---
title: CIS Windows 11 Components: 158 Checks | Wartiva
description: Wartiva's 158 checks for section 18.10, Windows Components, of the CIS Microsoft Windows 11 Stand-alone Benchmark, with rationale and remediation.
url: https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html
updated: 2026-10-07
---

CIS Microsoft Windows 11 Stand-alone Benchmark · Section 18.10

# Windows 11 Components: 158 Checks

Wartiva runs 158 checks for section 18.10, Windows Components, of the CIS Microsoft Windows 11 Stand-alone Benchmark. Each one lists what it finds, why it matters, and how to fix it.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. [How Wartiva works →](https://wartiva.com/platform.html)

## 18.10.3 App and Device Inventory

### [Ensure App And Device Inventory API Sampling Is Turned Off](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#app-and-device-inventory-api-sampling-is-turned-off)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.3

**Finding:** App and Device Inventory API sampling data is sent to Microsoft.

Checks whether API sampling data collected during system runtime is prevented from being sent to Microsoft.

This rule fails when `disableAPISamping` is not `true`.

**Rationale:** Runtime API sampling data may contain sensitive information that should not be shared with a third party without explicit consent.

**Impact:** API sampling data will no longer be transmitted to Microsoft.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\App and Device Inventory\Turn off API Sampling** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\AppCompat" /v DisableAPISamping /t REG_DWORD /d 1 /f
```

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure App And Device Inventory Application Footprint Is Turned Off](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#app-and-device-inventory-application-footprint-is-turned-off)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.3

**Finding:** App and Device Inventory Application Footprint data is sent to Microsoft.

Checks whether Application Footprint registry and file activity sampling is prevented from being sent to Microsoft.

This rule fails when `disableApplicationFootprint` is not `true`.

**Rationale:** Sampled registry and file activity may contain sensitive information that should not be shared with a third party without explicit consent.

**Impact:** Application Footprint data will no longer be transmitted to Microsoft.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\App and Device Inventory\Turn off Application Footprint** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\AppCompat" /v DisableApplicationFootprint /t REG_DWORD /d 1 /f
```

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure App And Device Inventory Install Tracing Is Turned Off](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#app-and-device-inventory-install-tracing-is-turned-off)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.3

**Finding:** App and Device Inventory Install Tracing data is sent to Microsoft.

Checks whether application-install tracing data is prevented from being sent to Microsoft.

This rule fails when `disableInstallTracing` is not `true`.

**Rationale:** Install tracing data may contain sensitive information that should not be shared with a third party without explicit consent.

**Impact:** Install Tracing data will no longer be transmitted to Microsoft.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\App and Device Inventory\Turn off Install Tracing** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\AppCompat" /v DisableInstallTracing /t REG_DWORD /d 1 /f
```

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## 18.10.4 App Package Deployment

### [Ensure Non-Admin Users Are Prevented From Installing Packaged Windows Apps](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#non-admin-users-are-prevented-from-installing-packaged-windows-apps)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.4

**Finding:** Non-admin users are permitted to install packaged Windows apps.

Checks whether non-administrator users are blocked from installing Windows app packages.

This rule fails when `blockNonAdminUserInstall` is not `true`.

**Rationale:** Application installs should be managed centrally by IT staff, not initiated freely by end users.

**Impact:** Non-administrators cannot install Store app packages unless explicitly permitted by other policy.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\App Package Deployment\Prevent non-admin users from installing packaged Windows apps** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Appx" /v BlockNonAdminUserInstall /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 2.5 Allowlist Authorized Software
- **NIST SP 800-53 Rev. 5**: CM-7 Least Functionality; CM-10 Software Usage Restrictions
- **NIST SP 800-171 Rev. 2**: 3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; 3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
- **CMMC 2.0 Level 2**: CM.L2-3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; SC.L2-3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality

Risk

Insecure Application

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

### [Ensure Per-User Unsigned Package Installation Is Disallowed By Default](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#per-user-unsigned-package-installation-is-disallowed-by-default)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.4

**Finding:** Per-user unsigned packages may install by default.

Checks whether standard users are blocked from installing unsigned Windows App packages by default.

This rule fails when `disablePerUserUnsignedPackagesByDefault` is not `true`.

**Rationale:** Application installs should be managed centrally by IT staff, not initiated freely by end users.

**Impact:** Standard users cannot install unsigned packaged Store apps unless explicitly permitted.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\App Package Deployment\Not allow per-user unsigned packages to install by default (requires explicitly allow per install)** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Appx" /v DisablePerUserUnsignedPackagesByDefault /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 2.5 Allowlist Authorized Software
- **NIST SP 800-53 Rev. 5**: CM-7 Least Functionality; CM-10 Software Usage Restrictions
- **NIST SP 800-171 Rev. 2**: 3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; 3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
- **CMMC 2.0 Level 2**: CM.L2-3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; SC.L2-3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality

Risk

Insecure Application

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

### [Ensure Windows Apps Are Prevented From Sharing Application Data Between Users](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#windows-apps-are-prevented-from-sharing-application-data-between-users)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.4

**Finding:** Windows apps are allowed to share application data between users.

Checks whether a Windows app can share data between users through the shared SharedLocal folder.

This rule fails when `allowSharedLocalAppData` is not `false`.

**Rationale:** Users of the same system could accidentally share sensitive data with one another through the shared app data folder.

**Impact:** None - this is the default behavior; apps cannot share data with other instances via SharedLocal.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\App Package Deployment\Allow a Windows app to share application data between users** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\AppModel\StateManager" /v AllowSharedLocalAppData /t REG_DWORD /d 0 /f
```

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## 18.10.5 App Privacy

### [Ensure Voice Activation Of Apps While The System Is Locked Is Forced Off](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#voice-activation-of-apps-while-the-system-is-locked-is-forced-off)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.5

**Finding:** Apps are allowed to activate with voice while the system is locked.

Checks whether apps and Cortana can be activated by voice while the system is locked.

