CIS Microsoft Windows 11 Stand-alone Benchmark · Section 18.10

Windows 11 Components: 158 Checks

Wartiva runs 158 checks for section 18.10, Windows Components, of the CIS Microsoft Windows 11 Stand-alone Benchmark. Each one lists what it finds, why it matters, and how to fix it.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →

All 158 checks on this page

18.10.3 App and Device Inventory

Ensure App And Device Inventory API Sampling Is Turned Off

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.3

Finding: App and Device Inventory API sampling data is sent to Microsoft.

Checks whether API sampling data collected during system runtime is prevented from being sent to Microsoft.

This rule fails when disableAPISamping is not true.

Rationale: Runtime API sampling data may contain sensitive information that should not be shared with a third party without explicit consent.

Impact: API sampling data will no longer be transmitted to Microsoft.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\App and Device Inventory\Turn off API Sampling and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\AppCompat" /v DisableAPISamping /t REG_DWORD /d 1 /f
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure App And Device Inventory Application Footprint Is Turned Off

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.3

Finding: App and Device Inventory Application Footprint data is sent to Microsoft.

Checks whether Application Footprint registry and file activity sampling is prevented from being sent to Microsoft.

This rule fails when disableApplicationFootprint is not true.

Rationale: Sampled registry and file activity may contain sensitive information that should not be shared with a third party without explicit consent.

Impact: Application Footprint data will no longer be transmitted to Microsoft.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\App and Device Inventory\Turn off Application Footprint and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\AppCompat" /v DisableApplicationFootprint /t REG_DWORD /d 1 /f
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure App And Device Inventory Install Tracing Is Turned Off

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.3

Finding: App and Device Inventory Install Tracing data is sent to Microsoft.

Checks whether application-install tracing data is prevented from being sent to Microsoft.

This rule fails when disableInstallTracing is not true.

Rationale: Install tracing data may contain sensitive information that should not be shared with a third party without explicit consent.

Impact: Install Tracing data will no longer be transmitted to Microsoft.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\App and Device Inventory\Turn off Install Tracing and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\AppCompat" /v DisableInstallTracing /t REG_DWORD /d 1 /f
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

18.10.4 App Package Deployment

Ensure Non-Admin Users Are Prevented From Installing Packaged Windows Apps

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.4

Finding: Non-admin users are permitted to install packaged Windows apps.

Checks whether non-administrator users are blocked from installing Windows app packages.

This rule fails when blockNonAdminUserInstall is not true.

Rationale: Application installs should be managed centrally by IT staff, not initiated freely by end users.

Impact: Non-administrators cannot install Store app packages unless explicitly permitted by other policy.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\App Package Deployment\Prevent non-admin users from installing packaged Windows apps and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Appx" /v BlockNonAdminUserInstall /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 2.5 Allowlist Authorized Software
  • NIST SP 800-53 Rev. 5: CM-7 Least Functionality; CM-10 Software Usage Restrictions
  • NIST SP 800-171 Rev. 2: 3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; 3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
  • CMMC 2.0 Level 2: CM.L2-3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; SC.L2-3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality
Risk
Insecure Application
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Per-User Unsigned Package Installation Is Disallowed By Default

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.4

Finding: Per-user unsigned packages may install by default.

Checks whether standard users are blocked from installing unsigned Windows App packages by default.

This rule fails when disablePerUserUnsignedPackagesByDefault is not true.

Rationale: Application installs should be managed centrally by IT staff, not initiated freely by end users.

Impact: Standard users cannot install unsigned packaged Store apps unless explicitly permitted.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\App Package Deployment\Not allow per-user unsigned packages to install by default (requires explicitly allow per install) and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Appx" /v DisablePerUserUnsignedPackagesByDefault /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 2.5 Allowlist Authorized Software
  • NIST SP 800-53 Rev. 5: CM-7 Least Functionality; CM-10 Software Usage Restrictions
  • NIST SP 800-171 Rev. 2: 3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; 3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
  • CMMC 2.0 Level 2: CM.L2-3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; SC.L2-3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality
Risk
Insecure Application
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Windows Apps Are Prevented From Sharing Application Data Between Users

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.4

Finding: Windows apps are allowed to share application data between users.

Checks whether a Windows app can share data between users through the shared SharedLocal folder.

This rule fails when allowSharedLocalAppData is not false.

Rationale: Users of the same system could accidentally share sensitive data with one another through the shared app data folder.

Impact: None - this is the default behavior; apps cannot share data with other instances via SharedLocal.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\App Package Deployment\Allow a Windows app to share application data between users and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\AppModel\StateManager" /v AllowSharedLocalAppData /t REG_DWORD /d 0 /f
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

18.10.5 App Privacy

Ensure Voice Activation Of Apps While The System Is Locked Is Forced Off

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.5

Finding: Apps are allowed to activate with voice while the system is locked.

Checks whether apps and Cortana can be activated by voice while the system is locked.

This rule fails when letAppsActivateWithVoiceAboveLock is not FORCE_DENY.

Rationale: No computer resource should be accessible via voice while the device is locked.

Impact: Users cannot activate apps by voice while the computer is locked.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\App Privacy\Let Windows apps activate with voice while the system is locked and set it to Enabled: Force Deny.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\AppPrivacy" /v LetAppsActivateWithVoiceAboveLock /t REG_DWORD /d 2 /f
Risk
Unprotected Principal
MITRE ATT&CK tactic
Initial Access (TA0001)

18.10.6 App runtime

Ensure Launching Universal Windows Apps With WinRT Access From Hosted Content Is Blocked

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.6

Finding: Universal Windows apps with Windows Runtime API access from hosted web content can be launched.

Checks whether Store apps with direct Windows Runtime API access from web content are blocked from launching.

This rule fails when blockHostedAppAccessWinRT is not true.

Rationale: Blocking web apps with direct access to the Windows API prevents malicious apps from running on a system.

Impact: Universal Windows apps declaring Windows Runtime API access in their manifest cannot be launched.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\App runtime\Block launching Universal Windows apps with Windows Runtime API access from hosted content. and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v BlockHostedAppAccessWinRT /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 2.5 Allowlist Authorized Software
  • NIST SP 800-53 Rev. 5: CM-7 Least Functionality; CM-10 Software Usage Restrictions
  • NIST SP 800-171 Rev. 2: 3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; 3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
  • CMMC 2.0 Level 2: CM.L2-3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; SC.L2-3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality
Risk
Insecure Application
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Microsoft Accounts Are Optional For Store Apps

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.6

Finding: Microsoft accounts are required for Store apps that support sign-in.

Checks whether Microsoft accounts are optional for Windows Store apps that require an account.

This rule fails when msaOptional is not true.

Rationale: Microsoft accounts cannot be centrally managed, so enterprise credential-security policies cannot be applied to them, putting any data accessed with them at risk.

Impact: Store apps that normally require a Microsoft account will allow sign-in with an enterprise account.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\App runtime\Allow Microsoft accounts to be optional and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v MSAOptional /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 5.6 Centralize Account Management
  • NIST SP 800-53 Rev. 5: AC-2 Account Management
Risk
Unprotected Principal
MITRE ATT&CK tactic
Initial Access (TA0001)

18.10.8 AutoPlay Policies

Ensure Autoplay Is Disallowed For Non-Volume Devices

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.8

Finding: Autoplay is allowed for non-volume MTP devices.

Checks whether AutoPlay is disallowed for MTP devices such as cameras and phones.

This rule fails when noAutoplayfornonVolume is not true.

Rationale: A threat actor could use AutoPlay on an attached device to launch a program that damages the computer or its data.

Impact: AutoPlay will not be allowed for MTP devices like cameras or phones.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\AutoPlay Policies\Disallow Autoplay for non-volume devices and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Explorer" /v NoAutoplayfornonVolume /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 10.3 Disable Autorun and Autoplay for Removable Media
  • NIST SP 800-53 Rev. 5: MP-7 Media Use
  • NIST SP 800-171 Rev. 2: 3.8.7 Control the use of removable media on system components
  • CMMC 2.0 Level 2: MP.L2-3.8.7 Control the use of removable media on system components
Risk
Insecure Application
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Autoplay Is Turned Off For All Drives

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.8

Finding: Autoplay is not turned off for all drive types.

Checks whether Autoplay, which starts reading media as soon as it is inserted, is turned off for all drives.

This rule fails when noDriveTypeAutoRun is not ALL_DRIVES.

Rationale: A threat actor could use Autoplay to launch a program that damages the computer or its data.

Impact: Autoplay is disabled; users must manually launch setup or installation programs from media.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\AutoPlay Policies\Turn off Autoplay and set it to Enabled: All drives.

From the command line:

reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoDriveTypeAutoRun /t REG_DWORD /d 255 /f
Framework mappings
  • CIS Controls v8: 10.3 Disable Autorun and Autoplay for Removable Media
  • NIST SP 800-53 Rev. 5: MP-7 Media Use
  • NIST SP 800-171 Rev. 2: 3.8.7 Control the use of removable media on system components
  • CMMC 2.0 Level 2: MP.L2-3.8.7 Control the use of removable media on system components
Risk
Insecure Application
MITRE ATT&CK tactic
Execution (TA0002)

Ensure The Default AutoRun Behavior Does Not Execute Any AutoRun Commands

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.8

Finding: The default AutoRun behavior permits execution of autorun commands.

Checks the default behavior for autorun commands (typically stored in autorun.inf files).

This rule fails when noAutorun is not XP.

Rationale: Automatically executing autorun commands when media is inserted allows code to run without the user's knowledge.

Impact: AutoRun commands will be completely disabled.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\AutoPlay Policies\Set the default behavior for AutoRun and set it to Enabled: Do not execute any autorun commands.

From the command line:

reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoAutorun /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 10.3 Disable Autorun and Autoplay for Removable Media
  • NIST SP 800-53 Rev. 5: MP-7 Media Use
  • NIST SP 800-171 Rev. 2: 3.8.7 Control the use of removable media on system components
  • CMMC 2.0 Level 2: MP.L2-3.8.7 Control the use of removable media on system components
Risk
Insecure Application
MITRE ATT&CK tactic
Execution (TA0002)

18.10.9 Biometrics

Ensure Enhanced Anti-Spoofing For Facial Features Is Enabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.9.1

Finding: Enhanced anti-spoofing for facial features is not enabled.

Checks whether enhanced anti-spoofing is required for Windows Hello facial authentication on capable devices.

This rule fails when enhancedAntiSpoofing is not true.

Rationale: Strengthening biometric facial authentication helps protect against spoofing and unauthorized access.

Impact: All users on capable devices will be required to use anti-spoofing for facial recognition.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Biometrics\Facial Features\Configure enhanced anti-spoofing and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Biometrics\FacialFeatures" /v EnhancedAntiSpoofing /t REG_DWORD /d 1 /f
Risk
Unprotected Principal
MITRE ATT&CK tactic
Initial Access (TA0001)

18.10.10 BitLocker Drive Encryption

Ensure A 256-Bit Recovery Key Is Allowed For BitLocker-Protected Fixed Data Drives

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.1

Finding: A 256-bit recovery key is not allowed for BitLocker-protected fixed data drives.

Checks whether users may generate a 256-bit recovery key for BitLocker fixed data drives.

This rule fails when fdvRecoveryKey is not one of ALLOW, REQUIRE.

Rationale: Administrators must always have a secure, controlled way to recover encrypted data when users cannot access it.

Impact: A 256-bit recovery key will be permitted for fixed drives.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Fixed Data Drives\Choose how BitLocker-protected fixed drives can be recovered: Recovery Key and set it to Enabled: Allow 256-bit recovery key (or Require).

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v FDVRecoveryKey /t REG_DWORD /d 2 /f
Framework mappings
  • CIS Controls v8: 3.6 Encrypt Data on End-User Devices
  • NIST SP 800-53 Rev. 5: SC-28 Protection of Information at Rest
  • NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
  • CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure A 48-Digit Recovery Password Is Allowed For BitLocker-Protected Fixed Data Drives

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.1

Finding: A 48-digit recovery password is not allowed for BitLocker-protected fixed data drives.

Checks whether users may generate a 48-digit recovery password for BitLocker fixed data drives.

This rule fails when fdvRecoveryPassword is not one of ALLOW, REQUIRE.

Rationale: Administrators must always have a secure, controlled way to recover encrypted data when users cannot access it.

Impact: A 48-digit recovery password will be permitted for fixed drives.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Fixed Data Drives\Choose how BitLocker-protected fixed drives can be recovered: Recovery Password and set it to Enabled: Allow 48-digit recovery password (or Require).

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v FDVRecoveryPassword /t REG_DWORD /d 2 /f
Framework mappings
  • CIS Controls v8: 3.6 Encrypt Data on End-User Devices
  • NIST SP 800-53 Rev. 5: SC-28 Protection of Information at Rest
  • NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
  • CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure A Data Recovery Agent Is Allowed For BitLocker-Protected Fixed Data Drives

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.1

Finding: A Data Recovery Agent is not allowed for BitLocker-protected fixed data drives.

Checks whether a Data Recovery Agent may be used to recover BitLocker-protected fixed data drives.

This rule fails when fdvManageDRA is not ALLOW.

Rationale: Administrators must always have a secure, controlled way to recover encrypted data when users cannot access it.

Impact: None - this is the default behavior; a DRA is allowed for fixed drives.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Fixed Data Drives\Choose how BitLocker-protected fixed drives can be recovered: Allow data recovery agent and set it to Enabled: True (checked).

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v FDVManageDRA /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 3.6 Encrypt Data on End-User Devices
  • NIST SP 800-53 Rev. 5: SC-28 Protection of Information at Rest
  • NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
  • CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Access To BitLocker-Protected Fixed Data Drives From Earlier Windows Versions Is Disabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.1

Finding: BitLocker-protected fixed data drives are accessible from earlier versions of Windows.

REG_SZ

This rule fails when fdvDiscoveryVolumeType is not false.

Rationale: Checks whether FAT-formatted BitLocker fixed data drives can be unlocked on legacy Windows via the BitLocker To Go Reader.

Impact: The BitLocker To Go Reader placed on the unencrypted portion of the drive is, like any app, subject to spoofing and could propagate malware.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Fixed Data Drives\Allow access to BitLocker-protected fixed data drives from earlier versions of Windows and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v FDVDiscoveryVolumeType /t FAT BitLocker fixed data drives cannot be unlocked on legacy Windows and BitLockerToGo.exe is not installed. /d "" /f
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Hardware-Based Encryption For BitLocker Fixed Data Drives Is Disabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.1

Finding: Hardware-based encryption is used for BitLocker fixed data drives.

Checks whether BitLocker uses hardware-based encryption for fixed data drives.

This rule fails when fdvHardwareEncryption is not false.

