---
title: CIS Windows 11 System: 57 Checks | Wartiva
description: Wartiva's 57 checks for section 18.9, System, of the CIS Microsoft Windows 11 Stand-alone Benchmark: what each one finds, why it matters, and how to fix it.
url: https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html
updated: 2026-10-07
---

CIS Microsoft Windows 11 Stand-alone Benchmark · Section 18.9

# Windows 11 System: 57 Checks

Wartiva runs 57 checks for section 18.9, System, of the CIS Microsoft Windows 11 Stand-alone Benchmark. Each one lists what it finds, why it matters, and how to fix it.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. [How Wartiva works →](https://wartiva.com/platform.html)

### [Ensure The Sudo Command Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#the-sudo-command-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9

**Finding:** The sudo command is enabled.

Checks whether the sudo.exe command line elevation tool is disabled.

This rule fails when `sudoEnabled` is not `DISABLED`.

**Rationale:** Disabling sudo removes a command line elevation path that could be abused for local privilege escalation.

**Impact:** Users cannot use the sudo command to run elevated commands from the command line.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Configure the behavior of the sudo command** and set it to **Enabled: Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Sudo" /v Enabled /t REG_DWORD /d 0 /f
```

Risk

Vulnerability

MITRE ATT&CK tactic

Privilege Escalation ([TA0004](https://attack.mitre.org/tactics/TA0004/))

## 18.9.3 Audit Process Creation

### [Ensure Command Line Is Included In Process Creation Events](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#command-line-is-included-in-process-creation-events)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.3

**Finding:** Command line information is not included in process creation events.

Checks whether the command line used to start each new process is recorded in the process-creation (4688) audit events.

This rule fails when `processCreationIncludeCmdLineEnabled` is not `true`.

**Rationale:** Capturing the full command line lets investigators see exactly what was executed, which is essential for detecting and reconstructing malicious activity.

**Impact:** Command-line arguments, which may occasionally contain sensitive data such as passwords, are written to the security event log for every new process.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Audit Process Creation\Include command line in process creation events** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Audit" /v ProcessCreationIncludeCmdLine_Enabled /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 8.8 Collect Command-Line Audit Logs
- **NIST SP 800-53 Rev. 5**: AC-6 Least Privilege; AU-2 Event Logging

Risk

Vulnerability

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

## 18.9.4 Credentials Delegation

### [Ensure Encryption Oracle Remediation Forces Updated Clients](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#encryption-oracle-remediation-forces-updated-clients)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.4

**Finding:** Encryption Oracle Remediation does not force updated clients.

Checks the CredSSP encryption oracle remediation level that governs whether unpatched clients or servers may establish CredSSP (e.g. RDP) sessions.

This rule fails when `allowEncryptionOracle` is not `FORCE`.

**Rationale:** Forcing updated clients blocks connections to or from hosts missing the CVE-2018-0886 CredSSP fix, closing an encryption-oracle remote code execution vector.

**Impact:** CredSSP clients and services cannot fall back to the vulnerable protocol version, so all remote hosts must be patched through at least May 2018.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Credentials Delegation\Encryption Oracle Remediation** and set it to **Enabled: Force Updated Clients**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\CredSSP\Parameters" /v AllowEncryptionOracle /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 10.5 Enable Anti-Exploitation Features
- **NIST SP 800-53 Rev. 5**: SI-16 Memory Protection

Risk

Vulnerability

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure Remote Host Delegation Of Non-Exportable Credentials Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#remote-host-delegation-of-non-exportable-credentials-is-enabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.4

**Finding:** Remote host delegation of non-exportable credentials is not enabled.

Checks whether Restricted Admin and Remote Credential Guard sessions may delegate only non-exportable credentials to the remote host.

This rule fails when `allowProtectedCreds` is not `true`.

**Rationale:** Delegating non-exportable credentials keeps reusable secrets off the remote host, reducing credential theft during Remote Desktop sessions.

**Impact:** Remote Desktop connections can use Restricted Admin or Remote Credential Guard mode.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Credentials Delegation\Remote host allows delegation of non-exportable credentials** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\CredentialsDelegation" /v AllowProtectedCreds /t REG_DWORD /d 1 /f
```

Risk

Insecure Use of Secrets

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

## 18.9.5 Device Guard

### [Ensure Credential Guard Is Enabled With UEFI Lock](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#credential-guard-is-enabled-with-uefi-lock)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.5

**Finding:** Credential Guard is not enabled with UEFI lock.

Checks whether Windows Defender Credential Guard is enabled and locked into UEFI firmware.

This rule fails when `lsaCfgFlags` is not `ENABLED_WITH_UEFI_LOCK`.

**Rationale:** Credential Guard isolates LSA secrets inside VBS so credential-theft tools cannot read them; the UEFI lock stops an attacker from disabling it remotely.

**Impact:** Domain credentials are protected by VBS isolation, and Credential Guard cannot be turned off without physical access to clear the UEFI variable.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Device Guard\Turn On Virtualization Based Security: Credential Guard Configuration** and set it to **Enabled with UEFI lock**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard" /v LsaCfgFlags /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 10.5 Enable Anti-Exploitation Features
- **NIST SP 800-53 Rev. 5**: SI-16 Memory Protection

Risk

Insecure Use of Secrets

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure Kernel Mode Hardware Enforced Stack Protection Is In Enforcement Mode](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#kernel-mode-hardware-enforced-stack-protection-is-in-enforcement-mode)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.5

**Finding:** Kernel-mode Hardware-enforced Stack Protection is not in enforcement mode.

Checks whether the hardware-enforced kernel shadow stack is active and enforcing, blocking operations that violate call-stack integrity.

This rule fails when `configureKernelShadowStacksLaunch` is not `ENABLED_ENFORCEMENT`.

**Rationale:** Enforcement mode stops return-oriented programming (ROP) attacks against the kernel by rejecting corrupted return addresses rather than only logging them.