This rule fails when `letAppsActivateWithVoiceAboveLock` is not `FORCE_DENY`.

**Rationale:** No computer resource should be accessible via voice while the device is locked.

**Impact:** Users cannot activate apps by voice while the computer is locked.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\App Privacy\Let Windows apps activate with voice while the system is locked** and set it to **Enabled: Force Deny**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\AppPrivacy" /v LetAppsActivateWithVoiceAboveLock /t REG_DWORD /d 2 /f
```

Risk

Unprotected Principal

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## 18.10.6 App runtime

### [Ensure Launching Universal Windows Apps With WinRT Access From Hosted Content Is Blocked](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#launching-universal-windows-apps-with-winrt-access-from-hosted-content-is-blocke)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.6

**Finding:** Universal Windows apps with Windows Runtime API access from hosted web content can be launched.

Checks whether Store apps with direct Windows Runtime API access from web content are blocked from launching.

This rule fails when `blockHostedAppAccessWinRT` is not `true`.

**Rationale:** Blocking web apps with direct access to the Windows API prevents malicious apps from running on a system.

**Impact:** Universal Windows apps declaring Windows Runtime API access in their manifest cannot be launched.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\App runtime\Block launching Universal Windows apps with Windows Runtime API access from hosted content.** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v BlockHostedAppAccessWinRT /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 2.5 Allowlist Authorized Software
- **NIST SP 800-53 Rev. 5**: CM-7 Least Functionality; CM-10 Software Usage Restrictions
- **NIST SP 800-171 Rev. 2**: 3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; 3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
- **CMMC 2.0 Level 2**: CM.L2-3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; SC.L2-3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality

Risk

Insecure Application

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

### [Ensure Microsoft Accounts Are Optional For Store Apps](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#microsoft-accounts-are-optional-for-store-apps)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.6

**Finding:** Microsoft accounts are required for Store apps that support sign-in.

Checks whether Microsoft accounts are optional for Windows Store apps that require an account.

This rule fails when `msaOptional` is not `true`.

**Rationale:** Microsoft accounts cannot be centrally managed, so enterprise credential-security policies cannot be applied to them, putting any data accessed with them at risk.

**Impact:** Store apps that normally require a Microsoft account will allow sign-in with an enterprise account.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\App runtime\Allow Microsoft accounts to be optional** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v MSAOptional /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 5.6 Centralize Account Management
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management

Risk

Unprotected Principal

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## 18.10.8 AutoPlay Policies

### [Ensure Autoplay Is Disallowed For Non-Volume Devices](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#autoplay-is-disallowed-for-non-volume-devices)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.8

**Finding:** Autoplay is allowed for non-volume MTP devices.

Checks whether AutoPlay is disallowed for MTP devices such as cameras and phones.

This rule fails when `noAutoplayfornonVolume` is not `true`.

**Rationale:** A threat actor could use AutoPlay on an attached device to launch a program that damages the computer or its data.

**Impact:** AutoPlay will not be allowed for MTP devices like cameras or phones.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\AutoPlay Policies\Disallow Autoplay for non-volume devices** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Explorer" /v NoAutoplayfornonVolume /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 10.3 Disable Autorun and Autoplay for Removable Media
- **NIST SP 800-53 Rev. 5**: MP-7 Media Use
- **NIST SP 800-171 Rev. 2**: 3.8.7 Control the use of removable media on system components
- **CMMC 2.0 Level 2**: MP.L2-3.8.7 Control the use of removable media on system components

Risk

Insecure Application

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

### [Ensure Autoplay Is Turned Off For All Drives](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#autoplay-is-turned-off-for-all-drives)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.8

**Finding:** Autoplay is not turned off for all drive types.

Checks whether Autoplay, which starts reading media as soon as it is inserted, is turned off for all drives.

This rule fails when `noDriveTypeAutoRun` is not `ALL_DRIVES`.

**Rationale:** A threat actor could use Autoplay to launch a program that damages the computer or its data.

**Impact:** Autoplay is disabled; users must manually launch setup or installation programs from media.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\AutoPlay Policies\Turn off Autoplay** and set it to **Enabled: All drives**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoDriveTypeAutoRun /t REG_DWORD /d 255 /f
```

Framework mappings

- **CIS Controls v8**: 10.3 Disable Autorun and Autoplay for Removable Media
- **NIST SP 800-53 Rev. 5**: MP-7 Media Use
- **NIST SP 800-171 Rev. 2**: 3.8.7 Control the use of removable media on system components
- **CMMC 2.0 Level 2**: MP.L2-3.8.7 Control the use of removable media on system components

Risk

Insecure Application

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

### [Ensure The Default AutoRun Behavior Does Not Execute Any AutoRun Commands](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#the-default-autorun-behavior-does-not-execute-any-autorun-commands)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.8

**Finding:** The default AutoRun behavior permits execution of autorun commands.

Checks the default behavior for autorun commands (typically stored in autorun.inf files).

This rule fails when `noAutorun` is not `XP`.

**Rationale:** Automatically executing autorun commands when media is inserted allows code to run without the user's knowledge.