Rationale: Hardware-based encryption on some self-encrypting drives has firmware vulnerabilities; software encryption avoids that risk.

Impact: None - this is the default behavior; BitLocker uses software-based encryption for fixed drives.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Fixed Data Drives\Configure use of hardware-based encryption for fixed data drives and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v FDVHardwareEncryption /t REG_DWORD /d 0 /f
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Password Unlock For BitLocker Fixed Data Drives Is Disabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.1

Finding: Password unlock is permitted for BitLocker fixed data drives.

Checks whether a password may be used to unlock BitLocker-protected fixed data drives.

This rule fails when fdvPassphrase is not false.

Rationale: BitLocker passwords lack TPM anti-hammering protection, so there is no throttle against rapid brute-force guessing.

Impact: The password option will not be available when configuring BitLocker for fixed drives.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Fixed Data Drives\Configure use of passwords for fixed data drives and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v FDVPassphrase /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 5.2 Use Unique Passwords
  • NIST SP 800-53 Rev. 5: IA-5 Authenticator Management
  • NIST SP 800-171 Rev. 2: 3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
  • CMMC 2.0 Level 2: IA.L2-3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
  • PCI DSS v4.0.1: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 8.3.5 Use unique initial passwords and force change on first use; 8.3.6 Enforce 12-character minimum password length with letters and numbers; 8.6.3 Rotate and harden passwords for application and system-level accounts
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Recovery Of BitLocker-Protected Fixed Data Drives Is Configured

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.1

Finding: Recovery of BitLocker-protected fixed data drives is not configured.

Checks whether recovery options for BitLocker-protected fixed data drives are governed by policy.

This rule fails when fdvRecovery is not true.

Rationale: Administrators must always have a secure, controlled way to recover encrypted data when users cannot access it.

Impact: A Data Recovery Agent must be configured for fixed drives; recovery requires controlled access to its private key.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Fixed Data Drives\Choose how BitLocker-protected fixed drives can be recovered and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v FDVRecovery /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 3.6 Encrypt Data on End-User Devices
  • NIST SP 800-53 Rev. 5: SC-28 Protection of Information at Rest
  • NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
  • CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Recovery Options Are Omitted From The BitLocker Setup Wizard For Fixed Data Drives

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.1

Finding: Recovery options are not omitted from the BitLocker setup wizard for fixed data drives.

Checks whether users are prevented from choosing recovery options during BitLocker setup of fixed data drives.

This rule fails when fdvHideRecoveryPage is not HIDE.

Rationale: Recovery options should be dictated by policy rather than left to users, ensuring a controlled recovery path.

Impact: Users cannot manually select recovery options for fixed drives in the BitLocker setup wizard.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Fixed Data Drives\Choose how BitLocker-protected fixed drives can be recovered: Omit recovery options from the BitLocker setup wizard and set it to Enabled: True (checked).

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v FDVHideRecoveryPage /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 3.6 Encrypt Data on End-User Devices
  • NIST SP 800-53 Rev. 5: SC-28 Protection of Information at Rest
  • NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
  • CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Smart Card Use For BitLocker Fixed Data Drives Is Enabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.1

Finding: Smart card use for BitLocker fixed data drives is not enabled.

Checks whether smart cards may be used to authenticate access to BitLocker fixed data drives.

This rule fails when fdvAllowUserCert is not true.

Rationale: A drive protected only by a guessable secret or an auto-unlock can be compromised if lost or stolen; smart cards raise the bar.

Impact: None - this is the default behavior; users may use smart cards to unlock fixed data drives.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Fixed Data Drives\Configure use of smart cards on fixed data drives and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v FDVAllowUserCert /t REG_DWORD /d 1 /f
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Smart Card Use Is Required For BitLocker Fixed Data Drives

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.1

Finding: Smart card use is not required for BitLocker fixed data drives.

Checks whether a smart card is required to authenticate access to BitLocker fixed data drives.

This rule fails when fdvEnforceUserCert is not REQUIRED.

Rationale: Requiring a smart card removes weaker unlock options and ties drive access to PKI-backed credentials.

Impact: Smart cards are required to unlock fixed data drives; users must authenticate with the card each restart.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Fixed Data Drives\Configure use of smart cards on fixed data drives: Require use of smart cards on fixed data drives and set it to Enabled: True (checked).

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v FDVEnforceUserCert /t REG_DWORD /d 1 /f
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure A 256-Bit Recovery Key Is Not Allowed For BitLocker-Protected Operating System Drives

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.2

Finding: A 256-bit recovery key is allowed for BitLocker-protected operating system drives.

Checks whether a 256-bit recovery key may be generated for BitLocker-protected OS drives.

This rule fails when osRecoveryKey is not DISALLOW.

Rationale: Standardizing OS-drive recovery on the 48-digit password avoids reliance on key files that are easily lost or copied.

Impact: A 256-bit recovery key is not permitted for the OS drive; users must be domain-connected to turn on BitLocker.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Operating System Drives\Choose how BitLocker-protected operating system drives can be recovered: Recovery Key and set it to Enabled: Do not allow 256-bit recovery key.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v OSRecoveryKey /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 3.6 Encrypt Data on End-User Devices
  • NIST SP 800-53 Rev. 5: SC-28 Protection of Information at Rest
  • NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
  • CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure A 48-Digit Recovery Password Is Required For BitLocker-Protected Operating System Drives

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.2

Finding: A 48-digit recovery password is not required for BitLocker-protected operating system drives.

Checks whether a 48-digit recovery password is required for BitLocker-protected OS drives.

This rule fails when osRecoveryPassword is not REQUIRE.

Rationale: A required recovery password ensures a reliable way back into the encrypted OS volume if the primary unlock method fails.

Impact: A 48-digit recovery password is required for the OS drive; users must be domain-connected to turn on BitLocker.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Operating System Drives\Choose how BitLocker-protected operating system drives can be recovered: Recovery Password and set it to Enabled: Require 48-digit recovery password.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v OSRecoveryPassword /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 3.6 Encrypt Data on End-User Devices
  • NIST SP 800-53 Rev. 5: SC-28 Protection of Information at Rest
  • NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
  • CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure A Data Recovery Agent Is Not Allowed For BitLocker-Protected Operating System Drives

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.2

Finding: A Data Recovery Agent is allowed for BitLocker-protected operating system drives.

Checks whether a Data Recovery Agent may be used to recover BitLocker-protected OS drives.

This rule fails when osManageDRA is not DISALLOW.

Rationale: Recovery of the OS volume should rely on a backed-up recovery password rather than a DRA private key that could itself be abused.

Impact: A Data Recovery Agent is not permitted for the OS drive; users must be domain-connected to turn on BitLocker.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Operating System Drives\Choose how BitLocker-protected operating system drives can be recovered: Allow data recovery agent and set it to Enabled: False (unchecked).

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v OSManageDRA /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 3.6 Encrypt Data on End-User Devices
  • NIST SP 800-53 Rev. 5: SC-28 Protection of Information at Rest
  • NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
  • CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Enhanced PINs For BitLocker Startup Are Allowed

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.2

Finding: Enhanced PINs for BitLocker startup are not allowed.

Checks whether enhanced startup PINs (letters, symbols, numbers, spaces) are allowed for BitLocker.

This rule fails when useEnhancedPin is not true.

Rationale: A numeric-only PIN provides far less entropy, making brute-force attacks against startup authentication more feasible.

Impact: All newly set BitLocker startup PINs will be enhanced PINs.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Operating System Drives\Allow enhanced PINs for startup and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v UseEnhancedPin /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 5.2 Use Unique Passwords
  • NIST SP 800-53 Rev. 5: IA-5 Authenticator Management
  • NIST SP 800-171 Rev. 2: 3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
  • CMMC 2.0 Level 2: IA.L2-3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
  • PCI DSS v4.0.1: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 8.3.5 Use unique initial passwords and force change on first use; 8.3.6 Enforce 12-character minimum password length with letters and numbers; 8.6.3 Rotate and harden passwords for application and system-level accounts
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Hardware-Based Encryption For BitLocker Operating System Drives Is Disabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.2

Finding: Hardware-based encryption is used for BitLocker operating system drives.

Checks whether BitLocker uses hardware-based encryption for the operating system drive.

This rule fails when osHardwareEncryption is not false.

Rationale: Hardware-based encryption on some self-encrypting drives has firmware vulnerabilities; software encryption avoids that risk.

Impact: None - this is the default behavior; BitLocker uses software-based encryption for the OS drive.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Operating System Drives\Configure use of hardware-based encryption for operating system drives and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v OSHardwareEncryption /t REG_DWORD /d 0 /f
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Recovery Of BitLocker-Protected Operating System Drives Is Configured

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.2

Finding: Recovery of BitLocker-protected operating system drives is not configured.

Checks whether recovery options for BitLocker-protected OS drives are governed by policy.

This rule fails when osRecovery is not true.

Rationale: If the OS volume fails integrity checks or the key is lost and recovery info was not backed up, the user may be permanently denied access to the encrypted data.

Impact: Users must be domain-connected to turn on BitLocker; this configuration is not FIPS compliant.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Operating System Drives\Choose how BitLocker-protected operating system drives can be recovered and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v OSRecovery /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 3.6 Encrypt Data on End-User Devices
  • NIST SP 800-53 Rev. 5: SC-28 Protection of Information at Rest
  • NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
  • CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Recovery Options Are Omitted From The BitLocker Setup Wizard For Operating System Drives

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.2

Finding: Recovery options are not omitted from the BitLocker setup wizard for operating system drives.

Checks whether users are prevented from choosing recovery options during BitLocker setup of OS drives.

This rule fails when osHideRecoveryPage is not HIDE.

Rationale: Recovery options should be dictated by policy rather than left to users, ensuring a controlled recovery path.

Impact: Users cannot manually select recovery options for the OS drive in the BitLocker setup wizard.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Operating System Drives\Choose how BitLocker-protected operating system drives can be recovered: Omit recovery options from the BitLocker setup wizard and set it to Enabled: True (checked).

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v OSHideRecoveryPage /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 3.6 Encrypt Data on End-User Devices
  • NIST SP 800-53 Rev. 5: SC-28 Protection of Information at Rest
  • NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
  • CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Secure Boot For BitLocker Integrity Validation Is Allowed

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.2

Finding: Secure Boot is not allowed for BitLocker integrity validation.

Checks whether Secure Boot may serve as the platform integrity provider for BitLocker OS drives.

This rule fails when osAllowSecureBootForIntegrity is not true.

Rationale: Secure Boot loads only firmware signed by authorized publishers during startup, reducing the risk of rootkits and boot-time malware.

Impact: None - this is the default behavior; BitLocker uses Secure Boot for integrity when capable.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Operating System Drives\Allow Secure Boot for integrity validation and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v OSAllowSecureBootForIntegrity /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 10.5 Enable Anti-Exploitation Features
  • NIST SP 800-53 Rev. 5: SI-16 Memory Protection
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure A 256-Bit Recovery Key Is Not Allowed For BitLocker-Protected Removable Data Drives

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.3

Finding: A 256-bit recovery key is allowed for BitLocker-protected removable data drives.

Checks whether a 256-bit recovery key may be generated for BitLocker removable data drives.

This rule fails when rdvRecoveryKey is not DISALLOW.

Rationale: Restricting user-chosen recovery secrets on portable media reduces the chance of weak, lost, or copied recovery material accompanying a stolen drive.

Impact: A 256-bit recovery key will not be permitted for removable drives.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Removable Data Drives\Choose how BitLocker-protected removable drives can be recovered: Recovery Key and set it to Enabled: Do not allow 256-bit recovery key.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v RDVRecoveryKey /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 3.9 Encrypt Data on Removable Media
  • NIST SP 800-53 Rev. 5: MP-5 Media Transport; MP-7 Media Use
  • NIST SP 800-171 Rev. 2: 3.8.7 Control the use of removable media on system components
  • CMMC 2.0 Level 2: MP.L2-3.8.7 Control the use of removable media on system components
  • PCI DSS v4.0.1: 3.5.1.2 Restrict disk- or partition-level PAN encryption to removable media or paired controls
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure A 48-Digit Recovery Password Is Not Allowed For BitLocker-Protected Removable Data Drives

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.3

Finding: A 48-digit recovery password is allowed for BitLocker-protected removable data drives.

Checks whether a 48-digit recovery password may be generated for BitLocker removable data drives.

This rule fails when rdvRecoveryPassword is not DISALLOW.

Rationale: Restricting user-chosen recovery secrets on portable media reduces the chance of weak, lost, or copied recovery material accompanying a stolen drive.

Impact: A 48-digit recovery password will not be permitted for removable drives.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Removable Data Drives\Choose how BitLocker-protected removable drives can be recovered: Recovery Password and set it to Enabled: Do not allow 48-digit recovery password.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v RDVRecoveryPassword /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 3.9 Encrypt Data on Removable Media
  • NIST SP 800-53 Rev. 5: MP-5 Media Transport; MP-7 Media Use
  • NIST SP 800-171 Rev. 2: 3.8.7 Control the use of removable media on system components
  • CMMC 2.0 Level 2: MP.L2-3.8.7 Control the use of removable media on system components
  • PCI DSS v4.0.1: 3.5.1.2 Restrict disk- or partition-level PAN encryption to removable media or paired controls
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure A Data Recovery Agent Is Allowed For BitLocker-Protected Removable Data Drives

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.3

Finding: A Data Recovery Agent is not allowed for BitLocker-protected removable data drives.

Checks whether a Data Recovery Agent may be used to recover BitLocker-protected removable data drives.

This rule fails when rdvManageDRA is not ALLOW.

Rationale: Administrators must always have a secure, controlled way to recover encrypted data when users cannot access it.

Impact: None - this is the default behavior; a DRA is allowed for removable drives.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Removable Data Drives\Choose how BitLocker-protected removable drives can be recovered: Allow data recovery agent and set it to Enabled: True (checked).

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v RDVManageDRA /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 3.9 Encrypt Data on Removable Media
  • NIST SP 800-53 Rev. 5: MP-5 Media Transport; MP-7 Media Use
  • NIST SP 800-171 Rev. 2: 3.8.7 Control the use of removable media on system components
  • CMMC 2.0 Level 2: MP.L2-3.8.7 Control the use of removable media on system components
  • PCI DSS v4.0.1: 3.5.1.2 Restrict disk- or partition-level PAN encryption to removable media or paired controls
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Access To BitLocker-Protected Removable Data Drives From Earlier Windows Versions Is Disabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.3

Finding: BitLocker-protected removable data drives are accessible from earlier versions of Windows.

REG_SZ

This rule fails when rdvDiscoveryVolumeType is not false.

Rationale: Checks whether FAT-formatted BitLocker removable data drives can be unlocked on legacy Windows via the BitLocker To Go Reader.