**Impact:** Requires compatible CPUs; incompatible kernel drivers may need updates before enforcement works cleanly.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Device Guard\Turn On Virtualization Based Security: Kernel-mode Hardware-enforced Stack Protection** and set it to **Enabled: Enabled in enforcement mode**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard" /v ConfigureKernelShadowStacksLaunch /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 10.5 Enable Anti-Exploitation Features
- **NIST SP 800-53 Rev. 5**: SI-16 Memory Protection

Risk

Vulnerability

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

### [Ensure Secure Launch Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#secure-launch-is-enabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.5

**Finding:** System Guard Secure Launch is not enabled.

Checks whether System Guard Secure Launch (Dynamic Root of Trust for Measurement) is enabled to establish a hardware-rooted, measured boot.

This rule fails when `configureSystemGuardLaunch` is not `ENABLED`.

**Rationale:** Secure Launch re-establishes trust in the boot environment using the CPU, protecting against firmware-level and early-boot tampering.

**Impact:** On supported hardware the system performs a measured Secure Launch during boot.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Device Guard\Turn On Virtualization Based Security: Secure Launch Configuration** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard" /v ConfigureSystemGuardLaunch /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 10.5 Enable Anti-Exploitation Features
- **NIST SP 800-53 Rev. 5**: SI-16 Memory Protection

Risk

Vulnerability

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

### [Ensure Virtualization Based Protection Of Code Integrity Uses UEFI Lock](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#virtualization-based-protection-of-code-integrity-uses-uefi-lock)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.5

**Finding:** Virtualization Based Protection of Code Integrity is not enabled with UEFI lock.

Checks whether Hypervisor-Protected Code Integrity (HVCI) is enabled and locked into UEFI firmware so it cannot be turned off remotely.

This rule fails when `hypervisorEnforcedCodeIntegrity` is not `ENABLED_WITH_UEFI_LOCK`.

**Rationale:** HVCI uses VBS to verify kernel-mode code integrity; the UEFI lock prevents an attacker from silently disabling it via policy.

**Impact:** Unsigned or improperly signed kernel drivers are blocked, and HVCI cannot be disabled without physical access to clear the UEFI variable.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Device Guard\Turn On Virtualization Based Security: Virtualization Based Protection of Code Integrity** and set it to **Enabled with UEFI lock**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard" /v HypervisorEnforcedCodeIntegrity /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 10.5 Enable Anti-Exploitation Features
- **NIST SP 800-53 Rev. 5**: SI-16 Memory Protection

Risk

Vulnerability

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

### [Ensure Virtualization Based Security Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#virtualization-based-security-is-enabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.5

**Finding:** Virtualization Based Security is not enabled.

Checks whether Virtualization Based Security (VBS), which uses the hypervisor to isolate critical OS components, is turned on.

This rule fails when `enableVirtualizationBasedSecurity` is not `true`.

**Rationale:** VBS is the foundation for Credential Guard, HVCI, and other protections that isolate secrets and kernel code from a compromised OS.

**Impact:** VBS is enabled on hardware that supports it; compatible virtualization and Secure Boot are required.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Device Guard\Turn On Virtualization Based Security** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard" /v EnableVirtualizationBasedSecurity /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 10.5 Enable Anti-Exploitation Features
- **NIST SP 800-53 Rev. 5**: SI-16 Memory Protection

Risk

Vulnerability

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

### [Ensure Virtualization Based Security Platform Level Is Secure Boot Or Higher](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#virtualization-based-security-platform-level-is-secure-boot-or-higher)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.5

**Finding:** Virtualization Based Security platform security level is below Secure Boot.

Checks that the VBS platform security level requires at least Secure Boot (optionally Secure Boot with DMA protection).

This rule fails when `requirePlatformSecurityFeatures` is neither `SECURE_BOOT` nor `SECURE_BOOT_AND_DMA_PROTECTION`.

**Rationale:** Requiring Secure Boot ensures VBS is anchored to a verified boot chain; adding DMA protection further blocks memory attacks from malicious peripherals.

**Impact:** VBS requires Secure Boot, and optionally hardware DMA protection, to be present.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Device Guard\Turn On Virtualization Based Security: Select Platform Security Level** and set it to **Enabled: Secure Boot or higher**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard" /v RequirePlatformSecurityFeatures /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 10.5 Enable Anti-Exploitation Features
- **NIST SP 800-53 Rev. 5**: SI-16 Memory Protection

Risk

Vulnerability

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

### [Ensure Virtualization Based Security Requires UEFI Memory Attributes Table](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#virtualization-based-security-requires-uefi-memory-attributes-table)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.5

**Finding:** Virtualization Based Security does not require the UEFI Memory Attributes Table.

Checks whether VBS requires firmware to provide a UEFI Memory Attributes Table (MAT).

This rule fails when `hvcimatRequired` is not `true`.

**Rationale:** Requiring the MAT ensures firmware memory is described correctly to the hypervisor, strengthening the memory-integrity guarantees VBS relies on.

**Impact:** VBS is only enabled on firmware that supplies a UEFI Memory Attributes Table.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Device Guard\Turn On Virtualization Based Security: Require UEFI Memory Attributes Table** and set it to **True (checked)**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard" /v HVCIMATRequired /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 10.5 Enable Anti-Exploitation Features
- **NIST SP 800-53 Rev. 5**: SI-16 Memory Protection

Risk

Vulnerability

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

## 18.9.7 Device Installation

### [Ensure Automatic Download Of Device Metadata From The Internet Is Prevented](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#automatic-download-of-device-metadata-from-the-internet-is-prevented)

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.7

**Finding:** Automatic download of device metadata from the internet is not prevented.

Checks whether Windows is blocked from retrieving device metadata for installed devices from the internet.

This rule fails when `preventDeviceMetadataFromNetwork` is not `true`.

**Rationale:** Preventing automatic metadata downloads avoids unnecessary outbound connections and reduces data shared with external services.