**Impact:** AutoRun commands will be completely disabled.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\AutoPlay Policies\Set the default behavior for AutoRun** and set it to **Enabled: Do not execute any autorun commands**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoAutorun /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 10.3 Disable Autorun and Autoplay for Removable Media
- **NIST SP 800-53 Rev. 5**: MP-7 Media Use
- **NIST SP 800-171 Rev. 2**: 3.8.7 Control the use of removable media on system components
- **CMMC 2.0 Level 2**: MP.L2-3.8.7 Control the use of removable media on system components

Risk

Insecure Application

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

## 18.10.9 Biometrics

### [Ensure Enhanced Anti-Spoofing For Facial Features Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#enhanced-anti-spoofing-for-facial-features-is-enabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.9.1

**Finding:** Enhanced anti-spoofing for facial features is not enabled.

Checks whether enhanced anti-spoofing is required for Windows Hello facial authentication on capable devices.

This rule fails when `enhancedAntiSpoofing` is not `true`.

**Rationale:** Strengthening biometric facial authentication helps protect against spoofing and unauthorized access.

**Impact:** All users on capable devices will be required to use anti-spoofing for facial recognition.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Biometrics\Facial Features\Configure enhanced anti-spoofing** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Biometrics\FacialFeatures" /v EnhancedAntiSpoofing /t REG_DWORD /d 1 /f
```

Risk

Unprotected Principal

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## 18.10.10 BitLocker Drive Encryption

### [Ensure A 256-Bit Recovery Key Is Allowed For BitLocker-Protected Fixed Data Drives](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#a-256-bit-recovery-key-is-allowed-for-bitlocker-protected-fixed-data-drives)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.1

**Finding:** A 256-bit recovery key is not allowed for BitLocker-protected fixed data drives.

Checks whether users may generate a 256-bit recovery key for BitLocker fixed data drives.

This rule fails when `fdvRecoveryKey` is not one of `ALLOW, REQUIRE`.

**Rationale:** Administrators must always have a secure, controlled way to recover encrypted data when users cannot access it.

**Impact:** A 256-bit recovery key will be permitted for fixed drives.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Fixed Data Drives\Choose how BitLocker-protected fixed drives can be recovered: Recovery Key** and set it to **Enabled: Allow 256-bit recovery key (or Require)**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v FDVRecoveryKey /t REG_DWORD /d 2 /f
```

Framework mappings

- **CIS Controls v8**: 3.6 Encrypt Data on End-User Devices
- **NIST SP 800-53 Rev. 5**: SC-28 Protection of Information at Rest
- **NIST SP 800-171 Rev. 2**: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
- **CMMC 2.0 Level 2**: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure A 48-Digit Recovery Password Is Allowed For BitLocker-Protected Fixed Data Drives](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#a-48-digit-recovery-password-is-allowed-for-bitlocker-protected-fixed-data-drive)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.1

**Finding:** A 48-digit recovery password is not allowed for BitLocker-protected fixed data drives.

Checks whether users may generate a 48-digit recovery password for BitLocker fixed data drives.

This rule fails when `fdvRecoveryPassword` is not one of `ALLOW, REQUIRE`.

**Rationale:** Administrators must always have a secure, controlled way to recover encrypted data when users cannot access it.

**Impact:** A 48-digit recovery password will be permitted for fixed drives.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Fixed Data Drives\Choose how BitLocker-protected fixed drives can be recovered: Recovery Password** and set it to **Enabled: Allow 48-digit recovery password (or Require)**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v FDVRecoveryPassword /t REG_DWORD /d 2 /f
```

Framework mappings

- **CIS Controls v8**: 3.6 Encrypt Data on End-User Devices
- **NIST SP 800-53 Rev. 5**: SC-28 Protection of Information at Rest
- **NIST SP 800-171 Rev. 2**: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
- **CMMC 2.0 Level 2**: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure A Data Recovery Agent Is Allowed For BitLocker-Protected Fixed Data Drives](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#a-data-recovery-agent-is-allowed-for-bitlocker-protected-fixed-data-drives)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.1

**Finding:** A Data Recovery Agent is not allowed for BitLocker-protected fixed data drives.

Checks whether a Data Recovery Agent may be used to recover BitLocker-protected fixed data drives.

This rule fails when `fdvManageDRA` is not `ALLOW`.

**Rationale:** Administrators must always have a secure, controlled way to recover encrypted data when users cannot access it.

**Impact:** None - this is the default behavior; a DRA is allowed for fixed drives.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Fixed Data Drives\Choose how BitLocker-protected fixed drives can be recovered: Allow data recovery agent** and set it to **Enabled: True (checked)**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v FDVManageDRA /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 3.6 Encrypt Data on End-User Devices
- **NIST SP 800-53 Rev. 5**: SC-28 Protection of Information at Rest
- **NIST SP 800-171 Rev. 2**: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
- **CMMC 2.0 Level 2**: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Access To BitLocker-Protected Fixed Data Drives From Earlier Windows Versions Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#access-to-bitlocker-protected-fixed-data-drives-from-earlier-windows-versions-is)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.1

**Finding:** BitLocker-protected fixed data drives are accessible from earlier versions of Windows.

REG_SZ

This rule fails when `fdvDiscoveryVolumeType` is not `false`.

**Rationale:** Checks whether FAT-formatted BitLocker fixed data drives can be unlocked on legacy Windows via the BitLocker To Go Reader.

**Impact:** The BitLocker To Go Reader placed on the unencrypted portion of the drive is, like any app, subject to spoofing and could propagate malware.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Fixed Data Drives\Allow access to BitLocker-protected fixed data drives from earlier versions of Windows** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v FDVDiscoveryVolumeType /t FAT BitLocker fixed data drives cannot be unlocked on legacy Windows and BitLockerToGo.exe is not installed. /d "" /f
```

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Hardware-Based Encryption For BitLocker Fixed Data Drives Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#hardware-based-encryption-for-bitlocker-fixed-data-drives-is-disabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.1

**Finding:** Hardware-based encryption is used for BitLocker fixed data drives.

Checks whether BitLocker uses hardware-based encryption for fixed data drives.