Impact: The BitLocker To Go Reader placed on the unencrypted portion of the drive is, like any app, subject to spoofing and could propagate malware.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Removable Data Drives\Allow access to BitLocker-protected removable data drives from earlier versions of Windows and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v RDVDiscoveryVolumeType /t FAT BitLocker removable drives cannot be unlocked on legacy Windows and BitLockerToGo.exe is not installed. /d "" /f
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Cross-Organization Write Access For BitLocker Removable Drives Is Not Denied

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.3

Finding: Write access to BitLocker removable drives configured in another organization is denied.

Checks whether the computer may write to BitLocker removable drives that were configured in another organization.

This rule fails when rdvDenyCrossOrg is not false.

Rationale: Denying cross-organization write access can hinder legitimate encrypted data sharing between business partners.

Impact: None - this is the default behavior; write access to cross-organization BitLocker removable drives is permitted.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Removable Data Drives\Deny write access to removable drives not protected by BitLocker: Do not allow write access to devices configured in another organization and set it to Enabled: False (unchecked).

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v RDVDenyCrossOrg /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 3.9 Encrypt Data on Removable Media
  • NIST SP 800-53 Rev. 5: MP-5 Media Transport; MP-7 Media Use
  • NIST SP 800-171 Rev. 2: 3.8.7 Control the use of removable media on system components
  • CMMC 2.0 Level 2: MP.L2-3.8.7 Control the use of removable media on system components
  • PCI DSS v4.0.1: 3.5.1.2 Restrict disk- or partition-level PAN encryption to removable media or paired controls
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Hardware-Based Encryption For BitLocker Removable Data Drives Is Disabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.3

Finding: Hardware-based encryption is used for BitLocker removable data drives.

Checks whether BitLocker uses hardware-based encryption for removable data drives.

This rule fails when rdvHardwareEncryption is not false.

Rationale: Hardware-based encryption on some self-encrypting drives has firmware vulnerabilities; software encryption avoids that risk.

Impact: None - this is the default behavior; BitLocker uses software-based encryption for removable drives.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Removable Data Drives\Configure use of hardware-based encryption for removable data drives and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v RDVHardwareEncryption /t REG_DWORD /d 0 /f
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Password Unlock For BitLocker Removable Data Drives Is Disabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.3

Finding: Password unlock is permitted for BitLocker removable data drives.

Checks whether a password may be used to unlock BitLocker-protected removable data drives.

This rule fails when rdvPassphrase is not false.

Rationale: BitLocker passwords lack TPM anti-hammering protection, so there is no throttle against rapid brute-force guessing.

Impact: The password option will not be available when configuring BitLocker for removable drives.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Removable Data Drives\Configure use of passwords for removable data drives and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v RDVPassphrase /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 5.2 Use Unique Passwords
  • NIST SP 800-53 Rev. 5: IA-5 Authenticator Management
  • NIST SP 800-171 Rev. 2: 3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
  • CMMC 2.0 Level 2: IA.L2-3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
  • PCI DSS v4.0.1: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 8.3.5 Use unique initial passwords and force change on first use; 8.3.6 Enforce 12-character minimum password length with letters and numbers; 8.6.3 Rotate and harden passwords for application and system-level accounts
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Recovery Of BitLocker-Protected Removable Data Drives Is Configured

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.3

Finding: Recovery of BitLocker-protected removable data drives is not configured.

Checks whether recovery options for BitLocker-protected removable data drives are governed by policy.

This rule fails when rdvRecovery is not true.

Rationale: Administrators must always have a secure, controlled way to recover encrypted data when users cannot access it.

Impact: A Data Recovery Agent must be configured for removable drives; recovery requires controlled access to its private key.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Removable Data Drives\Choose how BitLocker-protected removable drives can be recovered and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v RDVRecovery /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 3.9 Encrypt Data on Removable Media
  • NIST SP 800-53 Rev. 5: MP-5 Media Transport; MP-7 Media Use
  • NIST SP 800-171 Rev. 2: 3.8.7 Control the use of removable media on system components
  • CMMC 2.0 Level 2: MP.L2-3.8.7 Control the use of removable media on system components
  • PCI DSS v4.0.1: 3.5.1.2 Restrict disk- or partition-level PAN encryption to removable media or paired controls
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Recovery Options Are Omitted From The BitLocker Setup Wizard For Removable Data Drives

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.3

Finding: Recovery options are not omitted from the BitLocker setup wizard for removable data drives.

Checks whether users are prevented from choosing recovery options during BitLocker setup of removable data drives.

This rule fails when rdvHideRecoveryPage is not HIDE.

Rationale: Recovery options should be dictated by policy rather than left to users, ensuring a controlled recovery path.

Impact: Users cannot manually select recovery options for removable drives in the BitLocker setup wizard.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Removable Data Drives\Choose how BitLocker-protected removable drives can be recovered: Omit recovery options from the BitLocker setup wizard and set it to Enabled: True (checked).

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v RDVHideRecoveryPage /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 3.9 Encrypt Data on Removable Media
  • NIST SP 800-53 Rev. 5: MP-5 Media Transport; MP-7 Media Use
  • NIST SP 800-171 Rev. 2: 3.8.7 Control the use of removable media on system components
  • CMMC 2.0 Level 2: MP.L2-3.8.7 Control the use of removable media on system components
  • PCI DSS v4.0.1: 3.5.1.2 Restrict disk- or partition-level PAN encryption to removable media or paired controls
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Smart Card Use For BitLocker Removable Data Drives Is Enabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.3

Finding: Smart card use for BitLocker removable data drives is not enabled.

Checks whether smart cards may be used to authenticate access to BitLocker removable data drives.

This rule fails when rdvAllowUserCert is not true.

Rationale: A drive protected only by a guessable secret or an auto-unlock can be compromised if lost or stolen; smart cards raise the bar.

Impact: None - this is the default behavior; users may use smart cards to unlock removable data drives.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Removable Data Drives\Configure use of smart cards on removable data drives and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v RDVAllowUserCert /t REG_DWORD /d 1 /f
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Smart Card Use Is Required For BitLocker Removable Data Drives

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.3

Finding: Smart card use is not required for BitLocker removable data drives.

Checks whether a smart card is required to authenticate access to BitLocker removable data drives.

This rule fails when rdvEnforceUserCert is not REQUIRED.

Rationale: Requiring a smart card removes weaker unlock options and ties drive access to PKI-backed credentials.

Impact: Smart cards are required to unlock removable data drives; users must authenticate with the card each restart.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Removable Data Drives\Configure use of smart cards on removable data drives: Require use of smart cards on removable data drives and set it to Enabled: True (checked).

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v RDVEnforceUserCert /t REG_DWORD /d 1 /f
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Write Access To Removable Drives Not Protected By BitLocker Is Denied

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.3

Finding: Write access is permitted to removable drives not protected by BitLocker.

Checks whether removable data drives must be BitLocker-protected before the computer can write to them.

This rule fails when rdvDenyWriteAccess is not true.

Rationale: Without this control, users may save sensitive data to removable media that was never encrypted.

Impact: Removable drives not protected by BitLocker are mounted read-only; protected drives get read/write access.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Removable Data Drives\Deny write access to removable drives not protected by BitLocker and set it to Enabled.

From the command line:

reg add "HKLM\SYSTEM\CurrentControlSet\Policies\Microsoft\FVE" /v RDVDenyWriteAccess /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 3.9 Encrypt Data on Removable Media
  • NIST SP 800-53 Rev. 5: MP-5 Media Transport; MP-7 Media Use
  • NIST SP 800-171 Rev. 2: 3.8.7 Control the use of removable media on system components
  • CMMC 2.0 Level 2: MP.L2-3.8.7 Control the use of removable media on system components
  • PCI DSS v4.0.1: 3.5.1.2 Restrict disk- or partition-level PAN encryption to removable media or paired controls
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

18.10.11 Camera

Ensure Use Of The Camera Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.11

Finding: Use of the camera is permitted.

Checks whether camera devices on the machine are permitted for use.

This rule fails when allowCamera is not false.

Rationale: In high-security environments a camera poses privacy and data-exfiltration risks and should be disabled.

Impact: Users will not be able to use the camera on the system.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Camera\Allow Use of Camera and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Camera" /v AllowCamera /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

18.10.13 Cloud Content

Ensure Cloud Consumer Account State Content Is Turned Off

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.13

Finding: Cloud consumer account state content is allowed in Windows experiences.

Checks whether cloud consumer account state content is allowed across Windows experiences.

This rule fails when disableConsumerAccountStateContent is not true.

Rationale: Using consumer accounts in an enterprise-managed environment can lead to data leakage.

Impact: Windows experiences present default fallback content instead of consumer-account content.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Cloud Content\Turn off cloud consumer account state content and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\CloudContent" /v DisableConsumerAccountStateContent /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 5.6 Centralize Account Management
  • NIST SP 800-53 Rev. 5: AC-2 Account Management
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Cloud Optimized Content Is Turned Off

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.13

Finding: Cloud optimized content is allowed in Windows experiences.

Checks whether cloud-optimized content is turned off across Windows experiences.

This rule fails when disableCloudOptimizedContent is not true.

Rationale: Data should not be shared with third parties without explicit consent, as it may contain sensitive information.

Impact: Windows experiences present default fallback content instead of cloud-optimized content.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Cloud Content\Turn off cloud optimized content and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\CloudContent" /v DisableCloudOptimizedContent /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Microsoft Consumer Experiences Are Turned Off

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.13

Finding: Microsoft consumer experiences are enabled.

Checks whether consumer experiences such as suggested apps and Microsoft-account notifications are turned off.

This rule fails when disableWindowsConsumerFeatures is not true.

Rationale: Silent app installs in an enterprise environment, especially ones that send data to third parties, are poor security practice.

Impact: Users no longer see personalized Microsoft recommendations or Microsoft-account notifications.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Cloud Content\Turn off Microsoft consumer experiences and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\CloudContent" /v DisableWindowsConsumerFeatures /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

18.10.14 Connect

Ensure A PIN Is Required For Wireless Display Pairing

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.14

Finding: A PIN is not required for wireless display pairing.

Checks whether a PIN is required when pairing to a wireless display device.

This rule fails when requirePinForPairing is not one of FIRST_TIME, ALWAYS.

Rationale: Without a required pairing PIN, wireless display devices can be paired without authorization, increasing risk of misuse.

Impact: The pairing ceremony for new wireless display devices will require a PIN.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Connect\Require pin for pairing and set it to Enabled: First Time (or Always).

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Connect" /v RequirePinForPairing /t REG_DWORD /d 1 /f
Risk
Unprotected Principal
MITRE ATT&CK tactic
Initial Access (TA0001)

18.10.15 Credential User Interface

Ensure Administrator Accounts Are Not Enumerated On Elevation

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.15

Finding: Administrator accounts are enumerated during elevation.

Checks whether administrator accounts are listed when a user attempts to elevate an application.

This rule fails when enumerateAdministrators is not false.

Rationale: Displaying the administrator account list makes it slightly easier for a local attacker to target and crack those accounts.

Impact: None - this is the default behavior; users must always type a username and password to elevate.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Credential User Interface\Enumerate administrator accounts on elevation and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\CredUI" /v EnumerateAdministrators /t REG_DWORD /d 0 /f
Risk
Unprotected Principal
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure Security Questions For Local Accounts Are Prevented

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.15

Finding: Security questions can be used to reset local account passwords.

Checks whether security questions can be used to reset local account passwords.

This rule fails when noLocalPasswordResetQuestions is not true.

Rationale: Security questions are often easily guessed or researched via social media, letting an attacker reset a local password and take over the account.

Impact: Local accounts cannot set up or use security questions to reset their passwords.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Credential User Interface\Prevent the use of security questions for local accounts and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v NoLocalPasswordResetQuestions /t REG_DWORD /d 1 /f
Risk
Unprotected Principal
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure The Password Reveal Button Is Not Displayed

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.15

Finding: The password reveal button is displayed in password entry fields.

Checks whether the password reveal button is shown in password entry experiences.

This rule fails when disablePasswordReveal is not true.

Rationale: The reveal button can display a typed password on screen, where a nearby observer could read it.

Impact: The password reveal button will not appear after a user types a password.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Credential User Interface\Do not display the password reveal button and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\CredUI" /v DisablePasswordReveal /t REG_DWORD /d 1 /f
Risk
Unprotected Principal
MITRE ATT&CK tactic
Credential Access (TA0006)

18.10.16 Data Collection and Preview Builds

Ensure Authenticated Proxy Usage For The Connected User Experience And Telemetry Service Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.16

Finding: The Connected User Experience and Telemetry service may use an authenticated proxy.

Checks whether the Connected User Experience and Telemetry service is blocked from automatically using an authenticated proxy.

This rule fails when disableEnterpriseAuthProxy is not true.

Rationale: Data should not be shared with third parties without explicit consent, as it may contain sensitive information.

Impact: The telemetry service is blocked from automatically using an authenticated proxy to send data to Microsoft.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Data Collection and Preview Builds\Configure Authenticated Proxy usage for the Connected User Experience and Telemetry service and set it to Enabled: Disable Authenticated Proxy usage.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DataCollection" /v DisableEnterpriseAuthProxy /t REG_DWORD /d 1 /f
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Diagnostic Data Is Limited To Required Or Off

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.16

Finding: Diagnostic data is set above the required level.

Checks the amount of diagnostic and usage data the device reports to Microsoft.

This rule fails when allowTelemetry is not one of SECURITY, BASIC.

Rationale: Sending optional or full diagnostic data may transmit sensitive information to a third party without explicit consent.

Impact: The device sends at most the required diagnostic data (or none), limiting data shared with Microsoft.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Data Collection and Preview Builds\Allow Diagnostic Data and set it to Enabled: Diagnostic data off (or Send required diagnostic data).

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DataCollection" /v AllowTelemetry /t REG_DWORD /d 0 /f
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Diagnostic Log Collection Is Limited

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.16

Finding: Diagnostic log collection is not limited.

Checks whether the collection of additional diagnostic logs for troubleshooting is limited.

This rule fails when limitDiagnosticLogCollection is not true.

Rationale: Data should not be shared with third parties without explicit consent, as it may contain sensitive information.

Impact: Diagnostic logs and crash dumps will not be collected for transmission to Microsoft.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Data Collection and Preview Builds\Limit Diagnostic Log Collection and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DataCollection" /v LimitDiagnosticLogCollection /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Dump Collection Is Limited

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.16

Finding: Dump collection is not limited.

Checks whether the type of memory dumps collected for troubleshooting is limited.

This rule fails when limitDumpCollection is not true.

Rationale: Data should not be shared with third parties without explicit consent, as memory dumps may contain sensitive information.