**Impact:** Device metadata is not fetched from the internet; devices still function with locally available metadata.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Device Installation\Prevent automatic download of applications associated with device metadata** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceMetadata" /v PreventDeviceMetadataFromNetwork /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 2.5 Allowlist Authorized Software; 10.5 Enable Anti-Exploitation Features
- **NIST SP 800-53 Rev. 5**: CM-7 Least Functionality; CM-10 Software Usage Restrictions; SI-16 Memory Protection
- **NIST SP 800-171 Rev. 2**: 3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; 3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
- **CMMC 2.0 Level 2**: CM.L2-3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; SC.L2-3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Device Setup Class Restrictions Apply To Already Installed Devices](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#device-setup-class-restrictions-apply-to-already-installed-devices)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.7.1

**Finding:** Device setup class restrictions do not apply to already installed devices.

Checks whether the device setup class installation restrictions also apply to matching devices that were installed before the policy took effect.

This rule fails when `denyDeviceClassesRetroactive` is not `true`.

**Rationale:** Applying the restriction retroactively removes access to already-installed devices in the blocked classes, closing a gap an attacker could otherwise use.

**Impact:** Matching devices already present on the system are also blocked, not just newly connected ones.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Device Installation\Device Installation Restrictions\Prevent installation of devices using drivers that match these device setup classes: Also apply to matching devices that are already installed.** and set it to **True (checked)**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceInstall\Restrictions" /v DenyDeviceClassesRetroactive /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 10.5 Enable Anti-Exploitation Features
- **NIST SP 800-53 Rev. 5**: SI-16 Memory Protection

Risk

Vulnerability

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure IEEE 1394 Device Setup Classes Are In The Prevented Device List](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#ieee-1394-device-setup-classes-are-in-the-prevented-device-list)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.7.1

**Finding:** IEEE 1394 device setup classes are missing from the prevented device list.

Checks that the four IEEE 1394 (FireWire) device setup class GUIDs are present in the list of device classes Windows is prevented from installing.

This rule fails when any of the four IEEE 1394 device setup class GUIDs is absent from `denyDeviceClassesList`.

**Rationale:** IEEE 1394 controllers can perform Direct Memory Access; blocking their drivers helps protect a BitLocker-protected host from DMA attacks that could recover encryption keys from memory.

**Impact:** IEEE 1394 (FireWire) drives and devices can no longer be installed on the host.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Device Installation\Device Installation Restrictions\Prevent installation of devices using drivers that match these device setup classes** and set it to **Enabled, then add the four IEEE 1394 device setup class GUIDs**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceInstall\Restrictions\DenyDeviceClasses" /v 1 /t REG_SZ /d "{d48179be-ec20-11d1-b6b8-00c04fa372a7}" /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceInstall\Restrictions\DenyDeviceClasses" /v 2 /t REG_SZ /d "{7ebefbc0-3200-11d2-b4c2-00a0C9697d07}" /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceInstall\Restrictions\DenyDeviceClasses" /v 3 /t REG_SZ /d "{c06ff265-ae09-48f0-812c-16753d7cba83}" /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceInstall\Restrictions\DenyDeviceClasses" /v 4 /t REG_SZ /d "{6bdd1fc1-810f-11d0-bec7-08002be2092f}" /f
```

Risk

Vulnerability

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure Installation Of Devices Matching Configured Setup Classes Is Prevented](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#installation-of-devices-matching-configured-setup-classes-is-prevented)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.7.1

**Finding:** Installation of devices matching the configured setup classes is not prevented.

Checks whether Windows is prevented from installing drivers for the device setup classes listed in the deny list.

This rule fails when `denyDeviceClasses` is not `true`.

**Rationale:** Blocking driver installation for specified device classes reduces the attack surface from untrusted or DMA-capable hardware such as IEEE 1394 controllers.

**Impact:** Windows will not install or update drivers for devices whose setup class GUID is in the deny list.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Device Installation\Device Installation Restrictions\Prevent installation of devices using drivers that match these device setup classes** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceInstall\Restrictions" /v DenyDeviceClasses /t REG_DWORD /d 1 /f
```

Risk

Vulnerability

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## 18.9.13 Early Launch Antimalware

### [Ensure Boot Start Driver Initialization Allows Good Unknown And Critical Bad Drivers](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#boot-start-driver-initialization-allows-good-unknown-and-critical-bad-drivers)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.13

**Finding:** Boot-start driver initialization policy is not set to good, unknown and bad but critical.

Checks which boot-start drivers Early Launch Antimalware permits to initialize based on their classification.

This rule fails when `driverLoadPolicy` is not `GOOD_PLUS_UNKNOWN_PLUS_BAD_CRITICAL`.

**Rationale:** Allowing good, unknown, and only boot-critical bad drivers blocks known-malicious non-critical boot drivers while keeping the system bootable.

**Impact:** Non-critical drivers classified as bad by ELAM are prevented from loading at boot.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Early Launch Antimalware\Boot-Start Driver Initialization Policy** and set it to **Enabled: Good, unknown and bad but critical**.

From the command line:

```powershell
reg add "HKLM\SYSTEM\CurrentControlSet\Policies\EarlyLaunch" /v DriverLoadPolicy /t REG_DWORD /d 3 /f
```

Framework mappings

- **CIS Controls v8**: 10.5 Enable Anti-Exploitation Features
- **NIST SP 800-53 Rev. 5**: SI-16 Memory Protection

Risk

Vulnerability

MITRE ATT&CK tactic

Persistence ([TA0003](https://attack.mitre.org/tactics/TA0003/))

## 18.9.17 Filesystem (formerly NTFS Filesystem)

### [Ensure CLFS Logfile Authentication Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#clfs-logfile-authentication-is-enabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.17

**Finding:** CLFS logfile authentication is not enabled.

Checks whether the Common Log File System validates the authenticity of log files before processing them.

This rule fails when `clfsAuthenticationChecking` is not `true`.

**Rationale:** Authenticating CLFS logfiles blocks a class of parsing vulnerabilities in the CLFS driver that attackers have used for local privilege escalation.