This rule fails when `fdvHardwareEncryption` is not `false`.

**Rationale:** Hardware-based encryption on some self-encrypting drives has firmware vulnerabilities; software encryption avoids that risk.

**Impact:** None - this is the default behavior; BitLocker uses software-based encryption for fixed drives.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Fixed Data Drives\Configure use of hardware-based encryption for fixed data drives** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v FDVHardwareEncryption /t REG_DWORD /d 0 /f
```

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Password Unlock For BitLocker Fixed Data Drives Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#password-unlock-for-bitlocker-fixed-data-drives-is-disabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.1

**Finding:** Password unlock is permitted for BitLocker fixed data drives.

Checks whether a password may be used to unlock BitLocker-protected fixed data drives.

This rule fails when `fdvPassphrase` is not `false`.

**Rationale:** BitLocker passwords lack TPM anti-hammering protection, so there is no throttle against rapid brute-force guessing.

**Impact:** The password option will not be available when configuring BitLocker for fixed drives.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Fixed Data Drives\Configure use of passwords for fixed data drives** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v FDVPassphrase /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 5.2 Use Unique Passwords
- **NIST SP 800-53 Rev. 5**: IA-5 Authenticator Management
- **NIST SP 800-171 Rev. 2**: 3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- **CMMC 2.0 Level 2**: IA.L2-3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- **PCI DSS v4.0.1**: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 8.3.5 Use unique initial passwords and force change on first use; 8.3.6 Enforce 12-character minimum password length with letters and numbers; 8.6.3 Rotate and harden passwords for application and system-level accounts

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Recovery Of BitLocker-Protected Fixed Data Drives Is Configured](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#recovery-of-bitlocker-protected-fixed-data-drives-is-configured)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.1

**Finding:** Recovery of BitLocker-protected fixed data drives is not configured.

Checks whether recovery options for BitLocker-protected fixed data drives are governed by policy.

This rule fails when `fdvRecovery` is not `true`.

**Rationale:** Administrators must always have a secure, controlled way to recover encrypted data when users cannot access it.

**Impact:** A Data Recovery Agent must be configured for fixed drives; recovery requires controlled access to its private key.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Fixed Data Drives\Choose how BitLocker-protected fixed drives can be recovered** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v FDVRecovery /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 3.6 Encrypt Data on End-User Devices
- **NIST SP 800-53 Rev. 5**: SC-28 Protection of Information at Rest
- **NIST SP 800-171 Rev. 2**: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
- **CMMC 2.0 Level 2**: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Recovery Options Are Omitted From The BitLocker Setup Wizard For Fixed Data Drives](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#recovery-options-are-omitted-from-the-bitlocker-setup-wizard-for-fixed-data-driv)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.1

**Finding:** Recovery options are not omitted from the BitLocker setup wizard for fixed data drives.

Checks whether users are prevented from choosing recovery options during BitLocker setup of fixed data drives.

This rule fails when `fdvHideRecoveryPage` is not `HIDE`.

**Rationale:** Recovery options should be dictated by policy rather than left to users, ensuring a controlled recovery path.

**Impact:** Users cannot manually select recovery options for fixed drives in the BitLocker setup wizard.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Fixed Data Drives\Choose how BitLocker-protected fixed drives can be recovered: Omit recovery options from the BitLocker setup wizard** and set it to **Enabled: True (checked)**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v FDVHideRecoveryPage /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 3.6 Encrypt Data on End-User Devices
- **NIST SP 800-53 Rev. 5**: SC-28 Protection of Information at Rest
- **NIST SP 800-171 Rev. 2**: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
- **CMMC 2.0 Level 2**: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Smart Card Use For BitLocker Fixed Data Drives Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#smart-card-use-for-bitlocker-fixed-data-drives-is-enabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.1

**Finding:** Smart card use for BitLocker fixed data drives is not enabled.

Checks whether smart cards may be used to authenticate access to BitLocker fixed data drives.

This rule fails when `fdvAllowUserCert` is not `true`.

**Rationale:** A drive protected only by a guessable secret or an auto-unlock can be compromised if lost or stolen; smart cards raise the bar.

**Impact:** None - this is the default behavior; users may use smart cards to unlock fixed data drives.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Fixed Data Drives\Configure use of smart cards on fixed data drives** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v FDVAllowUserCert /t REG_DWORD /d 1 /f
```

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Smart Card Use Is Required For BitLocker Fixed Data Drives](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#smart-card-use-is-required-for-bitlocker-fixed-data-drives)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.1

**Finding:** Smart card use is not required for BitLocker fixed data drives.

Checks whether a smart card is required to authenticate access to BitLocker fixed data drives.

This rule fails when `fdvEnforceUserCert` is not `REQUIRED`.

