions without an explicit user request, closing a remote-access avenue.

Impact: Support staff cannot offer Remote Assistance; users must solicit help through other means if solicited assistance is also disabled.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Remote Assistance\Configure Offer Remote Assistance and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v fAllowUnsolicited /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Exposure
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Solicited Remote Assistance Is Disabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.37

Finding: Solicited Remote Assistance is enabled.

Checks whether users are prevented from requesting (soliciting) Remote Assistance from this computer.

This rule fails when fAllowToGetHelp is not false.

Rationale: Disabling solicited Remote Assistance removes a remote-control channel that an attacker could abuse to take over a session.

Impact: Users can no longer send Remote Assistance invitations from this computer.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Remote Assistance\Configure Solicited Remote Assistance and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v fAllowToGetHelp /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Exposure
MITRE ATT&CK tactic
Initial Access (TA0001)

18.9.38 Remote Procedure Call

Ensure RPC Endpoint Mapper Client Authentication Is Enabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.38

Finding: RPC Endpoint Mapper Client Authentication is not enabled.

Checks whether RPC clients authenticate to the Endpoint Mapper service when resolving RPC endpoints.

This rule fails when enableAuthEpResolution is not true.

Rationale: Requiring authentication to the Endpoint Mapper limits anonymous querying of RPC services available on the host.

Impact: RPC clients that cannot authenticate to the Endpoint Mapper may fail to resolve endpoints.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Remote Procedure Call\Enable RPC Endpoint Mapper Client Authentication and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Rpc" /v EnableAuthEpResolution /t REG_DWORD /d 1 /f
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Unauthenticated RPC Clients Are Restricted

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.38

Finding: Unauthenticated RPC clients are not restricted.

Checks whether the RPC runtime rejects unauthenticated remote RPC client connections.

This rule fails when restrictRemoteClients is not AUTHENTICATED.

Rationale: Restricting unauthenticated clients blocks anonymous access to RPC-exposed services, reducing the remote attack surface.

Impact: Remote RPC calls must be authenticated (except certain named-pipe calls), which may affect legacy applications that rely on anonymous RPC.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Remote Procedure Call\Restrict Unauthenticated RPC clients and set it to Enabled: Authenticated.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Rpc" /v RestrictRemoteClients /t REG_DWORD /d 1 /f
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

18.9.49 Troubleshooting and Diagnostics

Ensure MSDT Interactive Communication With Support Provider Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.49.5

Finding: MSDT interactive communication with the support provider is enabled.

Checks whether the Microsoft Support Diagnostic Tool is prevented from communicating interactively with a remote support provider.

This rule fails when disableQueryRemoteServer is not false.

Rationale: Disabling MSDT interactive communication stops potentially sensitive diagnostic data from being collected and sent to a third-party support provider.

Impact: MSDT cannot run in support mode, so no diagnostic data is collected or sent to a support provider.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Troubleshooting and Diagnostics\Microsoft Support Diagnostic Tool\Microsoft Support Diagnostic Tool: Turn on MSDT interactive communication with support provider and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\ScriptedDiagnosticsProvider\Policy" /v DisableQueryRemoteServer /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure PerfTrack Is Disabled

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.49.11

Finding: PerfTrack is enabled.

Checks whether the Windows Performance PerfTrack diagnostic scenario, which collects performance data, is disabled.

This rule fails when scenarioExecutionEnabled is not false.

Rationale: Disabling PerfTrack stops the collection and reporting of performance telemetry from the host.

Impact: Windows no longer collects PerfTrack performance data.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Troubleshooting and Diagnostics\Windows Performance PerfTrack\Enable/Disable PerfTrack and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WDI\{9c5a40da-b965-4fc3-8781-88dd50a6299d}" /v ScenarioExecutionEnabled /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

18.9.51 User Profiles

Ensure The Advertising ID Is Turned Off

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.51

Finding: The advertising ID is not turned off.

Checks whether the per-user advertising ID, which apps use to build cross-app usage profiles, is turned off.

This rule fails when disabledByGroupPolicy is not true.

Rationale: Disabling the advertising ID limits the tracking of user behavior across applications for targeted advertising.

Impact: Apps can no longer use the advertising ID to deliver personalized advertising.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\User Profiles\Turn off the advertising ID and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\AdvertisingInfo" /v DisabledByGroupPolicy /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

18.9.53 Windows Time Service

Ensure The Windows NTP Client Is Enabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.53.1

Finding: The Windows NTP client is disabled.

Checks whether the Windows NTP client is enabled so the host synchronizes its clock with a time source.

This rule fails when ntpClientEnabled is not true.

Rationale: Accurate time is essential for Kerberos authentication, certificate validation, and reliable security log correlation across systems.

Impact: The host synchronizes its clock using the configured NTP time source.

Remediation

Open Computer Configuration\Policies\Administrative Templates\System\Windows Time Service\Time Providers\Enable Windows NTP Client and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\W32Time\TimeProviders\NtpClient" /v Enabled /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 8.4 Standardize Time Synchronization
  • NIST SP 800-53 Rev. 5: AU-8 Time Stamps; AU-12 Audit Record Generation
  • NIST SP 800-171 Rev. 2: 3.3.7 Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records
  • CMMC 2.0 Level 2: AU.L2-3.3.7 Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records
  • PCI DSS v4.0.1: 10.6.1 Deploy time-sync technology to align all system clocks; 10.6.2 Use designated central time servers for correct, consistent time; 10.6.3 Restrict who can reach time data and log time setting changes
Risk
Vulnerability
MITRE ATT&CK tactic
Defense Evasion (TA0005)