**Impact:** CLFS rejects log files that fail authentication checks.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Filesystem\Enable / disable CLFS logfile authentication** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SYSTEM\CurrentControlSet\Policies" /v ClfsAuthenticationChecking /t REG_DWORD /d 1 /f
```

Risk

Vulnerability

MITRE ATT&CK tactic

Privilege Escalation ([TA0004](https://attack.mitre.org/tactics/TA0004/))

## 18.9.19 Group Policy

### [Ensure Continue Experiences On This Device Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#continue-experiences-on-this-device-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.19

**Finding:** Continue experiences on this device is enabled.

Checks whether the Connected Devices Platform, which lets Windows share activities across a user's devices, is turned off.

This rule fails when `enableCdp` is not `false`.

**Rationale:** Disabling cross-device continuation limits the sharing of user activity data between devices and cloud services.

**Impact:** Users can no longer resume activities from this device on another device.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Group Policy\Continue experiences on this device** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v EnableCdp /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## 18.9.20 Internet Communication Management

### [Ensure Access To The Store For Unknown File Types Is Turned Off](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#access-to-the-store-for-unknown-file-types-is-turned-off)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.20.1

**Finding:** Access to the Store for unknown file types is not turned off.

Checks whether the 'Look for an app in the Store' option is disabled when a user opens a file with an unknown extension.

This rule fails when `noUseStoreOpenWith` is not `true`.

**Rationale:** Preventing Store lookups for unknown file types stops users from being steered to install arbitrary apps to open unrecognized files.

**Impact:** Users are not offered the Microsoft Store when opening files with unknown extensions.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off access to the Store** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Explorer" /v NoUseStoreOpenWith /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 2.5 Allowlist Authorized Software
- **NIST SP 800-53 Rev. 5**: CM-7 Least Functionality; CM-10 Software Usage Restrictions
- **NIST SP 800-171 Rev. 2**: 3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; 3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
- **CMMC 2.0 Level 2**: CM.L2-3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; SC.L2-3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality

Risk

External Attack Surface

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

### [Ensure Downloading Of Print Drivers Over HTTP Is Turned Off](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#downloading-of-print-drivers-over-http-is-turned-off)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.20.1

**Finding:** Downloading of print drivers over HTTP is not turned off.

Checks whether Windows is blocked from downloading print drivers over HTTP.

This rule fails when `disableWebPnPDownload` is not `true`.

**Rationale:** Blocking HTTP print-driver downloads prevents fetching and installing driver code from untrusted internet sources.

**Impact:** Print drivers must be obtained from local or managed sources rather than over HTTP.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off downloading of print drivers over HTTP** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers" /v DisableWebPnPDownload /t REG_DWORD /d 1 /f
```

Risk

External Attack Surface

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

### [Ensure Handwriting Personalization Data Sharing Is Turned Off](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#handwriting-personalization-data-sharing-is-turned-off)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.20.1

**Finding:** Handwriting personalization data sharing is not turned off.

Checks whether the automatic sharing of handwriting recognition personalization data with Microsoft is turned off.

This rule fails when `preventHandwritingDataSharing` is not `true`.

**Rationale:** Stopping this upload keeps potentially sensitive handwriting samples from leaving the host.

**Impact:** Handwriting personalization data is no longer collected and sent to Microsoft.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off handwriting personalization data sharing** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\TabletPC" /v PreventHandwritingDataSharing /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Handwriting Recognition Error Reporting Is Turned Off](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#handwriting-recognition-error-reporting-is-turned-off)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.20.1

**Finding:** Handwriting recognition error reporting is not turned off.

Checks whether handwriting recognition error reports are prevented from being sent to Microsoft.

This rule fails when `preventHandwritingErrorReports` is not `true`.

**Rationale:** Suppressing these reports avoids transmitting recognized text and ink samples that may contain sensitive information.

**Impact:** Handwriting recognition error reports are not generated or uploaded.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off handwriting recognition error reporting** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\HandwritingErrorReports" /v PreventHandwritingErrorReports /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Internet Connection Wizard Cannot Connect To Microsoft.com](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#internet-connection-wizard-cannot-connect-to-microsoft-com)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.20.1

**Finding:** Internet Connection Wizard can connect to Microsoft.com.

Checks whether the Internet Connection Wizard is blocked from contacting Microsoft.com to download a list of ISPs.

This rule fails when `exitOnMSICW` is not `true`.

**Rationale:** Blocking this connection reduces unnecessary outbound traffic to external Microsoft services during connection setup.

**Impact:** The Internet Connection Wizard no longer downloads referral content from Microsoft.com.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off Internet Connection Wizard if URL connection is referring to Microsoft.com** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Internet Connection Wizard" /v ExitOnMSICW /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Internet Download For Web Publishing And Ordering Wizards Is Turned Off](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#internet-download-for-web-publishing-and-ordering-wizards-is-turned-off)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.20.1

**Finding:** Internet download for web publishing and online ordering wizards is not turned off.

Checks whether Windows is prevented from downloading a provider list for web publishing and online ordering wizards.

This rule fails when `noWebServices` is not `true`.

**Rationale:** Preventing these downloads limits outbound connections to third-party web-service providers.

**Impact:** Users cannot use the internet-based provider lists in the publishing and ordering wizards.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off Internet download for Web publishing and online ordering wizards** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoWebServices /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Printing Over HTTP Is Turned Off](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#printing-over-http-is-turned-off)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.20.1

**Finding:** Printing over HTTP is not turned off.

Checks whether the client's ability to print to printers over HTTP is turned off.

This rule fails when `disableHTTPPrinting` is not `true`.

**Rationale:** Disabling HTTP printing stops the host from sending print jobs to internet-hosted printers over an unencrypted channel.

**Impact:** The client can no longer print to HTTP-based printers on the internet.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off printing over HTTP** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers" /v DisableHTTPPrinting /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Registration Referring To Microsoft.com Is Turned Off](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#registration-referring-to-microsoft-com-is-turned-off)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.20.1

**Finding:** Registration referring to Microsoft.com is not turned off.

Checks whether the Windows Registration Wizard is blocked from connecting to Microsoft.com.