**Rationale:** Requiring a smart card removes weaker unlock options and ties drive access to PKI-backed credentials.

**Impact:** Smart cards are required to unlock fixed data drives; users must authenticate with the card each restart.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Fixed Data Drives\Configure use of smart cards on fixed data drives: Require use of smart cards on fixed data drives** and set it to **Enabled: True (checked)**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v FDVEnforceUserCert /t REG_DWORD /d 1 /f
```

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure A 256-Bit Recovery Key Is Not Allowed For BitLocker-Protected Operating System Drives](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#a-256-bit-recovery-key-is-not-allowed-for-bitlocker-protected-operating-system-d)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.2

**Finding:** A 256-bit recovery key is allowed for BitLocker-protected operating system drives.

Checks whether a 256-bit recovery key may be generated for BitLocker-protected OS drives.

This rule fails when `osRecoveryKey` is not `DISALLOW`.

**Rationale:** Standardizing OS-drive recovery on the 48-digit password avoids reliance on key files that are easily lost or copied.

**Impact:** A 256-bit recovery key is not permitted for the OS drive; users must be domain-connected to turn on BitLocker.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Operating System Drives\Choose how BitLocker-protected operating system drives can be recovered: Recovery Key** and set it to **Enabled: Do not allow 256-bit recovery key**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v OSRecoveryKey /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 3.6 Encrypt Data on End-User Devices
- **NIST SP 800-53 Rev. 5**: SC-28 Protection of Information at Rest
- **NIST SP 800-171 Rev. 2**: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
- **CMMC 2.0 Level 2**: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure A 48-Digit Recovery Password Is Required For BitLocker-Protected Operating System Drives](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#a-48-digit-recovery-password-is-required-for-bitlocker-protected-operating-syste)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.2

**Finding:** A 48-digit recovery password is not required for BitLocker-protected operating system drives.

Checks whether a 48-digit recovery password is required for BitLocker-protected OS drives.

This rule fails when `osRecoveryPassword` is not `REQUIRE`.

**Rationale:** A required recovery password ensures a reliable way back into the encrypted OS volume if the primary unlock method fails.

**Impact:** A 48-digit recovery password is required for the OS drive; users must be domain-connected to turn on BitLocker.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Operating System Drives\Choose how BitLocker-protected operating system drives can be recovered: Recovery Password** and set it to **Enabled: Require 48-digit recovery password**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v OSRecoveryPassword /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 3.6 Encrypt Data on End-User Devices
- **NIST SP 800-53 Rev. 5**: SC-28 Protection of Information at Rest
- **NIST SP 800-171 Rev. 2**: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
- **CMMC 2.0 Level 2**: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure A Data Recovery Agent Is Not Allowed For BitLocker-Protected Operating System Drives](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#a-data-recovery-agent-is-not-allowed-for-bitlocker-protected-operating-system-dr)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.2

**Finding:** A Data Recovery Agent is allowed for BitLocker-protected operating system drives.

Checks whether a Data Recovery Agent may be used to recover BitLocker-protected OS drives.

This rule fails when `osManageDRA` is not `DISALLOW`.

**Rationale:** Recovery of the OS volume should rely on a backed-up recovery password rather than a DRA private key that could itself be abused.

**Impact:** A Data Recovery Agent is not permitted for the OS drive; users must be domain-connected to turn on BitLocker.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Operating System Drives\Choose how BitLocker-protected operating system drives can be recovered: Allow data recovery agent** and set it to **Enabled: False (unchecked)**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v OSManageDRA /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 3.6 Encrypt Data on End-User Devices
- **NIST SP 800-53 Rev. 5**: SC-28 Protection of Information at Rest
- **NIST SP 800-171 Rev. 2**: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
- **CMMC 2.0 Level 2**: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Enhanced PINs For BitLocker Startup Are Allowed](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#enhanced-pins-for-bitlocker-startup-are-allowed)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.2

**Finding:** Enhanced PINs for BitLocker startup are not allowed.

Checks whether enhanced startup PINs (letters, symbols, numbers, spaces) are allowed for BitLocker.

This rule fails when `useEnhancedPin` is not `true`.

**Rationale:** A numeric-only PIN provides far less entropy, making brute-force attacks against startup authentication more feasible.

**Impact:** All newly set BitLocker startup PINs will be enhanced PINs.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Operating System Drives\Allow enhanced PINs for startup** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v UseEnhancedPin /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 5.2 Use Unique Passwords
- **NIST SP 800-53 Rev. 5**: IA-5 Authenticator Management
- **NIST SP 800-171 Rev. 2**: 3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- **CMMC 2.0 Level 2**: IA.L2-3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- **PCI DSS v4.0.1**: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 8.3.5 Use unique initial passwords and force change on first use; 8.3.6 Enforce 12-character minimum password length with letters and numbers; 8.6.3 Rotate and harden passwords for application and system-level accounts

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Hardware-Based Encryption For BitLocker Operating System Drives Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#hardware-based-encryption-for-bitlocker-operating-system-drives-is-disabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.2

**Finding:** Hardware-based encryption is used for BitLocker operating system drives.

Checks whether BitLocker uses hardware-based encryption for the operating system drive.

This rule fails when `osHardwareEncryption` is not `false`.

**Rationale:** Hardware-based encryption on some self-encrypting drives has firmware vulnerabilities; software encryption avoids that risk.

**Impact:** None - this is the default behavior; BitLocker uses software-based encryption for the OS drive.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Operating System Drives\Configure use of hardware-based encryption for operating system drives** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v OSHardwareEncryption /t REG_DWORD /d 0 /f
```

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Recovery Of BitLocker-Protected Operating System Drives Is Configured](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#recovery-of-bitlocker-protected-operating-system-drives-is-configured)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.2

**Finding:** Recovery of BitLocker-protected operating system drives is not configured.

Checks whether recovery options for BitLocker-protected OS drives are governed by policy.

This rule fails when `osRecovery` is not `true`.

**Rationale:** If the OS volume fails integrity checks or the key is lost and recovery info was not backed up, the user may be permanently denied access to the encrypted data.

**Impact:** Users must be domain-connected to turn on BitLocker; this configuration is not FIPS compliant.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Operating System Drives\Choose how BitLocker-protected operating system drives can be recovered** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v OSRecovery /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 3.6 Encrypt Data on End-User Devices
- **NIST SP 800-53 Rev. 5**: SC-28 Protection of Information at Rest
- **NIST SP 800-171 Rev. 2**: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
- **CMMC 2.0 Level 2**: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Recovery Options Are Omitted From The BitLocker Setup Wizard For Operating System Drives](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#recovery-options-are-omitted-from-the-bitlocker-setup-wizard-for-operating-syste)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.2

**Finding:** Recovery options are not omitted from the BitLocker setup wizard for operating system drives.

Checks whether users are prevented from choosing recovery options during BitLocker setup of OS drives.