Impact: Error reporting is limited to kernel mini and user-mode triage dumps, reducing sensitive data sent to Microsoft.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Data Collection and Preview Builds\Limit Dump Collection and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DataCollection" /v LimitDumpCollection /t REG_DWORD /d 1 /f
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Feedback Notifications Are Not Shown

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.16

Finding: Feedback notifications from Microsoft are shown.

Checks whether devices are prevented from showing Microsoft feedback questions.

This rule fails when doNotShowFeedbackNotifications is not true.

Rationale: Data should not be shared with third parties without explicit consent, as it may contain sensitive information.

Impact: Users no longer see feedback notifications through the Windows Feedback app.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Data Collection and Preview Builds\Do not show feedback notifications and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DataCollection" /v DoNotShowFeedbackNotifications /t REG_DWORD /d 1 /f
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure OneSettings Auditing Is Enabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.16

Finding: OneSettings auditing is not enabled.

Checks whether Windows records attempts to connect with the OneSettings service to the Event Log.

This rule fails when enableOneSettingsAuditing is not true.

Rationale: Without these records it may be difficult to determine the root cause of problems or to detect unauthorized activity.

Impact: Windows records OneSettings connection attempts to the Privacy-Auditing operational log channel.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Data Collection and Preview Builds\Enable OneSettings Auditing and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DataCollection" /v EnableOneSettingsAuditing /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 8.5 Collect Detailed Audit Logs
  • NIST SP 800-53 Rev. 5: AU-3 Content of Audit Records; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation; SI-4 System Monitoring
  • PCI DSS v4.0.1: 9.4.5 Keep a log-based inventory of electronic media holding cardholder data; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.5 Record account creation, privilege elevation, and other credential changes
Risk
High Profile Threat
MITRE ATT&CK tactic
Defense Evasion (TA0005)

18.10.17 Delivery Optimization

Ensure Delivery Optimization Download Mode Is Not Set To Internet

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.17

Finding: Delivery Optimization download mode is set to Internet.

Checks the Delivery Optimization download method used for Windows Updates, apps, and app updates.

This rule fails when doDownloadMode is INTERNET (or is not set).

Rationale: Updates should come only from Microsoft or a trusted internal peer, not from arbitrary peers across the public Internet.

Impact: Machines will not download updates from peers on the Internet.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Delivery Optimization\Download Mode and set it to any value other than Enabled: Internet (3).

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeliveryOptimization" /v DODownloadMode /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 7.3 Perform Automated Operating System Patch Management
  • NIST SP 800-53 Rev. 5: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation
Risk
External Attack Surface
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

18.10.18 Desktop App Installer

Ensure App Installer Experimental Features Are Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.18

Finding: App Installer experimental features are enabled.

Checks whether users can enable experimental features in the Windows Package Manager.

This rule fails when enableExperimentalFeatures is not false.

Rationale: Users should not have access to unfinished, experimental package-manager features.

Impact: Users cannot enable experimental winget features.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Desktop App Installer\Enable App Installer Experimental Features and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\AppInstaller" /v EnableExperimentalFeatures /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Insecure Application
MITRE ATT&CK tactic
Execution (TA0002)

Ensure App Installer Hash Override Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.18

Finding: App Installer hash override is enabled.

Checks whether users can override SHA256 security validation in the Windows Package Manager.

This rule fails when enableHashOverride is not false.

Rationale: Users should not be able to bypass package integrity (SHA256) validation.

Impact: Users cannot override the SHA256 security validation.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Desktop App Installer\Enable App Installer Hash Override and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\AppInstaller" /v EnableHashOverride /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Insecure Application
MITRE ATT&CK tactic
Execution (TA0002)

Ensure App Installer Local Archive Malware Scan Override Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.18

Finding: App Installer local archive malware scan override is enabled.

Checks whether malware scans can be overridden when installing a local archive file via winget.

This rule fails when enableLocalArchiveMalwareScanOverride is not false.

Rationale: Users should not be able to bypass malware scanning when installing archived packages.

Impact: Users cannot override malware scans when installing an archived file.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Desktop App Installer\Enable App Installer Local Archive Malware Scan Override and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\AppInstaller" /v EnableLocalArchiveMalwareScanOverride /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Insecure Application
MITRE ATT&CK tactic
Execution (TA0002)

Ensure App Installer Microsoft Store Source Certificate Validation Bypass Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.18

Finding: App Installer Microsoft Store source certificate validation bypass is enabled.

Checks whether winget certificate-pinning validation of the Microsoft Store source can be bypassed.

This rule fails when enableBypassCertificatePinningForMicrosoftStore is not false.

Rationale: The Microsoft Store source must be validated so that a spoofed source cannot be substituted.

Impact: Source certificate validation cannot be bypassed when winget connects to the Microsoft Store.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Desktop App Installer\Enable App Installer Microsoft Store Source Certificate Validation Bypass and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\AppInstaller" /v EnableBypassCertificatePinningForMicrosoftStore /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Insecure Application
MITRE ATT&CK tactic
Execution (TA0002)

Ensure The App Installer Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.18

Finding: The App Installer (Windows Package Manager) is enabled.

Checks whether standard users have access to the Windows Package Manager (winget).

This rule fails when enableAppInstaller is not false.

Rationale: The winget command-line tool can discover, install, and distribute software; standard users should not have access to such development tools.

Impact: Users cannot use winget to discover, install, upgrade, remove, configure, or distribute apps.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Desktop App Installer\Enable App Installer and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\AppInstaller" /v EnableAppInstaller /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Insecure Application
MITRE ATT&CK tactic
Execution (TA0002)

Ensure The App Installer Ms-Appinstaller Protocol Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.18

Finding: The App Installer ms-appinstaller protocol is enabled.

Checks whether users can install packages from a website via the ms-appinstaller protocol link.

This rule fails when enableMSAppInstallerProtocol is not false.

Rationale: Clicking an unknown or malicious ms-appinstaller link on a website could install malware on the system.

Impact: Users cannot use the ms-appinstaller protocol to install apps by clicking a website link.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Desktop App Installer\Enable App Installer ms-appinstaller protocol and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\AppInstaller" /v EnableMSAppInstallerProtocol /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Insecure Application
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Windows Package Manager Command Line Interfaces Are Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.18

Finding: Windows Package Manager command line interfaces are enabled.

Checks whether users can drive the Windows Package Manager through a CLI (Windows CLI or PowerShell).

This rule fails when enableWindowsPackageManagerCommandLineInterfaces is not false.

Rationale: The winget command-line tool can discover, install, and distribute software; standard users should not have access to such development tools.

Impact: Users cannot use the Windows Package Manager through Windows CLI or PowerShell.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Desktop App Installer\Enable Windows Package Manager command line interfaces and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\AppInstaller" /v EnableWindowsPackageManagerCommandLineInterfaces /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Insecure Application
MITRE ATT&CK tactic
Execution (TA0002)

18.10.26 Event Log Service

Ensure The Application Event Log Maximum Size Is At Least 32,768 KB

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.26.1

Finding: The Application event log maximum size is below 32,768 KB.

Checks the maximum size (KB) configured for the Application event log.

This rule fails when eventLogApplicationMaxSize is less than 32768.

Rationale: Too small a log lets an attacker overwrite evidence of an attack by generating many extraneous events; a larger log retains more forensic history.

Impact: A larger maximum log size retains more events before the oldest entries are overwritten.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Event Log Service\Application\Specify the maximum log file size (KB) and set it to Enabled: 32,768 or greater.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\EventLog\Application" /v MaxSize /t REG_DWORD /d 32768 /f
Framework mappings
  • CIS Controls v8: 8.3 Ensure Adequate Audit Log Storage
  • NIST SP 800-53 Rev. 5: AU-4 Audit Log Storage Capacity; AU-5 Response to Audit Logging Process Failures
Risk
High Profile Threat
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure The Application Event Log Overwrites Events When Full

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.26.1

Finding: The Application event log is configured to retain events instead of overwriting when full.

REG_SZ

This rule fails when eventLogApplicationRetention is not false.

Rationale: Checks Event Log behavior when the Application log reaches its maximum size; Disabled lets new events overwrite the oldest events rather than halting logging.

Impact: If new events stop being recorded it may be difficult or impossible to determine the root cause of problems or to detect an attacker's activity.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Event Log Service\Application\Control Event Log behavior when the log file reaches its maximum size and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\EventLog\Application" /v Retention /t None - this is the default behavior; new events overwrite old events when the log is full. /d 0 /f
Framework mappings
  • CIS Controls v8: 8.3 Ensure Adequate Audit Log Storage
  • NIST SP 800-53 Rev. 5: AU-4 Audit Log Storage Capacity; AU-5 Response to Audit Logging Process Failures
Risk
High Profile Threat
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure The Security Event Log Maximum Size Is At Least 196,608 KB

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.26.2

Finding: The Security event log maximum size is below 196,608 KB.

Checks the maximum size (KB) configured for the Security event log.

This rule fails when eventLogSecurityMaxSize is less than 196608.

Rationale: Too small a log lets an attacker overwrite evidence of an attack by generating many extraneous events; a larger log retains more forensic history.

Impact: A larger maximum log size retains more events before the oldest entries are overwritten.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Event Log Service\Security\Specify the maximum log file size (KB) and set it to Enabled: 196,608 or greater.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\EventLog\Security" /v MaxSize /t REG_DWORD /d 196608 /f
Framework mappings
  • CIS Controls v8: 8.3 Ensure Adequate Audit Log Storage
  • NIST SP 800-53 Rev. 5: AU-4 Audit Log Storage Capacity; AU-5 Response to Audit Logging Process Failures
Risk
High Profile Threat
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure The Security Event Log Overwrites Events When Full

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.26.2

Finding: The Security event log is configured to retain events instead of overwriting when full.

REG_SZ

This rule fails when eventLogSecurityRetention is not false.

Rationale: Checks Event Log behavior when the Security log reaches its maximum size; Disabled lets new events overwrite the oldest events rather than halting logging.

Impact: If new events stop being recorded it may be difficult or impossible to determine the root cause of problems or to detect an attacker's activity.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Event Log Service\Security\Control Event Log behavior when the log file reaches its maximum size and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\EventLog\Security" /v Retention /t None - this is the default behavior; new events overwrite old events when the log is full. /d 0 /f
Framework mappings
  • CIS Controls v8: 8.3 Ensure Adequate Audit Log Storage
  • NIST SP 800-53 Rev. 5: AU-4 Audit Log Storage Capacity; AU-5 Response to Audit Logging Process Failures
Risk
High Profile Threat
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure The Setup Event Log Maximum Size Is At Least 32,768 KB

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.26.3

Finding: The Setup event log maximum size is below 32,768 KB.

Checks the maximum size (KB) configured for the Setup event log.

This rule fails when eventLogSetupMaxSize is less than 32768.

Rationale: Too small a log lets an attacker overwrite evidence of an attack by generating many extraneous events; a larger log retains more forensic history.

Impact: A larger maximum log size retains more events before the oldest entries are overwritten.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Event Log Service\Setup\Specify the maximum log file size (KB) and set it to Enabled: 32,768 or greater.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\EventLog\Setup" /v MaxSize /t REG_DWORD /d 32768 /f
Framework mappings
  • CIS Controls v8: 8.3 Ensure Adequate Audit Log Storage
  • NIST SP 800-53 Rev. 5: AU-4 Audit Log Storage Capacity; AU-5 Response to Audit Logging Process Failures
Risk
High Profile Threat
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure The Setup Event Log Overwrites Events When Full

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.26.3

Finding: The Setup event log is configured to retain events instead of overwriting when full.

REG_SZ

This rule fails when eventLogSetupRetention is not false.

Rationale: Checks Event Log behavior when the Setup log reaches its maximum size; Disabled lets new events overwrite the oldest events rather than halting logging.

Impact: If new events stop being recorded it may be difficult or impossible to determine the root cause of problems or to detect an attacker's activity.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Event Log Service\Setup\Control Event Log behavior when the log file reaches its maximum size and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\EventLog\Setup" /v Retention /t None - this is the default behavior; new events overwrite old events when the log is full. /d 0 /f
Framework mappings
  • CIS Controls v8: 8.3 Ensure Adequate Audit Log Storage
  • NIST SP 800-53 Rev. 5: AU-4 Audit Log Storage Capacity; AU-5 Response to Audit Logging Process Failures
Risk
High Profile Threat
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure The System Event Log Maximum Size Is At Least 32,768 KB

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.26.4

Finding: The System event log maximum size is below 32,768 KB.

Checks the maximum size (KB) configured for the System event log.

This rule fails when eventLogSystemMaxSize is less than 32768.

Rationale: Too small a log lets an attacker overwrite evidence of an attack by generating many extraneous events; a larger log retains more forensic history.

Impact: A larger maximum log size retains more events before the oldest entries are overwritten.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Event Log Service\System\Specify the maximum log file size (KB) and set it to Enabled: 32,768 or greater.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\EventLog\System" /v MaxSize /t REG_DWORD /d 32768 /f
Framework mappings
  • CIS Controls v8: 8.3 Ensure Adequate Audit Log Storage
  • NIST SP 800-53 Rev. 5: AU-4 Audit Log Storage Capacity; AU-5 Response to Audit Logging Process Failures
Risk
High Profile Threat
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure The System Event Log Overwrites Events When Full

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.26.4

Finding: The System event log is configured to retain events instead of overwriting when full.

REG_SZ

This rule fails when eventLogSystemRetention is not false.

Rationale: Checks Event Log behavior when the System log reaches its maximum size; Disabled lets new events overwrite the oldest events rather than halting logging.

Impact: If new events stop being recorded it may be difficult or impossible to determine the root cause of problems or to detect an attacker's activity.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Event Log Service\System\Control Event Log behavior when the log file reaches its maximum size and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\EventLog\System" /v Retention /t None - this is the default behavior; new events overwrite old events when the log is full. /d 0 /f
Framework mappings
  • CIS Controls v8: 8.3 Ensure Adequate Audit Log Storage
  • NIST SP 800-53 Rev. 5: AU-4 Audit Log Storage Capacity; AU-5 Response to Audit Logging Process Failures
Risk
High Profile Threat
MITRE ATT&CK tactic
Defense Evasion (TA0005)

18.10.29 File Explorer (formerly Windows Explorer)

Ensure Data Execution Prevention For File Explorer Is Not Turned Off

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.29

Finding: Data Execution Prevention for File Explorer is turned off.

Checks whether Data Execution Prevention (DEP) for Windows Explorer is left enabled.

This rule fails when noDataExecutionPreventionForExplorer is not false.

Rationale: DEP is an important protection that limits the impact of certain malware against Explorer.