This rule fails when `noRegistration` is not `true`.

**Rationale:** Blocking online registration avoids sending user and system details to external Microsoft registration services.

**Impact:** Users cannot register the product online through the wizard.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off Registration if URL connection is referring to Microsoft.com** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Registration Wizard Control" /v NoRegistration /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Search Companion Content File Updates Are Turned Off](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#search-companion-content-file-updates-are-turned-off)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.20.1

**Finding:** Search Companion content file updates are not turned off.

Checks whether the Search Companion is prevented from automatically downloading content file updates.

This rule fails when `disableContentFileUpdates` is not `true`.

**Rationale:** Preventing automatic content downloads reduces unsolicited outbound connections to Microsoft services.

**Impact:** Search Companion does not download updated content files over the internet.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off Search Companion content file updates** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\SearchCompanion" /v DisableContentFileUpdates /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure The Order Prints Picture Task Is Turned Off](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#the-order-prints-picture-task-is-turned-off)

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.20.1

**Finding:** The Order Prints picture task is not turned off.

Checks whether the 'Order Prints Online' task, which uploads pictures to online print providers, is removed.

This rule fails when `noOnlinePrintsWizard` is not `true`.

**Rationale:** Removing the online prints task prevents users from uploading local images to third-party internet services.

**Impact:** The 'Order Prints Online' option no longer appears in picture folders and tasks.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off the "Order Prints" picture task** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoOnlinePrintsWizard /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure The Publish To Web Task For Files And Folders Is Turned Off](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#the-publish-to-web-task-for-files-and-folders-is-turned-off)

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.20.1

**Finding:** The Publish to Web task for files and folders is not turned off.

Checks whether the 'Publish to Web' task for files and folders is removed from File Explorer.

This rule fails when `noPublishingWizard` is not `true`.

**Rationale:** Removing this task prevents users from uploading local files and folders to internet hosting services.

**Impact:** The 'Publish to Web' option is no longer available for files and folders.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off the "Publish to Web" task for files and folders** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoPublishingWizard /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure The Windows Customer Experience Improvement Program Is Turned Off](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#the-windows-customer-experience-improvement-program-is-turned-off)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.20.1

**Finding:** The Windows Customer Experience Improvement Program is not turned off.

Checks whether Windows is prevented from participating in the Customer Experience Improvement Program.

This rule fails when `ceipEnable` is not `false`.

**Rationale:** Opting out stops Windows usage and configuration data from being collected and sent to Microsoft.

**Impact:** Windows no longer collects or transmits Customer Experience Improvement data.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off Windows Customer Experience Improvement Program** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\SQMClient\Windows" /v CEIPEnable /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure The Windows Messenger Customer Experience Improvement Program Is Turned Off](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#the-windows-messenger-customer-experience-improvement-program-is-turned-off)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.20.1

**Finding:** The Windows Messenger Customer Experience Improvement Program is not turned off.

Checks whether Windows Messenger is prevented from participating in the Customer Experience Improvement Program.

This rule fails when `ceip` is not `false`.

**Rationale:** Opting out stops usage data from being collected and sent to Microsoft by Windows Messenger.

**Impact:** Windows Messenger no longer collects or transmits Customer Experience Improvement data.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off the Windows Messenger Customer Experience Improvement Program** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Messenger\Client" /v CEIP /t REG_DWORD /d 2 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Windows Error Reporting Is Turned Off](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#windows-error-reporting-is-turned-off)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.20.1

**Finding:** Windows Error Reporting is not turned off.

Checks whether Windows Error Reporting is disabled so crash and error reports are not sent to Microsoft.

This rule fails when `windowsErrorReportingDisabled` is not `true`.

**Rationale:** Error reports can contain memory snapshots and other sensitive data; disabling reporting keeps that information on the host.

**Impact:** Application and system error data is no longer transmitted to Microsoft.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off Windows Error Reporting** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Windows Error Reporting" /v Disabled /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## 18.9.23 Kerberos

### [Ensure Device Authentication Using Certificate Is Set To Automatic](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#device-authentication-using-certificate-is-set-to-automatic)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.23

**Finding:** Device authentication using certificate is not set to automatic.

Checks whether the device attempts Kerberos PKINIT certificate authentication, falling back to password authentication when a supporting domain controller is unavailable.

This rule fails when `devicePKInitEnabled` is not `true` or `devicePKInitBehavior` is not `AUTOMATIC`.

**Rationale:** Certificate-based device authentication is stronger than username and password; the automatic mode uses it whenever possible without breaking connectivity.

**Impact:** None; this matches the default behavior when the supporting infrastructure is present.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Kerberos\Support device authentication using certificate** and set it to **Enabled: Automatic**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\kerberos\parameters" /v DevicePKInitEnabled /t REG_DWORD /d 1 /f
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\kerberos\parameters" /v DevicePKInitBehavior /t REG_DWORD /d 0 /f
```

Risk

Unprotected Principal

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

## 18.9.24 Kernel DMA Protection

### [Ensure External Devices Incompatible With Kernel DMA Protection Are Blocked](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#external-devices-incompatible-with-kernel-dma-protection-are-blocked)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.24

**Finding:** External devices incompatible with Kernel DMA Protection are not blocked.

Checks the enumeration policy for external DMA-capable devices that are not compatible with Kernel DMA Protection.

This rule fails when `deviceEnumerationPolicy` is not `BLOCK_ALL`.

**Rationale:** Blocking incompatible external DMA devices prevents malicious peripherals from reading system memory, which could expose credentials or encryption keys.

**Impact:** External Thunderbolt/PCIe devices lacking DMA-remapping support are not enumerated, even while a user is signed in.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Kernel DMA Protection\Enumeration policy for external devices incompatible with Kernel DMA Protection** and set it to **Enabled: Block All**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Kernel DMA Protection" /v DeviceEnumerationPolicy /t REG_DWORD /d 0 /f
```

Risk

Unprotected Data

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

## 18.9.27 Local Security Authority

### [Ensure Custom SSPs And APs Cannot Be Loaded Into LSASS](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#custom-ssps-and-aps-cannot-be-loaded-into-lsass)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.27

**Finding:** Custom SSPs and APs can be loaded into LSASS.

Checks whether custom Security Support Providers and Authentication Packages are blocked from being loaded into the LSASS process.