This rule fails when `osHideRecoveryPage` is not `HIDE`.

**Rationale:** Recovery options should be dictated by policy rather than left to users, ensuring a controlled recovery path.

**Impact:** Users cannot manually select recovery options for the OS drive in the BitLocker setup wizard.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Operating System Drives\Choose how BitLocker-protected operating system drives can be recovered: Omit recovery options from the BitLocker setup wizard** and set it to **Enabled: True (checked)**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v OSHideRecoveryPage /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 3.6 Encrypt Data on End-User Devices
- **NIST SP 800-53 Rev. 5**: SC-28 Protection of Information at Rest
- **NIST SP 800-171 Rev. 2**: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
- **CMMC 2.0 Level 2**: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Secure Boot For BitLocker Integrity Validation Is Allowed](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#secure-boot-for-bitlocker-integrity-validation-is-allowed)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.2

**Finding:** Secure Boot is not allowed for BitLocker integrity validation.

Checks whether Secure Boot may serve as the platform integrity provider for BitLocker OS drives.

This rule fails when `osAllowSecureBootForIntegrity` is not `true`.

**Rationale:** Secure Boot loads only firmware signed by authorized publishers during startup, reducing the risk of rootkits and boot-time malware.

**Impact:** None - this is the default behavior; BitLocker uses Secure Boot for integrity when capable.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Operating System Drives\Allow Secure Boot for integrity validation** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v OSAllowSecureBootForIntegrity /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 10.5 Enable Anti-Exploitation Features
- **NIST SP 800-53 Rev. 5**: SI-16 Memory Protection

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure A 256-Bit Recovery Key Is Not Allowed For BitLocker-Protected Removable Data Drives](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#a-256-bit-recovery-key-is-not-allowed-for-bitlocker-protected-removable-data-dri)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.3

**Finding:** A 256-bit recovery key is allowed for BitLocker-protected removable data drives.

Checks whether a 256-bit recovery key may be generated for BitLocker removable data drives.

This rule fails when `rdvRecoveryKey` is not `DISALLOW`.

**Rationale:** Restricting user-chosen recovery secrets on portable media reduces the chance of weak, lost, or copied recovery material accompanying a stolen drive.

**Impact:** A 256-bit recovery key will not be permitted for removable drives.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Removable Data Drives\Choose how BitLocker-protected removable drives can be recovered: Recovery Key** and set it to **Enabled: Do not allow 256-bit recovery key**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v RDVRecoveryKey /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 3.9 Encrypt Data on Removable Media
- **NIST SP 800-53 Rev. 5**: MP-5 Media Transport; MP-7 Media Use
- **NIST SP 800-171 Rev. 2**: 3.8.7 Control the use of removable media on system components
- **CMMC 2.0 Level 2**: MP.L2-3.8.7 Control the use of removable media on system components
- **PCI DSS v4.0.1**: 3.5.1.2 Restrict disk- or partition-level PAN encryption to removable media or paired controls

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure A 48-Digit Recovery Password Is Not Allowed For BitLocker-Protected Removable Data Drives](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#a-48-digit-recovery-password-is-not-allowed-for-bitlocker-protected-removable-da)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.3

**Finding:** A 48-digit recovery password is allowed for BitLocker-protected removable data drives.

Checks whether a 48-digit recovery password may be generated for BitLocker removable data drives.

This rule fails when `rdvRecoveryPassword` is not `DISALLOW`.

**Rationale:** Restricting user-chosen recovery secrets on portable media reduces the chance of weak, lost, or copied recovery material accompanying a stolen drive.

**Impact:** A 48-digit recovery password will not be permitted for removable drives.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Removable Data Drives\Choose how BitLocker-protected removable drives can be recovered: Recovery Password** and set it to **Enabled: Do not allow 48-digit recovery password**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v RDVRecoveryPassword /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 3.9 Encrypt Data on Removable Media
- **NIST SP 800-53 Rev. 5**: MP-5 Media Transport; MP-7 Media Use
- **NIST SP 800-171 Rev. 2**: 3.8.7 Control the use of removable media on system components
- **CMMC 2.0 Level 2**: MP.L2-3.8.7 Control the use of removable media on system components
- **PCI DSS v4.0.1**: 3.5.1.2 Restrict disk- or partition-level PAN encryption to removable media or paired controls

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure A Data Recovery Agent Is Allowed For BitLocker-Protected Removable Data Drives](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#a-data-recovery-agent-is-allowed-for-bitlocker-protected-removable-data-drives)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.3

**Finding:** A Data Recovery Agent is not allowed for BitLocker-protected removable data drives.

Checks whether a Data Recovery Agent may be used to recover BitLocker-protected removable data drives.

This rule fails when `rdvManageDRA` is not `ALLOW`.

**Rationale:** Administrators must always have a secure, controlled way to recover encrypted data when users cannot access it.

**Impact:** None - this is the default behavior; a DRA is allowed for removable drives.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Removable Data Drives\Choose how BitLocker-protected removable drives can be recovered: Allow data recovery agent** and set it to **Enabled: True (checked)**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v RDVManageDRA /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 3.9 Encrypt Data on Removable Media
- **NIST SP 800-53 Rev. 5**: MP-5 Media Transport; MP-7 Media Use
- **NIST SP 800-171 Rev. 2**: 3.8.7 Control the use of removable media on system components
- **CMMC 2.0 Level 2**: MP.L2-3.8.7 Control the use of removable media on system components
- **PCI DSS v4.0.1**: 3.5.1.2 Restrict disk- or partition-level PAN encryption to removable media or paired controls

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Access To BitLocker-Protected Removable Data Drives From Earlier Windows Versions Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#access-to-bitlocker-protected-removable-data-drives-from-earlier-windows-version)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.3

**Finding:** BitLocker-protected removable data drives are accessible from earlier versions of Windows.

REG_SZ

This rule fails when `rdvDiscoveryVolumeType` is not `false`.