Impact: None - this is the default behavior; DEP continues to protect Explorer.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\File Explorer\Turn off Data Execution Prevention for Explorer and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Explorer" /v NoDataExecutionPrevention /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 10.5 Enable Anti-Exploitation Features
  • NIST SP 800-53 Rev. 5: SI-16 Memory Protection
Risk
Vulnerability
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Heap Termination On Corruption Is Not Turned Off

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.29

Finding: Heap termination on corruption is turned off for File Explorer.

Checks whether heap termination on corruption is left active for File Explorer.

This rule fails when noHeapTerminationOnCorruption is not false.

Rationale: Allowing an application to keep running after its session is corrupt increases the system's risk posture.

Impact: None - this is the default behavior; heap termination on corruption remains enabled.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\File Explorer\Turn off heap termination on corruption and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Explorer" /v NoHeapTerminationOnCorruption /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Vulnerability
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Shell Protocol Protected Mode Is Not Turned Off

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.29

Finding: Shell protocol protected mode is turned off.

Checks whether the shell protocol runs in protected mode, limiting applications to a restricted set of folders.

This rule fails when preXPSP2ShellProtocolBehavior is not false.

Rationale: Limiting which files and folders can be opened reduces the attack surface of the system.

Impact: None - this is the default behavior; the shell protocol stays in protected mode.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\File Explorer\Turn off shell protocol protected mode and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v PreXPSP2ShellProtocolBehavior /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Vulnerability
MITRE ATT&CK tactic
Execution (TA0002)

Ensure The Mark Of The Web Tag Is Applied To Files From Insecure Sources

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.29

Finding: The Mark of the Web tag is not applied to files copied from insecure sources.

Checks whether files sourced from insecure locations are tagged with Mark of the Web (MOTW).

This rule fails when disableMotWOnInsecurePathCopy is not false.

Rationale: MOTW ensures files from insecure locations are treated with extra caution; untagged files expose users to security risks.

Impact: None - this is the default behavior; files copied from insecure sources are tagged with MOTW.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\File Explorer\Do not apply the Mark of the Web tag to files copied from insecure sources and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Explorer" /v DisableMotWOnInsecurePathCopy /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 10.5 Enable Anti-Exploitation Features
  • NIST SP 800-53 Rev. 5: SI-16 Memory Protection
Risk
Vulnerability
MITRE ATT&CK tactic
Execution (TA0002)

18.10.36 Location and Sensors

Ensure The Location Feature Is Turned Off

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.36

Finding: The location feature is turned on.

Checks whether the Windows location feature is turned off for the computer.

This rule fails when disableLocation is not true.

Rationale: Revealing device location to software is undesirable in high-security environments.

Impact: The location feature is off, and all programs are prevented from using location information.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Location and Sensors\Turn off location and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\LocationAndSensors" /v DisableLocation /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

18.10.40 Messaging

Ensure Message Service Cloud Sync Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.40

Finding: Message Service cloud sync is allowed.

Checks whether cellular text messages may be backed up to and restored from Microsoft's cloud.

This rule fails when allowMessageSync is not false.

Rationale: Data should not be shared with third parties without explicit consent, as messages may contain sensitive information.

Impact: Cellular text messages will not be backed up to or restored from Microsoft's cloud services.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Messaging\Allow Message Service Cloud Sync and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Messaging" /v AllowMessageSync /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

18.10.41 Microsoft account

Ensure Consumer Microsoft Account User Authentication Is Blocked

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.41

Finding: Consumer Microsoft account user authentication is permitted.

Checks whether apps and services may authenticate with consumer Microsoft accounts via the Windows OnlineID and WebAccountManager APIs.

This rule fails when disableUserAuth is not true.

Rationale: Blocking consumer Microsoft accounts lets an organization keep firm control of which identities are used and helps meet compliance requirements.

Impact: Apps and services cannot start new authentications with consumer Microsoft accounts via those APIs; direct browser/OAuth sign-ins are unaffected.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft accounts\Block all consumer Microsoft account user authentication and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\MicrosoftAccount" /v DisableUserAuth /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 5.6 Centralize Account Management
  • NIST SP 800-53 Rev. 5: AC-2 Account Management
Risk
Unprotected Principal
MITRE ATT&CK tactic
Initial Access (TA0001)

18.10.43 Microsoft Defender Application Guard

Ensure Auditing Events In Microsoft Defender Application Guard Are Allowed

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.43

Finding: Auditing events in Microsoft Defender Application Guard are not allowed.

Checks whether auditing events can be collected from Microsoft Defender Application Guard.

This rule fails when auditApplicationGuard is not true.

Rationale: Application Guard audit events can be valuable when investigating a security incident.

Impact: Application Guard audits system events; collected logs are reviewable through Microsoft Edge.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Application Guard\Allow auditing events in Microsoft Defender Application Guard and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\AppHVSI" /v AuditApplicationGuard /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 8.2 Collect Audit Logs
  • NIST SP 800-53 Rev. 5: AU-2 Event Logging; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation
  • PCI DSS v4.0.1: 5.3.4 Enable and retain anti-malware audit logs; 6.4.1 Assess or shield public-facing web applications against known attacks; 6.4.2 Deploy an automated solution that blocks attacks on public web apps; 10.2.1.1 Record every individual user's cardholder data access; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.3 Record any access made to audit records themselves; 10.2.1.4 Record failed logical access attempts; 10.2.1.5 Record account creation, privilege elevation, and other credential changes; 10.2.1.6 Record when audit logging is initialized, started, stopped, or paused; 10.2.1.7 Record the creation or removal of system-level objects; 10.2.2 Include user, event type, date, and time in each log entry
Risk
High Profile Threat
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure Camera And Microphone Access In Microsoft Defender Application Guard Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.43

Finding: Applications inside Microsoft Defender Application Guard can access the camera and microphone.

Checks whether apps inside the Application Guard container can access the device camera and microphone.

This rule fails when allowCameraMicrophoneRedirection is not false.

Rationale: Untrusted sites in the Application Guard container should not reach the camera or microphone, preventing capture of sensitive information.

Impact: Applications inside Application Guard cannot access the device camera or microphone.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Application Guard\Allow camera and microphone access in Microsoft Defender Application Guard and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\AppHVSI" /v AllowCameraMicrophoneRedirection /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Data Persistence For Microsoft Defender Application Guard Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.43

Finding: Data persists across sessions in Microsoft Defender Application Guard.

Checks whether data persists across sessions in the Microsoft Defender Application Guard container.

This rule fails when allowPersistence is not false.

Rationale: Persistence undermines the sandbox: malicious content could remain active in the container between sessions.

Impact: None - this is the default behavior; Application Guard deletes container user data between sessions.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Application Guard\Allow data persistence for Microsoft Defender Application Guard and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\AppHVSI" /v AllowPersistence /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Insecure Application
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure Downloading And Saving Files To The Host From Microsoft Defender Application Guard Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.43

Finding: Files can be downloaded and saved to the host operating system from Microsoft Defender Application Guard.

Checks whether downloaded files may be saved from the Application Guard container to the host OS.

This rule fails when saveFilesToHost is not false.

Rationale: Potentially malicious files should not be copied from the sandbox to the host, which could put the host at risk.

Impact: None - this is the default behavior; users cannot save downloaded files from the container to the host.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Application Guard\Allow files to download and save to the host operating system from Microsoft Defender Application Guard and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\AppHVSI" /v SaveFilesToHost /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Insecure Application
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure Microsoft Defender Application Guard Clipboard Is Limited To Isolated-Session-To-Host

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.43

Finding: The Microsoft Defender Application Guard clipboard is not limited to isolated-session-to-host only.

Checks how the clipboard behaves between the Application Guard container and the host.

This rule fails when appHVSIClipboardSettings is not HOST_TO_GUARD.

Rationale: Exposing the host clipboard to the container could leak sensitive information to a compromised session; limiting to container-to-host reduces that risk.

Impact: Application Guard sessions cannot read the host clipboard, but the host can read the container clipboard.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Application Guard\Configure Microsoft Defender Application Guard clipboard settings: Clipboard behavior setting and set it to Enabled: Enable clipboard operation from an isolated session to the host.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\AppHVSI" /v AppHVSIClipboardSettings /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Insecure Application
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure Microsoft Defender Application Guard Is Turned On In Managed Mode For Edge

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.43

Finding: Microsoft Defender Application Guard is not turned on in Managed Mode for Microsoft Edge.

Checks whether application isolation through Microsoft Defender Application Guard is enabled for Microsoft Edge.

This rule fails when allowAppHVSIProviderSet is not ENABLED_EDGE.

Rationale: Application Guard uses virtualization-based isolation so that improper interactions and app vulnerabilities cannot compromise the kernel or other apps.

Impact: Application Guard will be turned on for Microsoft Edge.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Application Guard\Turn on Microsoft Defender Application Guard in Managed Mode and set it to Enabled: 1.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\AppHVSI" /v AllowAppHVSI_ProviderSet /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 10.5 Enable Anti-Exploitation Features
  • NIST SP 800-53 Rev. 5: SI-16 Memory Protection
Risk
Insecure Application
MITRE ATT&CK tactic
Execution (TA0002)

18.10.49 News and interests

Ensure News And Interests On The Taskbar Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.49

Finding: News and interests on the taskbar is enabled.

Checks whether the news and interests feature is allowed on the taskbar.

This rule fails when enableFeeds is not false.

Rationale: News and interests may share data with third parties and can display inappropriate content, and should be treated as a security risk.

Impact: The news and interests feature on the taskbar will not be available on the device.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\News and interests\Enable news and interests on the taskbar and set it to Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Windows Feeds" /v EnableFeeds /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

18.10.50 OneDrive (formerly SkyDrive)

Ensure Use Of OneDrive For File Storage Is Prevented

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.50

Finding: Use of OneDrive for file storage is permitted.

Checks whether apps and features are prevented from working with OneDrive via the Next Generation Sync Client.

This rule fails when disableFileSyncNGSC is not true.

Rationale: Preventing OneDrive use stops users from accidentally or intentionally uploading confidential corporate information to the cloud service.

Impact: Users cannot access OneDrive from the app or file picker, and files are not synced with the cloud.

Remediation

Navigate to Computer Configuration\Policies\Administrative Templates\Windows Components\OneDrive\Prevent the usage of OneDrive for file storage and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\OneDrive" /v DisableFileSyncNGSC /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

18.10.56 Push To Install

Ensure Turn Off Push To Install Service Is Enabled

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.56

Finding: Push To Install service is not turned off.

Checks whether the Push To Install service, which lets remotely initiated Store installs push apps to the device, is turned off.

This rule fails when disablePushToInstall is not true.

Rationale: The Push To Install service can be used to silently place applications on a device from a linked account, expanding what unattended software can appear.

Impact: Users can no longer remotely queue Store app installs to this device from another device.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Push To Install > Turn off Push To Install service and set Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\PushToInstall" /v DisablePushToInstall /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 2.5 Allowlist Authorized Software
  • NIST SP 800-53 Rev. 5: CM-7 Least Functionality; CM-10 Software Usage Restrictions
  • NIST SP 800-171 Rev. 2: 3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; 3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
  • CMMC 2.0 Level 2: CM.L2-3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; SC.L2-3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality
Risk
External Attack Surface
MITRE ATT&CK tactic
Execution (TA0002)

18.10.57 Remote Desktop Services (formerly Terminal Services)

Ensure Disable Cloud Clipboard Integration For Server To Client Is Enabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.57.2

Finding: Cloud clipboard integration for server-to-client transfer is not disabled.

Checks whether cloud clipboard content is prevented from flowing from a Remote Desktop server back to the client.

This rule fails when disableCloudClipboardIntegration is not true.

Rationale: Cloud clipboard flow from an untrusted remote host to the client can leak sensitive data onto the local device.

Impact: Clipboard data synchronised through the cloud will not transfer from the server to the client.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Connection Client > Disable Cloud Clipboard integration for server-to-client data transfer and set Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services\Client" /v DisableCloudClipboardIntegration /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Do Not Allow Passwords To Be Saved Is Enabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.57.2

Finding: Saving of Remote Desktop passwords is allowed.

Checks whether the Remote Desktop Connection client is prevented from saving connection passwords.

This rule fails when disablePasswordSaving is not true.

Rationale: Saved RDP passwords stored on the client can be recovered by an attacker and reused against remote hosts.

Impact: The Remote Desktop client no longer offers to save passwords; users must enter them each time.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Connection Client > Do not allow passwords to be saved and set Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v DisablePasswordSaving /t REG_DWORD /d 1 /f
Risk
Insecure Use of Secrets
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure Allow Users To Connect Remotely By Using Remote Desktop Services Is Disabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.57.3.2

Finding: Remote Desktop Services connections to this computer are allowed.

Checks whether inbound Remote Desktop Services connections to this computer are denied (the policy that allows remote connections is disabled).

This rule fails when fDenyTSConnections is not true.

Rationale: An exposed Remote Desktop listener is a frequent target for credential attacks and lateral movement.

Impact: Users cannot connect to this computer using Remote Desktop until the policy is re-enabled.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Connections > Allow users to connect remotely by using Remote Desktop Services and set Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v fDenyTSConnections /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Exposure
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Allow UI Automation Redirection Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.57.3.3

Finding: UI Automation redirection is enabled for Remote Desktop.

Checks whether UI Automation redirection between a Remote Desktop session and the local device is disabled.

This rule fails when enableUiaRedirection is not false.

Rationale: UI Automation redirection lets accessibility automation cross the session boundary, which can be abused to drive or observe the remote or local desktop.

Impact: UI Automation clients cannot interact across the Remote Desktop session boundary.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Device and Resource Redirection > Allow UI Automation redirection and set Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v EnableUiaRedirection /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Do Not Allow Drive Redirection Is Enabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.57.3.3

Finding: Drive redirection is allowed in Remote Desktop sessions.

Checks whether mapping of local drives into a Remote Desktop session is prevented.

This rule fails when fDisableCdm is not true.

Rationale: Drive redirection lets files move freely between the session host and the client, a path for data theft and malware transfer.

Impact: Local drives are no longer mapped into Remote Desktop sessions.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Device and Resource Redirection > Do not allow drive redirection and set Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v fDisableCdm /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Do Not Allow Location Redirection Is Enabled

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.57.3.3

Finding: Location redirection is allowed in Remote Desktop sessions.

Checks whether device location information is prevented from being redirected into a Remote Desktop session.

This rule fails when fDisableLocationRedir is not true.

Rationale: Redirected location data exposes the physical whereabouts of the client to the remote host.

Impact: Location information is no longer redirected into Remote Desktop sessions.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Device and Resource Redirection > Do not allow location redirection and set Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v fDisableLocationRedir /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Do Not Allow LPT Port Redirection Is Enabled

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.57.3.3

Finding: LPT port redirection is allowed in Remote Desktop sessions.