This rule fails when `allowCustomSSPsAPs` is not `false`.

**Rationale:** Blocking custom SSPs/APs prevents attackers from injecting credential-harvesting modules into LSASS.

**Impact:** Third-party authentication modules that rely on loading into LSASS will not load.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Local Security Authority\Allow Custom SSPs and APs to be loaded into LSASS** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v AllowCustomSSPsAPs /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 10.5 Enable Anti-Exploitation Features
- **NIST SP 800-53 Rev. 5**: SI-16 Memory Protection

Risk

Insecure Use of Secrets

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure LSASS Runs As A Protected Process With UEFI Lock](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#lsass-runs-as-a-protected-process-with-uefi-lock)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.27

**Finding:** LSASS does not run as a protected process with UEFI lock.

Checks whether LSASS runs as a Protected Process Light with the configuration locked into UEFI firmware.

This rule fails when `runAsPPL` is not `ENABLED_WITH_UEFI_LOCK`.

**Rationale:** Running LSASS as a protected process blocks non-protected code (such as Mimikatz) from reading its memory; the UEFI lock prevents remote disabling.

**Impact:** Unsigned or non-protected plug-ins cannot load into LSASS, and the protection cannot be removed without physical access to clear the UEFI variable.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Local Security Authority\Configures LSASS to run as a protected process** and set it to **Enabled: Enabled with UEFI Lock**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v RunAsPPL /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 10.5 Enable Anti-Exploitation Features
- **NIST SP 800-53 Rev. 5**: SI-16 Memory Protection

Risk

Insecure Use of Secrets

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

## 18.9.28 Locale Services

### [Ensure Copying Of User Input Methods To The System Account For Sign In Is Disallowed](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#copying-of-user-input-methods-to-the-system-account-for-sign-in-is-disallowed)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.28

**Finding:** Copying of user input methods to the system account for sign-in is allowed.

Checks whether user-configured input methods are prevented from being copied to the system account used at the sign-in screen.

This rule fails when `blockUserInputMethodsForSignIn` is not `true`.

**Rationale:** Blocking this copy keeps user-specific input method configurations from influencing the system account context at sign-in.

**Impact:** The system account uses only the system default input methods at the sign-in screen.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Locale Services\Disallow copying of user input methods to the system account for sign-in** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\ControlPanel\International" /v BlockUserInputMethodsForSignIn /t REG_DWORD /d 1 /f
```

Risk

Vulnerability

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

## 18.9.29 Logon

### [Ensure App Notifications On The Lock Screen Are Turned Off](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#app-notifications-on-the-lock-screen-are-turned-off)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.29

**Finding:** App notifications on the lock screen are not turned off.

Checks whether application notifications are prevented from appearing on the lock screen.

This rule fails when `disableLockScreenAppNotifications` is not `true`.

**Rationale:** Suppressing lock-screen notifications keeps potentially sensitive content from being shown on an unattended device.

**Impact:** Apps can no longer display notifications on the lock screen.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Logon\Turn off app notifications on the lock screen** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v DisableLockScreenAppNotifications /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Convenience PIN Sign In Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#convenience-pin-sign-in-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.29

**Finding:** Convenience PIN sign-in is enabled.

Checks whether domain users are prevented from signing in with a convenience PIN.

This rule fails when `allowDomainPINLogon` is not `false`.

**Rationale:** A convenience PIN is drawn from a small character set and is generally weaker than a password, so disabling it preserves stronger authentication.

**Impact:** Domain users must sign in with their password rather than a convenience PIN.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Logon\Turn on convenience PIN sign-in** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v AllowDomainPINLogon /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Principal

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure The Network Selection UI Is Not Displayed](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#the-network-selection-ui-is-not-displayed)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.29

**Finding:** The network selection UI is displayed on the logon screen.

Checks whether the network selection UI is hidden from users on the lock/logon screen.

This rule fails when `dontDisplayNetworkSelectionUI` is not `true`.

**Rationale:** Hiding network selection prevents an unauthenticated person from changing network connectivity from the lock screen.

**Impact:** Users cannot change the device's network connection from the sign-in screen.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Logon\Do not display network selection UI** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v DontDisplayNetworkSelectionUI /t REG_DWORD /d 1 /f
```

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure Users Are Blocked From Showing Account Details On Sign In](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#users-are-blocked-from-showing-account-details-on-sign-in)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.29

**Finding:** Users are not blocked from showing account details on sign-in.

Checks whether users are prevented from displaying account details, such as email address, on the sign-in screen.

This rule fails when `blockUserFromShowingAccountDetailsOnSignin` is not `true`.

**Rationale:** Hiding account details reduces the information an onlooker can gather from an unattended lock screen.

**Impact:** Account details are not shown on the sign-in screen.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Logon\Block user from showing account details on sign-in** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v BlockUserFromShowingAccountDetailsOnSignin /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process
- **NIST SP 800-53 Rev. 5**: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components

Risk

Unprotected Data

MITRE ATT&CK tactic

Discovery ([TA0007](https://attack.mitre.org/tactics/TA0007/))

## 18.9.33 OS Policies

### [Ensure Clipboard Synchronization Across Devices Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#clipboard-synchronization-across-devices-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.33

**Finding:** Clipboard synchronization across devices is enabled.

Checks whether clipboard contents are prevented from being synchronized across a user's devices through the cloud.

This rule fails when `allowCrossDeviceClipboard` is not `false`.

**Rationale:** Disabling cross-device clipboard keeps potentially sensitive copied data from being uploaded to and shared through cloud services.