**Rationale:** Checks whether FAT-formatted BitLocker removable data drives can be unlocked on legacy Windows via the BitLocker To Go Reader.

**Impact:** The BitLocker To Go Reader placed on the unencrypted portion of the drive is, like any app, subject to spoofing and could propagate malware.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Removable Data Drives\Allow access to BitLocker-protected removable data drives from earlier versions of Windows** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v RDVDiscoveryVolumeType /t FAT BitLocker removable drives cannot be unlocked on legacy Windows and BitLockerToGo.exe is not installed. /d "" /f
```

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Cross-Organization Write Access For BitLocker Removable Drives Is Not Denied](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#cross-organization-write-access-for-bitlocker-removable-drives-is-not-denied)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.3

**Finding:** Write access to BitLocker removable drives configured in another organization is denied.

Checks whether the computer may write to BitLocker removable drives that were configured in another organization.

This rule fails when `rdvDenyCrossOrg` is not `false`.

**Rationale:** Denying cross-organization write access can hinder legitimate encrypted data sharing between business partners.

**Impact:** None - this is the default behavior; write access to cross-organization BitLocker removable drives is permitted.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Removable Data Drives\Deny write access to removable drives not protected by BitLocker: Do not allow write access to devices configured in another organization** and set it to **Enabled: False (unchecked)**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v RDVDenyCrossOrg /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 3.9 Encrypt Data on Removable Media
- **NIST SP 800-53 Rev. 5**: MP-5 Media Transport; MP-7 Media Use
- **NIST SP 800-171 Rev. 2**: 3.8.7 Control the use of removable media on system components
- **CMMC 2.0 Level 2**: MP.L2-3.8.7 Control the use of removable media on system components
- **PCI DSS v4.0.1**: 3.5.1.2 Restrict disk- or partition-level PAN encryption to removable media or paired controls

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Hardware-Based Encryption For BitLocker Removable Data Drives Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#hardware-based-encryption-for-bitlocker-removable-data-drives-is-disabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.3

**Finding:** Hardware-based encryption is used for BitLocker removable data drives.

Checks whether BitLocker uses hardware-based encryption for removable data drives.

This rule fails when `rdvHardwareEncryption` is not `false`.

**Rationale:** Hardware-based encryption on some self-encrypting drives has firmware vulnerabilities; software encryption avoids that risk.

**Impact:** None - this is the default behavior; BitLocker uses software-based encryption for removable drives.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Removable Data Drives\Configure use of hardware-based encryption for removable data drives** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v RDVHardwareEncryption /t REG_DWORD /d 0 /f
```

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Password Unlock For BitLocker Removable Data Drives Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#password-unlock-for-bitlocker-removable-data-drives-is-disabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.3

**Finding:** Password unlock is permitted for BitLocker removable data drives.

Checks whether a password may be used to unlock BitLocker-protected removable data drives.

This rule fails when `rdvPassphrase` is not `false`.

**Rationale:** BitLocker passwords lack TPM anti-hammering protection, so there is no throttle against rapid brute-force guessing.

**Impact:** The password option will not be available when configuring BitLocker for removable drives.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Removable Data Drives\Configure use of passwords for removable data drives** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v RDVPassphrase /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 5.2 Use Unique Passwords
- **NIST SP 800-53 Rev. 5**: IA-5 Authenticator Management
- **NIST SP 800-171 Rev. 2**: 3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- **CMMC 2.0 Level 2**: IA.L2-3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- **PCI DSS v4.0.1**: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 8.3.5 Use unique initial passwords and force change on first use; 8.3.6 Enforce 12-character minimum password length with letters and numbers; 8.6.3 Rotate and harden passwords for application and system-level accounts

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Recovery Of BitLocker-Protected Removable Data Drives Is Configured](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#recovery-of-bitlocker-protected-removable-data-drives-is-configured)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.3

**Finding:** Recovery of BitLocker-protected removable data drives is not configured.

Checks whether recovery options for BitLocker-protected removable data drives are governed by policy.

This rule fails when `rdvRecovery` is not `true`.

**Rationale:** Administrators must always have a secure, controlled way to recover encrypted data when users cannot access it.

**Impact:** A Data Recovery Agent must be configured for removable drives; recovery requires controlled access to its private key.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Removable Data Drives\Choose how BitLocker-protected removable drives can be recovered** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v RDVRecovery /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 3.9 Encrypt Data on Removable Media
- **NIST SP 800-53 Rev. 5**: MP-5 Media Transport; MP-7 Media Use
- **NIST SP 800-171 Rev. 2**: 3.8.7 Control the use of removable media on system components
- **CMMC 2.0 Level 2**: MP.L2-3.8.7 Control the use of removable media on system components
- **PCI DSS v4.0.1**: 3.5.1.2 Restrict disk- or partition-level PAN encryption to removable media or paired controls

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Recovery Options Are Omitted From The BitLocker Setup Wizard For Removable Data Drives](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#recovery-options-are-omitted-from-the-bitlocker-setup-wizard-for-removable-data)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.3

**Finding:** Recovery options are not omitted from the BitLocker setup wizard for removable data drives.

Checks whether users are prevented from choosing recovery options during BitLocker setup of removable data drives.

This rule fails when `rdvHideRecoveryPage` is not `HIDE`.

**Rationale:** Recovery options should be dictated by policy rather than left to users, ensuring a controlled recovery path.