Checks whether redirection of local LPT (parallel) ports into a Remote Desktop session is prevented.

This rule fails when fDisableLPT is not true.

Rationale: LPT port redirection widens the session's device surface with no legitimate need in most environments.

Impact: Local LPT ports are no longer available inside Remote Desktop sessions.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Device and Resource Redirection > Do not allow LPT port redirection and set Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v fDisableLPT /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Do Not Allow Supported Plug And Play Device Redirection Is Enabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.57.3.3

Finding: Supported Plug and Play device redirection is allowed in Remote Desktop sessions.

Checks whether redirection of supported Plug and Play devices into a Remote Desktop session is prevented.

This rule fails when fDisablePNPRedir is not true.

Rationale: PnP device redirection can bridge removable media and other peripherals into the session, enabling data movement and malware transfer.

Impact: Supported Plug and Play devices are no longer redirected into Remote Desktop sessions.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Device and Resource Redirection > Do not allow supported Plug and Play device redirection and set Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v fDisablePNPRedir /t REG_DWORD /d 1 /f
Risk
External Attack Surface
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Do Not Allow WebAuthn Redirection Is Enabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.57.3.3

Finding: WebAuthn redirection is allowed in Remote Desktop sessions.

Checks whether WebAuthn (FIDO) authenticator redirection into a Remote Desktop session is prevented.

This rule fails when fDisableWebAuthn is not true.

Rationale: Redirecting WebAuthn authenticators lets the remote host use the client's security keys, weakening the trust boundary around strong authentication.

Impact: Local WebAuthn authenticators are no longer available to Remote Desktop sessions.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Device and Resource Redirection > Do not allow WebAuthn redirection and set Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v fDisableWebAuthn /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Insecure Use of Secrets
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure Restrict Clipboard Transfer From Server To Client Is Set To Disable Clipboard Transfers

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.57.3.3

Finding: Clipboard transfer from a Remote Desktop server to the client is not disabled.

Checks whether clipboard content is blocked from being copied from a Remote Desktop session server to the connecting client.

This rule fails when scClipLevel is not DISABLED.

Rationale: Allowing the server to push clipboard data to the client can exfiltrate data from an untrusted remote host onto the local device.

Impact: Clipboard content originating on the Remote Desktop server can no longer be pasted on the client.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Device and Resource Redirection > Restrict clipboard transfer from server to client and set Enabled: Disable clipboard transfers from server to client.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v SCClipLevel /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Always Prompt For Password Upon Connection Is Enabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.57.3.9

Finding: Remote Desktop connections do not always prompt for a password.

Checks whether Remote Desktop always requires the user to enter a password when connecting.

This rule fails when fPromptForPassword is not true.

Rationale: If the client can supply a cached password automatically, an attacker at the client can connect without re-authenticating.

Impact: Users are always prompted for their password when establishing a Remote Desktop connection.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Security > Always prompt for password upon connection and set Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v fPromptForPassword /t REG_DWORD /d 1 /f
Risk
Unprotected Principal
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure Require Secure RPC Communication Is Enabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.57.3.9

Finding: Secure RPC communication is not required for Remote Desktop.

Checks whether the Remote Desktop server requires authenticated and encrypted RPC requests.

This rule fails when fEncryptRPCTraffic is not true.

Rationale: Without secure RPC, unauthenticated or unencrypted management requests to the RD service are accepted, exposing it to interception and abuse.

Impact: Only RPC clients that support secure, encrypted requests can communicate with the Remote Desktop service.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Security > Require secure RPC communication and set Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v fEncryptRPCTraffic /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 3.10 Encrypt Sensitive Data in Transit
  • NIST SP 800-53 Rev. 5: AC-17 Remote Access; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
  • NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
  • CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
  • PCI DSS v4.0.1: 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography
Risk
External Exposure
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Require Use Of Specific Security Layer For Remote Connections Is Set To SSL

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.57.3.9

Finding: Remote Desktop connections do not require the SSL security layer.

Checks whether Remote Desktop connections require the SSL (TLS) security layer for server authentication and session encryption.

This rule fails when securityLayer is not SSL_TLS.

Rationale: Native RDP encryption does not authenticate the server, leaving connections open to man-in-the-middle attacks; SSL/TLS provides server authentication.

Impact: Clients that cannot negotiate SSL/TLS will be unable to connect to the Remote Desktop host.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Security > Require use of specific security layer for remote (RDP) connections and set Enabled: SSL.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v SecurityLayer /t REG_DWORD /d 2 /f
Framework mappings
  • CIS Controls v8: 3.10 Encrypt Sensitive Data in Transit
  • NIST SP 800-53 Rev. 5: AC-17 Remote Access; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
  • NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
  • CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
  • PCI DSS v4.0.1: 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography
Risk
External Exposure
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Require User Authentication For Remote Connections By Using Network Level Authentication Is Enabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.57.3.9

Finding: Network Level Authentication is not required for Remote Desktop connections.

Checks whether Remote Desktop requires Network Level Authentication before a session is established.

This rule fails when userAuthentication is not true.

Rationale: NLA forces the user to authenticate before a full session is created, protecting the host from pre-authentication attacks and resource exhaustion.

Impact: Only clients that support Network Level Authentication can connect to the Remote Desktop host.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Security > Require user authentication for remote connections by using Network Level Authentication and set Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v UserAuthentication /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 3.10 Encrypt Sensitive Data in Transit
  • NIST SP 800-53 Rev. 5: AC-17 Remote Access; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
  • NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
  • CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
  • PCI DSS v4.0.1: 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography
Risk
External Exposure
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure Set Client Connection Encryption Level Is Set To High Level

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.57.3.9

Finding: Remote Desktop client connection encryption level is below High.

Checks whether Remote Desktop connections encrypt all traffic in both directions using 128-bit keys.

This rule fails when minEncryptionLevel is not HIGH.

Rationale: Weaker encryption levels leave part of the session traffic recoverable by an attacker on the network.

Impact: Clients that cannot support 128-bit encryption will be unable to connect to the Remote Desktop host.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Security > Set client connection encryption level and set Enabled: High Level.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v MinEncryptionLevel /t REG_DWORD /d 3 /f
Framework mappings
  • CIS Controls v8: 3.10 Encrypt Sensitive Data in Transit
  • NIST SP 800-53 Rev. 5: AC-17 Remote Access; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
  • NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
  • CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
  • PCI DSS v4.0.1: 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Set Time Limit For Active But Idle Remote Desktop Services Sessions Is 15 Minutes Or Less

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.57.3.10

Finding: Active but idle Remote Desktop sessions have no limit or exceed 15 minutes.

Checks the maximum time an active but idle Remote Desktop session may remain before it is disconnected.

This rule fails when maxIdleTime is 0 (Never) or greater than 900000000000 ns (15 minutes).

Rationale: An idle session left open indefinitely can be hijacked by anyone with access to the client, and consumes host resources.

Impact: Idle Remote Desktop sessions are disconnected after the configured time limit.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Session Time Limits > Set time limit for active but idle Remote Desktop Services sessions and set Enabled: 15 minutes or less, but not Never (0).

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v MaxIdleTime /t REG_DWORD /d 900000 /f
Risk
Unprotected Principal
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Temporary Folders Are Deleted Upon Remote Desktop Session Exit

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.57.3.11

Finding: Per-session temporary folders are retained after Remote Desktop session exit.

Checks whether per-session temporary folders are deleted when a Remote Desktop session ends.

This rule fails when deleteTempDirsOnExit is not true.

Rationale: Retained per-session temp folders can leave sensitive working data on disk for later recovery.

Impact: Per-session temporary folders are cleared when each Remote Desktop session ends.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Temporary folders > Do not delete temp folders upon exit (set to Disabled) and set Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v DeleteTempDirsOnExit /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 3.4 Enforce Data Retention
  • NIST SP 800-53 Rev. 5: AU-11 Audit Record Retention; SI-12 Information Management and Retention
  • PCI DSS v4.0.1: 3.2.1 Minimize stored account data via defined retention and secure deletion rules
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

18.10.58 RSS Feeds

Ensure Prevent Downloading Of Enclosures Is Enabled

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.58

Finding: Downloading of RSS feed enclosures is allowed.

Checks whether the automatic download of RSS/Atom feed enclosures (attachments) is prevented.

This rule fails when disableEnclosureDownload is not true.

Rationale: Feed enclosures can silently pull attacker-supplied files onto the device without user interaction.

Impact: Enclosures attached to RSS feeds are no longer downloaded automatically.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > RSS Feeds > Prevent downloading of enclosures and set Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer\Feeds" /v DisableEnclosureDownload /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 9.4 Restrict Unnecessary or Unauthorized Browser and Email Client Extensions
  • NIST SP 800-53 Rev. 5: CM-10 Software Usage Restrictions; CM-11 User-installed Software; SC-18 Mobile Code
  • PCI DSS v4.0.1: 2.2.4 Enable only required services and remove unneeded functionality
Risk
External Attack Surface
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Allow Cortana Above Lock Screen Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.59

Finding: Cortana is allowed above the lock screen.

Checks whether Cortana can be used from the lock screen without signing in.

This rule fails when allowCortanaAboveLock is not false.

Rationale: An assistant available above the lock screen lets an unauthenticated person interact with the device and potentially disclose information.

Impact: Cortana is unavailable on the lock screen until the user signs in.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Search > Allow Cortana above lock screen and set Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Windows Search" /v AllowCortanaAboveLock /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Principal
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Allow Cortana Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.59

Finding: Cortana is allowed.

Checks whether the Cortana voice assistant is disabled.

This rule fails when allowCortana is not false.

Rationale: Cortana sends queries and contextual data to cloud services and expands the input surface of the device.

Impact: Cortana is turned off; users cannot use its assistant features.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Search > Allow Cortana and set Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Windows Search" /v AllowCortana /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Allow Indexing Of Encrypted Files Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.59

Finding: Indexing of encrypted files is allowed.

Checks whether the search indexer is prevented from indexing encrypted files and stores.

This rule fails when allowIndexingEncryptedStoresOrItems is not false.

Rationale: Indexing encrypted content copies plaintext-derived index data outside the protected store, undermining the encryption.

Impact: Encrypted files are excluded from the search index and will not appear in indexed search results.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Search > Allow indexing of encrypted files and set Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Windows Search" /v AllowIndexingEncryptedStoresOrItems /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Allow Search And Cortana To Use Location Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.59

Finding: Search and Cortana are allowed to use device location.

Checks whether Search and Cortana are prevented from accessing the device's location.

This rule fails when allowSearchToUseLocation is not false.

Rationale: Location access by search components leaks the device's physical whereabouts to local and cloud features.

Impact: Search and Cortana no longer use the device location for results.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Search > Allow search and Cortana to use location and set Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Windows Search" /v AllowSearchToUseLocation /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Allow Search Highlights Is Disabled

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.59

Finding: Search highlights are allowed.

Checks whether dynamic search highlights, which fetch content into the search box from the internet, are disabled.

This rule fails when enableDynamicContentInWSB is not false.

Rationale: Search highlights pull remote content and telemetry into the search experience, adding an untrusted content channel.

Impact: The search box no longer displays dynamic highlight content.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Search > Allow search highlights and set Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Windows Search" /v EnableDynamicContentInWSB /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

18.10.63 Software Protection Platform

Ensure Turn Off KMS Client Online AVS Validation Is Enabled

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.63

Finding: KMS Client Online AVS Validation is not turned off.

Checks whether the KMS client is prevented from contacting Microsoft's Activation and Validation Service online.

This rule fails when noGenTicket is not true.

Rationale: Blocking the online validation call removes an outbound connection to Microsoft that is unnecessary for KMS-activated enterprise hosts.

Impact: The KMS client no longer performs the online AVS validation call.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Software Protection Platform > Turn off KMS Client Online AVS Validation and set Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\Software Protection Platform" /v NoGenTicket /t REG_DWORD /d 1 /f
Risk
External Attack Surface
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

18.10.66 Store

Ensure Disable All Apps From Microsoft Store Is Configured

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.66

Finding: Microsoft Store apps are not restricted per policy.

Checks whether the Microsoft Store app-restriction policy is applied so that unmanaged Store apps are constrained.

This rule fails when disableStoreApps is not true.

Rationale: Unrestricted Store apps let users install software outside of IT control, broadening the software attack surface.

Impact: Microsoft Store apps are constrained according to the configured Store policy.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Store > Disable all apps from Microsoft Store (set to Disabled) and set Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\WindowsStore" /v DisableStoreApps /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 2.5 Allowlist Authorized Software
  • NIST SP 800-53 Rev. 5: CM-7 Least Functionality; CM-10 Software Usage Restrictions
  • NIST SP 800-171 Rev. 2: 3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; 3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
  • CMMC 2.0 Level 2: CM.L2-3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; SC.L2-3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality
Risk
Insecure Application
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Turn Off Automatic Download And Install Of Updates Is Disabled

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.66

Finding: Automatic download and install of Store app updates is not turned off.

Checks whether automatic download and installation of Microsoft Store app updates is turned off.

This rule fails when autoDownload is not NEVER.

Rationale: Uncontrolled automatic Store updates can introduce unvetted changes to installed apps.

Impact: Microsoft Store app updates are not downloaded or installed automatically; updates must be initiated manually.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Store > Turn off Automatic Download and Install of updates and set Enabled: Never download.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\WindowsStore" /v AutoDownload /t REG_DWORD /d 4 /f
Framework mappings
  • CIS Controls v8: 7.3 Perform Automated Operating System Patch Management
  • NIST SP 800-53 Rev. 5: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation
Risk
Reliability Impact
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Turn Off The Offer To Update To The Latest Version Of Windows Is Enabled

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.66

Finding: The Store offer to update to the latest version of Windows is not turned off.

Checks whether the Microsoft Store is prevented from offering an in-place upgrade to the latest Windows version.

This rule fails when disableOSUpgrade is not true.

Rationale: An unmanaged Store-driven OS upgrade can move a device to an unvalidated Windows release outside change control.

Impact: Users are no longer offered a Windows version upgrade through the Microsoft Store.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Store > Turn off the offer to update to the latest version of Windows and set Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\WindowsStore" /v DisableOSUpgrade /t REG_DWORD /d 1 /f
Risk
Reliability Impact
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Turn Off The Store Application Is Enabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.66

Finding: The Microsoft Store application is not turned off.

Checks whether access to the Microsoft Store application is removed.

This rule fails when removeWindowsStore is not true.

Rationale: The Store lets users acquire and run applications outside IT control, expanding the software attack surface.