**Impact:** Clipboard contents are not shared between this device and the user's other devices.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\OS Policies\Allow Clipboard synchronization across devices** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v AllowCrossDeviceClipboard /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Upload Of User Activities Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#upload-of-user-activities-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.33

**Finding:** Upload of User Activities is enabled.

Checks whether the Activity Feed is prevented from uploading published user activities to the cloud.

This rule fails when `uploadUserActivities` is not `false`.

**Rationale:** Blocking activity uploads limits the user-behavior data shared with Microsoft cloud services.

**Impact:** User activities are not uploaded, so cross-device timeline continuation is unavailable.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\OS Policies\Allow upload of User Activities** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v UploadUserActivities /t REG_DWORD /d 0 /f
```

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## 18.9.35 Power Management

### [Ensure A Password Is Required When Waking On Battery](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#a-password-is-required-when-waking-on-battery)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.35.6

**Finding:** A password is not required when the computer wakes on battery.

Checks whether the user is prompted for a password when the device wakes from sleep on battery.

This rule fails when `requirePasswordOnWakeOnBattery` is not `true`.

**Rationale:** Requiring a password on wake prevents someone with physical access from using an unattended device without authenticating.

**Impact:** Users must re-enter their password when the device wakes from sleep on battery.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Power Management\Sleep Settings\Require a password when a computer wakes (on battery)** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Power\PowerSettings\0e796bdb-100d-47d6-a2d5-f7d2daa51f51" /v DCSettingIndex /t REG_DWORD /d 1 /f
```

Risk

Unprotected Principal

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure A Password Is Required When Waking Plugged In](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#a-password-is-required-when-waking-plugged-in)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.35.6

**Finding:** A password is not required when the computer wakes while plugged in.

Checks whether the user is prompted for a password when the device wakes from sleep while plugged in.

This rule fails when `requirePasswordOnWakeWhenPluggedIn` is not `true`.

**Rationale:** Requiring a password on wake prevents someone with physical access from using an unattended device without authenticating.

**Impact:** Users must re-enter their password when the device wakes from sleep while plugged in.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Power Management\Sleep Settings\Require a password when a computer wakes (plugged in)** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Power\PowerSettings\0e796bdb-100d-47d6-a2d5-f7d2daa51f51" /v ACSettingIndex /t REG_DWORD /d 1 /f
```

Risk

Unprotected Principal

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure Network Connectivity During Connected Standby On Battery Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#network-connectivity-during-connected-standby-on-battery-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.35.6

**Finding:** Network connectivity during connected-standby on battery is allowed.

Checks whether network connectivity is prevented while the device is in connected standby running on battery.

This rule fails when `allowNetworkConDuringStandbyOnBattery` is not `false`.

**Rationale:** Disabling standby network connectivity reduces the window in which a sleeping, unattended device is reachable over the network.

**Impact:** The device does not maintain network connectivity during connected standby on battery.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Power Management\Sleep Settings\Allow network connectivity during connected-standby (on battery)** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Power\PowerSettings\f15576e8-98b7-4186-b944-eafa664402d9" /v DCSettingIndex /t REG_DWORD /d 0 /f
```

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure Network Connectivity During Connected Standby Plugged In Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#network-connectivity-during-connected-standby-plugged-in-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.35.6

**Finding:** Network connectivity during connected-standby plugged in is allowed.

Checks whether network connectivity is prevented while the device is in connected standby while plugged in.

This rule fails when `allowNetworkConDuringStandbyPluggedIn` is not `false`.

**Rationale:** Disabling standby network connectivity reduces the window in which a sleeping, unattended device is reachable over the network.

**Impact:** The device does not maintain network connectivity during connected standby when plugged in.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Power Management\Sleep Settings\Allow network connectivity during connected-standby (plugged in)** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Power\PowerSettings\f15576e8-98b7-4186-b944-eafa664402d9" /v ACSettingIndex /t REG_DWORD /d 0 /f
```

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure Standby States When Sleeping On Battery Are Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#standby-states-when-sleeping-on-battery-are-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.35.6

**Finding:** Standby states (S1-S3) when sleeping on battery are allowed.

Checks whether S1-S3 standby sleep states are prevented while the device is on battery.

This rule fails when `allowStandbyStatesWhenSleeping` is not `false`.

**Rationale:** Blocking standby sleep states keeps encryption keys and other secrets out of easily attacked powered memory when the device is left unattended.

**Impact:** On battery the device uses hibernate or shutdown instead of S1-S3 standby.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Power Management\Sleep Settings\Allow standby states (S1-S3) when sleeping (on battery)** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Power\PowerSettings\abfc2519-3608-4c2a-94ea-171b0ed546ab" /v DCSettingIndex /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process
- **NIST SP 800-53 Rev. 5**: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components

Risk

Unprotected Data

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure Standby States When Sleeping Plugged In Are Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#standby-states-when-sleeping-plugged-in-are-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.35.6

**Finding:** Standby states (S1-S3) when sleeping plugged in are allowed.

Checks whether S1-S3 standby sleep states are prevented while the device is plugged in.

This rule fails when `allowStandbyStatesWhenPluggedIn` is not `false`.

**Rationale:** Blocking standby sleep states keeps encryption keys and other secrets out of easily attacked powered memory when the device is left unattended.

**Impact:** When plugged in the device uses hibernate or shutdown instead of S1-S3 standby.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Power Management\Sleep Settings\Allow standby states (S1-S3) when sleeping (plugged in)** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Power\PowerSettings\abfc2519-3608-4c2a-94ea-171b0ed546ab" /v ACSettingIndex /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process
- **NIST SP 800-53 Rev. 5**: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components

Risk

Unprotected Data

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

## 18.9.37 Remote Assistance

### [Ensure Offer Remote Assistance Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#offer-remote-assistance-is-disabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.37

**Finding:** Offer Remote Assistance is enabled.

Checks whether unsolicited (offered) Remote Assistance connections to this computer are prevented.

This rule fails when `fAllowUnsolicited` is not `false`.

**Rationale:** Disabling offered Remote Assistance stops helpers from initiating remote control sessions without an explicit user request, closing a remote-access avenue.

**Impact:** Support staff cannot offer Remote Assistance; users must solicit help through other means if solicited assistance is also disabled.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Remote Assistance\Configure Offer Remote Assistance** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v fAllowUnsolicited /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Exposure

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure Solicited Remote Assistance Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#solicited-remote-assistance-is-disabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.37

**Finding:** Solicited Remote Assistance is enabled.

Checks whether users are prevented from requesting (soliciting) Remote Assistance from this computer.

This rule fails when `fAllowToGetHelp` is not `false`.

**Rationale:** Disabling solicited Remote Assistance removes a remote-control channel that an attacker could abuse to take over a session.

**Impact:** Users can no longer send Remote Assistance invitations from this computer.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Remote Assistance\Configure Solicited Remote Assistance** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v fAllowToGetHelp /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Exposure

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## 18.9.38 Remote Procedure Call

### [Ensure RPC Endpoint Mapper Client Authentication Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#rpc-endpoint-mapper-client-authentication-is-enabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.38

**Finding:** RPC Endpoint Mapper Client Authentication is not enabled.

Checks whether RPC clients authenticate to the Endpoint Mapper service when resolving RPC endpoints.

This rule fails when `enableAuthEpResolution` is not `true`.

**Rationale:** Requiring authentication to the Endpoint Mapper limits anonymous querying of RPC services available on the host.

**Impact:** RPC clients that cannot authenticate to the Endpoint Mapper may fail to resolve endpoints.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Remote Procedure Call\Enable RPC Endpoint Mapper Client Authentication** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Rpc" /v EnableAuthEpResolution /t REG_DWORD /d 1 /f
```