Impact: The Microsoft Store application is inaccessible to users on the device.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Store > Turn off the Store application and set Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\WindowsStore" /v RemoveWindowsStore /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 2.5 Allowlist Authorized Software
  • NIST SP 800-53 Rev. 5: CM-7 Least Functionality; CM-10 Software Usage Restrictions
  • NIST SP 800-171 Rev. 2: 3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; 3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
  • CMMC 2.0 Level 2: CM.L2-3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; SC.L2-3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality
Risk
Insecure Application
MITRE ATT&CK tactic
Execution (TA0002)

18.10.72 Widgets

Ensure Allow Widgets Is Disabled

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.72

Finding: Widgets are allowed.

Checks whether the Widgets board (news and interests feed) is disabled.

This rule fails when allowNewsAndInterests is not false.

Rationale: The Widgets feed pulls remote content and telemetry into the desktop, adding an untrusted content channel.

Impact: The Widgets board is turned off and its taskbar entry is removed.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Widgets > Allow widgets and set Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Dsh" /v AllowNewsAndInterests /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

18.10.73 Windows AI

Ensure Allow Recall To Be Enabled Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.73

Finding: Windows Recall is allowed to be enabled.

Checks whether the Windows Recall feature, which periodically snapshots the screen, is prevented from being enabled.

This rule fails when allowRecallEnablement is not false.

Rationale: Recall stores a searchable history of on-screen content, creating a rich local trove of sensitive data that an attacker could harvest.

Impact: Users cannot enable the Windows Recall feature on the device.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows AI > Allow Recall to be enabled and set Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsAI" /v AllowRecallEnablement /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

18.10.77 Windows Defender SmartScreen

Ensure Enhanced Phishing Protection Automatic Data Collection Is Enabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.77.1

Finding: Enhanced Phishing Protection automatic data collection is disabled.

Checks whether Enhanced Phishing Protection collects additional context from suspicious sites or apps for security analysis.

This rule fails when captureThreatWindow is not true.

Rationale: Automatic data collection improves detection of phishing and unsafe credential entry across the device.

Impact: Enhanced Phishing Protection captures additional threat context when a suspicious event is detected.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Defender SmartScreen > Enhanced Phishing Protection > Automatic Data Collection and set Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WTDS\Components" /v CaptureThreatWindow /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 10.5 Enable Anti-Exploitation Features
  • NIST SP 800-53 Rev. 5: SI-16 Memory Protection
Risk
High Profile Threat
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure Enhanced Phishing Protection Notify Malicious Is Enabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.77.1

Finding: Enhanced Phishing Protection malicious-site notifications are disabled.

Checks whether users are warned when they enter their password on a known malicious site or app.

This rule fails when notifyMalicious is not true.

Rationale: Warning on malicious credential entry is a key defence against phishing and credential theft.

Impact: Users receive a warning when they attempt to use their password on a site or app flagged as malicious.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Defender SmartScreen > Enhanced Phishing Protection > Notify Malicious and set Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WTDS\Components" /v NotifyMalicious /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 10.5 Enable Anti-Exploitation Features
  • NIST SP 800-53 Rev. 5: SI-16 Memory Protection
Risk
High Profile Threat
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure Enhanced Phishing Protection Notify Password Reuse Is Enabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.77.1

Finding: Enhanced Phishing Protection password-reuse notifications are disabled.

Checks whether users are warned when they reuse their work or school password on other sites or apps.

This rule fails when notifyPasswordReuse is not true.

Rationale: Password reuse spreads the impact of a single compromised credential; warning users curbs the practice.

Impact: Users are warned when they reuse their protected password elsewhere.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Defender SmartScreen > Enhanced Phishing Protection > Notify Password Reuse and set Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WTDS\Components" /v NotifyPasswordReuse /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 10.5 Enable Anti-Exploitation Features
  • NIST SP 800-53 Rev. 5: SI-16 Memory Protection
Risk
Insecure Use of Secrets
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure Enhanced Phishing Protection Notify Unsafe App Is Enabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.77.1

Finding: Enhanced Phishing Protection unsafe-app notifications are disabled.

Checks whether users are warned when they type their password into an application considered unsafe.

This rule fails when notifyUnsafeApp is not true.

Rationale: Entering a password into an untrusted app is a common credential-theft vector; the warning intercepts it.

Impact: Users receive a warning when they enter their password into an app flagged as unsafe.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Defender SmartScreen > Enhanced Phishing Protection > Notify Unsafe App and set Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WTDS\Components" /v NotifyUnsafeApp /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 10.5 Enable Anti-Exploitation Features
  • NIST SP 800-53 Rev. 5: SI-16 Memory Protection
Risk
High Profile Threat
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure Enhanced Phishing Protection Service Is Enabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.77.1

Finding: The Enhanced Phishing Protection service is disabled.

Checks whether the Enhanced Phishing Protection service is turned on.

This rule fails when serviceEnabled is not true.

Rationale: The service underpins all phishing and password-protection warnings; if it is off, none of them apply.

Impact: The Enhanced Phishing Protection service runs and enforces the configured phishing protections.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Defender SmartScreen > Enhanced Phishing Protection > Service Enabled and set Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WTDS\Components" /v ServiceEnabled /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 10.5 Enable Anti-Exploitation Features
  • NIST SP 800-53 Rev. 5: SI-16 Memory Protection
Risk
High Profile Threat
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure Configure Windows Defender SmartScreen Is Set To Warn And Prevent Bypass

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.77.2

Finding: Windows Defender SmartScreen is not set to warn and prevent bypass.

Checks whether Windows Defender SmartScreen is turned on for File Explorer and configured to block, rather than merely warn about, unrecognized applications.

This rule fails when enableSmartScreen is not WARN_PREVENT_BYPASS or shellSmartScreenLevel is not BLOCK.

Rationale: SmartScreen in warn-only mode lets users click through the warning and run malicious downloads; preventing bypass stops execution of unrecognized apps.

Impact: Users cannot override the SmartScreen warning to run unrecognized applications.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > File Explorer > Configure Windows Defender SmartScreen and set Enabled: Warn and prevent bypass.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v EnableSmartScreen /t REG_DWORD /d 1 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v ShellSmartScreenLevel /t REG_SZ /d Block /f
Framework mappings
  • CIS Controls v8: 10.5 Enable Anti-Exploitation Features
  • NIST SP 800-53 Rev. 5: SI-16 Memory Protection
Risk
High Profile Threat
MITRE ATT&CK tactic
Execution (TA0002)

18.10.79 Windows Game Recording and Broadcasting

Ensure Windows Game Recording And Broadcasting Is Disabled

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.79

Finding: Windows Game Recording and Broadcasting is enabled.

Checks whether the Game DVR recording and broadcasting feature is disabled.

This rule fails when allowGameDVR is not false.

Rationale: Game DVR can capture on-screen content and stream it, an unnecessary capability that could record sensitive information.

Impact: Game recording and broadcasting features are turned off.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Game Recording and Broadcasting > Enables or disables Windows Game Recording and Broadcasting and set Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\GameDVR" /v AllowGameDVR /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Attack Surface
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

18.10.80 Windows Hello for Business

Ensure Enable Enhanced Sign In Security With Supported Peripherals Is Enabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.80

Finding: Enhanced Sign-in Security with supported peripherals is not enabled.

Checks whether Enhanced Sign-in Security uses hardware-isolated biometric processing on supported peripherals.

This rule fails when enableESSwithSupportedPeripherals is not ENABLED.

Rationale: Enhanced Sign-in Security isolates biometric operations from the rest of the OS, hardening Windows Hello against tampering of biometric input.

Impact: Biometric sign-in uses hardware-isolated processing when supported peripheral hardware is present.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Hello for Business > Enable ESS with Supported Peripherals and set Enabled: 1.

From the command line:

reg add "HKLM\SOFTWARE\Microsoft\Policies\PassportForWork\Biometrics" /v EnableESSwithSupportedPeripherals /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 10.5 Enable Anti-Exploitation Features
  • NIST SP 800-53 Rev. 5: SI-16 Memory Protection
Risk
Unprotected Principal
MITRE ATT&CK tactic
Credential Access (TA0006)

18.10.81 Windows Ink Workspace

Ensure Allow Suggested Apps In Windows Ink Workspace Is Disabled

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.81

Finding: Suggested apps in Windows Ink Workspace are allowed.

Checks whether app suggestions in the Windows Ink Workspace are disabled.

This rule fails when allowSuggestedAppsInWindowsInkWorkspace is not false.

Rationale: App suggestions surface and advertise store content in the workspace, an unnecessary remote content channel.

Impact: The Windows Ink Workspace no longer shows suggested apps.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Ink Workspace > Allow suggested apps in Windows Ink Workspace and set Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\WindowsInkWorkspace" /v AllowSuggestedAppsInWindowsInkWorkspace /t REG_DWORD /d 0 /f
Risk
External Attack Surface
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Allow Windows Ink Workspace Is Disabled Or On Without Access Above The Lock Screen

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.81

Finding: Windows Ink Workspace is accessible above the lock screen.

Checks whether the Windows Ink Workspace is either disabled or, if enabled, made inaccessible from the lock screen.

This rule fails when allowWindowsInkWorkspace is not DISABLED and not ON_NO_INK_BELOW_LOCK (i.e. it is fully ON).

Rationale: Ink features available above the lock screen let an unauthenticated person interact with the device before signing in.

Impact: If enabled, the Ink Workspace is available only after sign-in; it cannot be reached from the lock screen.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Ink Workspace > Allow Windows Ink Workspace and set Enabled: On, but disallow access above lock or Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\WindowsInkWorkspace" /v AllowWindowsInkWorkspace /t REG_DWORD /d 1 /f
Risk
Unprotected Principal
MITRE ATT&CK tactic
Initial Access (TA0001)

18.10.82 Windows Installer

Ensure Allow User Control Over Installs Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.82

Finding: User control over Windows Installer installs is allowed.

Checks whether users are prevented from changing installation options that are normally reserved for administrators.

This rule fails when enableUserControl is not false.

Rationale: Allowing user control over installs lets non-administrators alter protected install settings, potentially installing software insecurely.

Impact: Users cannot override administrator-controlled Windows Installer options.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Installer > Allow user control over installs and set Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer" /v EnableUserControl /t REG_DWORD /d 0 /f
Risk
Insecure Application
MITRE ATT&CK tactic
Privilege Escalation (TA0004)

Ensure Always Install With Elevated Privileges Is Disabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.82

Finding: Windows Installer always installs with elevated privileges.

Checks whether Windows Installer is prevented from installing packages with full system privileges for standard users.

This rule fails when alwaysInstallElevated is not false.

Rationale: This setting lets any user run installer packages as SYSTEM, a well-known local privilege-escalation path.

Impact: Windows Installer packages run with the invoking user's privileges rather than elevated system rights.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Installer > Always install with elevated privileges and set Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer" /v AlwaysInstallElevated /t REG_DWORD /d 0 /f
Risk
Insecure Application
MITRE ATT&CK tactic
Privilege Escalation (TA0004)

Ensure Prevent Internet Explorer Security Prompt For Windows Installer Scripts Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.82

Finding: The Internet Explorer security prompt for Windows Installer scripts is suppressed.

Checks whether scripted (web-hosted) Windows Installer installs still trigger the security prompt rather than running silently.

This rule fails when safeForScripting is not false.

Rationale: Suppressing the prompt lets web pages silently launch installer packages, enabling drive-by software installation.

Impact: Scripted Windows Installer installs continue to raise the standard security prompt.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Installer > Prevent Internet Explorer security prompt for Windows Installer scripts and set Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer" /v SafeForScripting /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 2.5 Allowlist Authorized Software
  • NIST SP 800-53 Rev. 5: CM-7 Least Functionality; CM-10 Software Usage Restrictions
  • NIST SP 800-171 Rev. 2: 3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; 3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
  • CMMC 2.0 Level 2: CM.L2-3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; SC.L2-3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality
Risk
Insecure Application
MITRE ATT&CK tactic
Execution (TA0002)

18.10.83 Windows Logon Options

Ensure Sign In And Lock Last Interactive User Automatically After A Restart Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.83

Finding: The last interactive user is automatically signed in and locked after an update restart.

Checks whether automatic sign-in and lock of the last interactive user after an update-driven restart is disabled.

This rule fails when disableAutomaticRestartSignOn is not true.

Rationale: Automatic restart sign-on caches the user's credentials to re-establish the session, exposing them if the device is captured during the reboot window.

Impact: After an update restart the device returns to the sign-in screen instead of auto-signing-in the last user.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Logon Options > Sign-in and lock last interactive user automatically after a restart (set to Disabled) and set Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v DisableAutomaticRestartSignOn /t REG_DWORD /d 1 /f
Risk
Unprotected Principal
MITRE ATT&CK tactic
Persistence (TA0003)

Ensure Transmission Of The User Password In MPR Notifications Sent By Winlogon Is Disabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.83

Finding: The user's password is transmitted in MPR notifications sent by winlogon.

Checks whether winlogon is prevented from including the user's plaintext password in the MPR notifications it sends to network providers.

This rule fails when enableMPRNotifications is not false.

Rationale: Including the password in MPR notifications exposes the credential to any registered network provider, including malicious ones.

Impact: Winlogon no longer includes the user's password in MPR notifications; providers relying on it lose that data.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Logon Options > Configure the transmission of the user's password in the content of MPR notifications sent by winlogon and set Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v EnableMPRNotifications /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Insecure Use of Secrets
MITRE ATT&CK tactic
Credential Access (TA0006)

18.10.88 Windows PowerShell

Ensure Turn On PowerShell Script Block Logging Is Enabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.88

Finding: PowerShell script block logging is disabled.

Checks whether PowerShell records the content of executed script blocks to the event log.

This rule fails when enableScriptBlockLogging is not true.

Rationale: Script block logging captures obfuscated and in-memory PowerShell attacker activity that would otherwise leave no trace, aiding detection and investigation.

Impact: The content of executed PowerShell script blocks is written to the operational event log.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows PowerShell > Turn on PowerShell Script Block Logging and set Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging" /v EnableScriptBlockLogging /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 8.8 Collect Command-Line Audit Logs
  • NIST SP 800-53 Rev. 5: AC-6 Least Privilege; AU-2 Event Logging
Risk
High Profile Threat
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Turn On PowerShell Transcription Is Enabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.88

Finding: PowerShell transcription is disabled.

Checks whether PowerShell writes a transcript of input and output for each session to a log file.

This rule fails when enableTranscripting is not true.

Rationale: Session transcripts provide a durable record of interactive and scripted PowerShell activity for incident response.

Impact: PowerShell sessions produce transcript files capturing commands and their output.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows PowerShell > Turn on PowerShell Transcription and set Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\PowerShell\Transcription" /v EnableTranscripting /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 8.8 Collect Command-Line Audit Logs
  • NIST SP 800-53 Rev. 5: AC-6 Least Privilege; AU-2 Event Logging
Risk
High Profile Threat
MITRE ATT&CK tactic
Execution (TA0002)

18.10.90 Windows Remote Management (WinRM)

Ensure WinRM Client Allow Basic Authentication Is Disabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.90.1

Finding: The WinRM client allows Basic authentication.

Checks whether the WinRM client is prevented from using Basic authentication.

This rule fails when winRMClientAllowBasic is not false.

Rationale: Basic authentication sends credentials with trivial encoding; over WinRM it exposes them to interception.

Impact: The WinRM client can no longer authenticate to remote hosts using Basic authentication.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Remote Management (WinRM) > WinRM Client > Allow Basic authentication and set Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WinRM\Client" /v AllowBasic /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 3.10 Encrypt Sensitive Data in Transit
  • NIST SP 800-53 Rev. 5: AC-17 Remote Access; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
  • NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
  • CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
  • PCI DSS v4.0.1: 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography
Risk
Insecure Use of Secrets
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure WinRM Client Allow Unencrypted Traffic Is Disabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.90.1

Finding: The WinRM client allows unencrypted traffic.

Checks whether the WinRM client is prevented from sending unencrypted management traffic.

This rule fails when winRMClientAllowUnencryptedTraffic is not false.

Rationale: Unencrypted WinRM traffic exposes commands and credentials to network eavesdropping and tampering.

Impact: The WinRM client only communicates over encrypted channels.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Remote Management (WinRM) > WinRM Client > Allow unencrypted traffic and set Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WinRM\Client" /v AllowUnencryptedTraffic /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 3.10 Encrypt Sensitive Data in Transit
  • NIST SP 800-53 Rev. 5: AC-17 Remote Access; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
  • NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
  • CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
  • PCI DSS v4.0.1: 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography
Risk
External Exposure
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure WinRM Client Disallow Digest Authentication Is Enabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.90.1

Finding: The WinRM client allows Digest authentication.

Checks whether the WinRM client is prevented from using Digest authentication.

This rule fails when winRMClientAllowDigest is not false.

Rationale: Digest authentication over WinRM is weak and can expose credentials to relay and interception attacks.

Impact: The WinRM client can no longer use Digest authentication.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Remote Management (WinRM) > WinRM Client > Disallow Digest authentication and set Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WinRM\Client" /v AllowDigest /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 3.10 Encrypt Sensitive Data in Transit
  • NIST SP 800-53 Rev. 5: AC-17 Remote Access; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
  • NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
  • CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
  • PCI DSS v4.0.1: 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography
Risk
Insecure Use of Secrets
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure Allow Remote Server Management Through WinRM Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.90.2

Finding: Remote server management through WinRM is allowed.

Checks whether the WinRM service is prevented from automatically listening for and accepting remote management requests.

This rule fails when winRMServiceAllowAutoConfig is not false.

Rationale: An always-listening WinRM service is a remote entry point that can be leveraged for lateral movement.

Impact: The WinRM service does not automatically configure a listener for remote management.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Remote Management (WinRM) > WinRM Service > Allow remote server management through WinRM and set Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WinRM\Service" /v AllowAutoConfig /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Exposure
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Disallow WinRM From Storing RunAs Credentials Is Enabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.90.2

Finding: WinRM is allowed to store RunAs credentials.

Checks whether the WinRM service is prevented from storing RunAs credentials for plug-ins.

This rule fails when winRMServiceDisableRunAs is not true.

Rationale: Stored RunAs credentials can be extracted from the host and reused, enabling credential theft.

Impact: WinRM plug-ins can no longer store RunAs credentials on the host.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Remote Management (WinRM) > WinRM Service > Disallow WinRM from storing RunAs credentials and set Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WinRM\Service" /v DisableRunAs /t REG_DWORD /d 1 /f
Risk
Insecure Use of Secrets
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure WinRM Service Allow Basic Authentication Is Disabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.90.2

Finding: The WinRM service allows Basic authentication.

Checks whether the WinRM service is prevented from accepting Basic authentication.

This rule fails when winRMServiceAllowBasic is not false.

Rationale: Accepting Basic authentication lets remote clients present credentials with trivial encoding, exposing them to interception.

Impact: The WinRM service rejects Basic authentication from remote clients.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Remote Management (WinRM) > WinRM Service > Allow Basic authentication and set Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WinRM\Service" /v AllowBasic /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 3.10 Encrypt Sensitive Data in Transit
  • NIST SP 800-53 Rev. 5: AC-17 Remote Access; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
  • NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
  • CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
  • PCI DSS v4.0.1: 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography
Risk
Insecure Use of Secrets
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure WinRM Service Allow Unencrypted Traffic Is Disabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.90.2

Finding: The WinRM service allows unencrypted traffic.

Checks whether the WinRM service is prevented from accepting unencrypted management traffic.

This rule fails when winRMServiceAllowUnencryptedTraffic is not false.

Rationale: Unencrypted WinRM traffic exposes commands and credentials to network eavesdropping and tampering.

Impact: The WinRM service only accepts management traffic over encrypted channels.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Remote Management (WinRM) > WinRM Service > Allow unencrypted traffic and set Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WinRM\Service" /v AllowUnencryptedTraffic /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 3.10 Encrypt Sensitive Data in Transit
  • NIST SP 800-53 Rev. 5: AC-17 Remote Access; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
  • NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
  • CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
  • PCI DSS v4.0.1: 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography
Risk
External Exposure
MITRE ATT&CK tactic
Initial Access (TA0001)

18.10.91 Windows Remote Shell

Ensure Allow Remote Shell Access Is Disabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.91

Finding: Remote shell access is allowed.

Checks whether remote shell (WinRS) access to the computer is disabled.

This rule fails when allowRemoteShellAccess is not false.

Rationale: Remote shell access provides an interactive command channel to the host that can be abused for lateral movement and command execution.

Impact: Remote WinRS shell connections to the computer are refused.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Remote Shell > Allow Remote Shell Access and set Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WinRM\Service\WinRS" /v AllowRemoteShellAccess /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Exposure
MITRE ATT&CK tactic
Initial Access (TA0001)

18.10.92 Windows Sandbox

Ensure Allow Clipboard Sharing With Windows Sandbox Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.92

Finding: Clipboard sharing with Windows Sandbox is allowed.

Checks whether clipboard sharing between the host and Windows Sandbox is disabled.

This rule fails when allowClipboardRedirection is not false.

Rationale: A shared clipboard bridges data between the untrusted sandbox and the host, undermining the isolation the sandbox provides.

Impact: The clipboard is not shared between the host and Windows Sandbox.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Sandbox > Allow clipboard sharing with Windows Sandbox and set Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Sandbox" /v AllowClipboardRedirection /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Allow Mapping Folders Into Windows Sandbox Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.92

Finding: Mapping folders into Windows Sandbox is allowed.

Checks whether host folders can be mapped into Windows Sandbox with write access.

This rule fails when allowWriteToMappedFolders is not false.

Rationale: Mapped folders let files move between the untrusted sandbox and the host filesystem, undermining the sandbox isolation.

Impact: Host folders can no longer be mapped with write access into Windows Sandbox.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Sandbox > Allow mapping folders into Windows Sandbox and set Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Sandbox" /v AllowWriteToMappedFolders /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Allow Networking In Windows Sandbox Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.92

Finding: Networking in Windows Sandbox is allowed.

Checks whether network access from within Windows Sandbox is disabled.

This rule fails when allowNetworking is not false.

Rationale: Network access lets untrusted code in the sandbox reach the internal network and external command channels.

Impact: Windows Sandbox instances run without network connectivity.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Sandbox > Allow networking in Windows Sandbox and set Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Sandbox" /v AllowNetworking /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
External Exposure
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

18.10.93 Windows Security

Ensure Prevent Users From Modifying Exploit Protection Settings Is Enabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.93.2

Finding: Users are allowed to modify Exploit Protection settings.

Checks whether standard users are prevented from changing Exploit Protection settings in the Windows Security app.

This rule fails when disallowExploitProtectionOverride is not true.

Rationale: If users can weaken Exploit Protection, malware or an unwitting user can disable key exploit mitigations.

Impact: Users can no longer modify Exploit Protection settings; only administrators via policy can change them.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Security > App and browser protection > Prevent users from modifying settings and set Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender Security Center\App and Browser protection" /v DisallowExploitProtectionOverride /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 10.5 Enable Anti-Exploitation Features
  • NIST SP 800-53 Rev. 5: SI-16 Memory Protection
Risk
High Profile Threat
MITRE ATT&CK tactic
Defense Evasion (TA0005)

18.10.94 Windows Update

Ensure No Auto Restart With Logged On Users For Scheduled Automatic Updates Installations Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.94.1

Finding: Automatic-update installations wait for logged-on users instead of restarting to complete.

Checks whether scheduled automatic-update installations are allowed to restart the computer rather than waiting indefinitely for a logged-on user.

This rule fails when noAutoRebootWithLoggedOnUsers is not false.

Rationale: Suppressing the restart leaves update installations incomplete, so critical security fixes are not applied until the user chooses to reboot.

Impact: Scheduled automatic-update installations restart the computer to complete, after warning logged-on users.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Update > Legacy Policies > No auto-restart with logged on users for scheduled automatic updates installations and set Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v NoAutoRebootWithLoggedOnUsers /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 7.3 Perform Automated Operating System Patch Management
  • NIST SP 800-53 Rev. 5: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation
Risk
Reliability Impact
MITRE ATT&CK tactic
Impact (TA0040)

Ensure Configure Automatic Updates Is Enabled

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.94.2

Finding: Automatic Updates are not configured (turned off).

Checks whether Automatic Updates are enabled so the device downloads and installs updates on a schedule.

This rule fails when noAutoUpdate is not false.

Rationale: Disabled automatic updates leave known vulnerabilities unpatched, exposing the device to exploitation.

Impact: The device automatically downloads and installs Windows updates on the configured schedule.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Update > Manage end user experience > Configure Automatic Updates and set Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v NoAutoUpdate /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 7.3 Perform Automated Operating System Patch Management
  • NIST SP 800-53 Rev. 5: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation
Risk
Vulnerability
MITRE ATT&CK tactic
Impact (TA0040)

Ensure Configure Automatic Updates Scheduled Install Day Is Set To Every Day

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.94.2

Finding: The Automatic Updates scheduled install day is not set to every day.

Checks whether scheduled automatic-update installation is set to occur every day rather than on a single weekday.

This rule fails when scheduledInstallDay is not EVERY_DAY.

Rationale: Installing updates every day minimises the window in which a released fix is available but not yet applied.

Impact: Scheduled automatic-update installations run every day rather than only on one weekday.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Update > Manage end user experience > Configure Automatic Updates and set Enabled: 0 - Every day (Scheduled install day).

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v ScheduledInstallDay /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 7.3 Perform Automated Operating System Patch Management
  • NIST SP 800-53 Rev. 5: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation
Risk
Vulnerability
MITRE ATT&CK tactic
Impact (TA0040)

Ensure Enable Features Introduced Via Servicing That Are Off By Default Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.94.2

Finding: Features introduced via servicing that are off by default may be turned on.

Checks whether features that ship turned-off within monthly quality updates are prevented from being enabled automatically.

This rule fails when allowTemporaryEnterpriseFeatureControl is not false.

Rationale: Allowing off-by-default serviced features to turn on introduces unvalidated functionality outside of planned feature updates.

Impact: New features delivered off-by-default in quality updates remain off until explicitly enabled.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Update > Manage end user experience > Enable features introduced via servicing that are off by default and set Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /v AllowTemporaryEnterpriseFeatureControl /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 7.3 Perform Automated Operating System Patch Management
  • NIST SP 800-53 Rev. 5: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation
Risk
Reliability Impact
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Remove Access To Pause Updates Feature Is Enabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.94.2

Finding: Access to the Pause updates feature is available to users.

Checks whether the user-facing option to pause Windows updates is removed.

This rule fails when setDisablePauseUXAccess is not true.

Rationale: If users can pause updates, they can delay critical security fixes indefinitely, leaving the device exposed.

Impact: The Pause updates option is removed from the Windows Update settings UI.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Update > Manage end user experience > Remove access to "Pause updates" feature and set Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /v SetDisablePauseUXAccess /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 7.3 Perform Automated Operating System Patch Management
  • NIST SP 800-53 Rev. 5: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation
Risk
Vulnerability
MITRE ATT&CK tactic
Impact (TA0040)

Ensure Enable Optional Updates Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.94.4

Finding: Optional updates are enabled.

Checks whether the device is prevented from receiving optional updates, including Controlled Feature Rollouts.

This rule fails when setAllowOptionalContent is not false.

Rationale: Optional updates and gradual feature rollouts deliver unvalidated changes outside the planned update cycle.

Impact: The device does not receive optional updates or Controlled Feature Rollouts.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Update > Manage updates offered from Windows Update > Enable optional updates and set Disabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /v SetAllowOptionalContent /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 7.3 Perform Automated Operating System Patch Management
  • NIST SP 800-53 Rev. 5: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation
Risk
Reliability Impact
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Manage Preview Builds Is Disabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.94.4

Finding: Windows Insider preview builds are not blocked.

Checks whether installation of Windows Insider preview builds is blocked.

This rule fails when managePreviewBuilds is not DISABLE.

Rationale: Preview builds are pre-release and unsupported for production, carrying stability and security risk.

Impact: Windows Insider preview builds cannot be installed on the device.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Update > Manage updates offered from Windows Update > Manage preview builds and set Enabled: Disable preview builds.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /v ManagePreviewBuildsPolicyValue /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 2.5 Allowlist Authorized Software
  • NIST SP 800-53 Rev. 5: CM-7 Least Functionality; CM-10 Software Usage Restrictions
  • NIST SP 800-171 Rev. 2: 3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; 3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
  • CMMC 2.0 Level 2: CM.L2-3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; SC.L2-3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality
Risk
Reliability Impact
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Select When Quality Updates Are Received Is Set To Zero Days

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.94.4

Finding: Quality updates are deferred by more than zero days.

Checks whether the quality-update deferral policy is configured with a deferral period of zero days, so security fixes are received without delay.

This rule fails when deferQualityUpdates is not true or deferQualityUpdatesPeriodInDays is not 0.

Rationale: Deferring quality updates delays the delivery of security fixes, leaving known vulnerabilities unpatched for the deferral period.

Impact: Quality updates are received as soon as they are released, with no deferral.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Update > Manage updates offered from Windows Update > Select when Quality Updates are received and set Enabled: 0 days.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /v DeferQualityUpdates /t REG_DWORD /d 1 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /v DeferQualityUpdatesPeriodInDays /t REG_DWORD /d 0 /f
Framework mappings
  • CIS Controls v8: 7.3 Perform Automated Operating System Patch Management
  • NIST SP 800-53 Rev. 5: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation
Risk
Vulnerability
MITRE ATT&CK tactic
Impact (TA0040)