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure Unauthenticated RPC Clients Are Restricted](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#unauthenticated-rpc-clients-are-restricted)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.38

**Finding:** Unauthenticated RPC clients are not restricted.

Checks whether the RPC runtime rejects unauthenticated remote RPC client connections.

This rule fails when `restrictRemoteClients` is not `AUTHENTICATED`.

**Rationale:** Restricting unauthenticated clients blocks anonymous access to RPC-exposed services, reducing the remote attack surface.

**Impact:** Remote RPC calls must be authenticated (except certain named-pipe calls), which may affect legacy applications that rely on anonymous RPC.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Remote Procedure Call\Restrict Unauthenticated RPC clients** and set it to **Enabled: Authenticated**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Rpc" /v RestrictRemoteClients /t REG_DWORD /d 1 /f
```

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## 18.9.49 Troubleshooting and Diagnostics

### [Ensure MSDT Interactive Communication With Support Provider Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#msdt-interactive-communication-with-support-provider-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.49.5

**Finding:** MSDT interactive communication with the support provider is enabled.

Checks whether the Microsoft Support Diagnostic Tool is prevented from communicating interactively with a remote support provider.

This rule fails when `disableQueryRemoteServer` is not `false`.

**Rationale:** Disabling MSDT interactive communication stops potentially sensitive diagnostic data from being collected and sent to a third-party support provider.

**Impact:** MSDT cannot run in support mode, so no diagnostic data is collected or sent to a support provider.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Troubleshooting and Diagnostics\Microsoft Support Diagnostic Tool\Microsoft Support Diagnostic Tool: Turn on MSDT interactive communication with support provider** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\ScriptedDiagnosticsProvider\Policy" /v DisableQueryRemoteServer /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure PerfTrack Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#perftrack-is-disabled)

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.49.11

**Finding:** PerfTrack is enabled.

Checks whether the Windows Performance PerfTrack diagnostic scenario, which collects performance data, is disabled.

This rule fails when `scenarioExecutionEnabled` is not `false`.

**Rationale:** Disabling PerfTrack stops the collection and reporting of performance telemetry from the host.

**Impact:** Windows no longer collects PerfTrack performance data.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Troubleshooting and Diagnostics\Windows Performance PerfTrack\Enable/Disable PerfTrack** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WDI\{9c5a40da-b965-4fc3-8781-88dd50a6299d}" /v ScenarioExecutionEnabled /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## 18.9.51 User Profiles

### [Ensure The Advertising ID Is Turned Off](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#the-advertising-id-is-turned-off)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.51

**Finding:** The advertising ID is not turned off.

Checks whether the per-user advertising ID, which apps use to build cross-app usage profiles, is turned off.

This rule fails when `disabledByGroupPolicy` is not `true`.

**Rationale:** Disabling the advertising ID limits the tracking of user behavior across applications for targeted advertising.

**Impact:** Apps can no longer use the advertising ID to deliver personalized advertising.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\User Profiles\Turn off the advertising ID** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\AdvertisingInfo" /v DisabledByGroupPolicy /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## 18.9.53 Windows Time Service

### [Ensure The Windows NTP Client Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/system.html#the-windows-ntp-client-is-enabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.9.53.1

**Finding:** The Windows NTP client is disabled.

Checks whether the Windows NTP client is enabled so the host synchronizes its clock with a time source.

This rule fails when `ntpClientEnabled` is not `true`.

**Rationale:** Accurate time is essential for Kerberos authentication, certificate validation, and reliable security log correlation across systems.

**Impact:** The host synchronizes its clock using the configured NTP time source.

#### Remediation

Open **Computer Configuration\Policies\Administrative Templates\System\Windows Time Service\Time Providers\Enable Windows NTP Client** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\W32Time\TimeProviders\NtpClient" /v Enabled /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 8.4 Standardize Time Synchronization
- **NIST SP 800-53 Rev. 5**: AU-8 Time Stamps; AU-12 Audit Record Generation
- **NIST SP 800-171 Rev. 2**: 3.3.7 Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records
- **CMMC 2.0 Level 2**: AU.L2-3.3.7 Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records
- **PCI DSS v4.0.1**: 10.6.1 Deploy time-sync technology to align all system clocks; 10.6.2 Use designated central time servers for correct, consistent time; 10.6.3 Restrict who can reach time data and log time setting changes

Risk

Vulnerability

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