**Impact:** Users cannot manually select recovery options for removable drives in the BitLocker setup wizard.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Removable Data Drives\Choose how BitLocker-protected removable drives can be recovered: Omit recovery options from the BitLocker setup wizard** and set it to **Enabled: True (checked)**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v RDVHideRecoveryPage /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 3.9 Encrypt Data on Removable Media
- **NIST SP 800-53 Rev. 5**: MP-5 Media Transport; MP-7 Media Use
- **NIST SP 800-171 Rev. 2**: 3.8.7 Control the use of removable media on system components
- **CMMC 2.0 Level 2**: MP.L2-3.8.7 Control the use of removable media on system components
- **PCI DSS v4.0.1**: 3.5.1.2 Restrict disk- or partition-level PAN encryption to removable media or paired controls

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Smart Card Use For BitLocker Removable Data Drives Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#smart-card-use-for-bitlocker-removable-data-drives-is-enabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.3

**Finding:** Smart card use for BitLocker removable data drives is not enabled.

Checks whether smart cards may be used to authenticate access to BitLocker removable data drives.

This rule fails when `rdvAllowUserCert` is not `true`.

**Rationale:** A drive protected only by a guessable secret or an auto-unlock can be compromised if lost or stolen; smart cards raise the bar.

**Impact:** None - this is the default behavior; users may use smart cards to unlock removable data drives.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Removable Data Drives\Configure use of smart cards on removable data drives** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v RDVAllowUserCert /t REG_DWORD /d 1 /f
```

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Smart Card Use Is Required For BitLocker Removable Data Drives](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#smart-card-use-is-required-for-bitlocker-removable-data-drives)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.3

**Finding:** Smart card use is not required for BitLocker removable data drives.

Checks whether a smart card is required to authenticate access to BitLocker removable data drives.

This rule fails when `rdvEnforceUserCert` is not `REQUIRED`.

**Rationale:** Requiring a smart card removes weaker unlock options and ties drive access to PKI-backed credentials.

**Impact:** Smart cards are required to unlock removable data drives; users must authenticate with the card each restart.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Removable Data Drives\Configure use of smart cards on removable data drives: Require use of smart cards on removable data drives** and set it to **Enabled: True (checked)**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\FVE" /v RDVEnforceUserCert /t REG_DWORD /d 1 /f
```

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Write Access To Removable Drives Not Protected By BitLocker Is Denied](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#write-access-to-removable-drives-not-protected-by-bitlocker-is-denied)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.10.3

**Finding:** Write access is permitted to removable drives not protected by BitLocker.

Checks whether removable data drives must be BitLocker-protected before the computer can write to them.

This rule fails when `rdvDenyWriteAccess` is not `true`.

**Rationale:** Without this control, users may save sensitive data to removable media that was never encrypted.

**Impact:** Removable drives not protected by BitLocker are mounted read-only; protected drives get read/write access.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\BitLocker Drive Encryption\Removable Data Drives\Deny write access to removable drives not protected by BitLocker** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SYSTEM\CurrentControlSet\Policies\Microsoft\FVE" /v RDVDenyWriteAccess /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 3.9 Encrypt Data on Removable Media
- **NIST SP 800-53 Rev. 5**: MP-5 Media Transport; MP-7 Media Use
- **NIST SP 800-171 Rev. 2**: 3.8.7 Control the use of removable media on system components
- **CMMC 2.0 Level 2**: MP.L2-3.8.7 Control the use of removable media on system components
- **PCI DSS v4.0.1**: 3.5.1.2 Restrict disk- or partition-level PAN encryption to removable media or paired controls

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## 18.10.11 Camera

### [Ensure Use Of The Camera Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#use-of-the-camera-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.11

**Finding:** Use of the camera is permitted.

Checks whether camera devices on the machine are permitted for use.

This rule fails when `allowCamera` is not `false`.

**Rationale:** In high-security environments a camera poses privacy and data-exfiltration risks and should be disabled.

**Impact:** Users will not be able to use the camera on the system.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Camera\Allow Use of Camera** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Camera" /v AllowCamera /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## 18.10.13 Cloud Content

### [Ensure Cloud Consumer Account State Content Is Turned Off](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#cloud-consumer-account-state-content-is-turned-off)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.13

**Finding:** Cloud consumer account state content is allowed in Windows experiences.

Checks whether cloud consumer account state content is allowed across Windows experiences.

This rule fails when `disableConsumerAccountStateContent` is not `true`.

**Rationale:** Using consumer accounts in an enterprise-managed environment can lead to data leakage.

**Impact:** Windows experiences present default fallback content instead of consumer-account content.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Cloud Content\Turn off cloud consumer account state content** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\CloudContent" /v DisableConsumerAccountStateContent /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 5.6 Centralize Account Management
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Cloud Optimized Content Is Turned Off](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#cloud-optimized-content-is-turned-off)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.13

**Finding:** Cloud optimized content is allowed in Windows experiences.

Checks whether cloud-optimized content is turned off across Windows experiences.

This rule fails when `disableCloudOptimizedContent` is not `true`.

**Rationale:** Data should not be shared with third parties without explicit consent, as it may contain sensitive information.

**Impact:** Windows experiences present default fallback content instead of cloud-optimized content.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Cloud Content\Turn off cloud optimized content** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\CloudContent" /v DisableCloudOptimizedContent /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Microsoft Consumer Experiences Are Turned Off](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#microsoft-consumer-experiences-are-turned-off)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.13

**Finding:** Microsoft consumer experiences are enabled.

Checks whether consumer experiences such as suggested apps and Microsoft-account notifications are turned off.

This rule fails when `disableWindowsConsumerFeatures` is not `true`.

**Rationale:** Silent app installs in an enterprise environment, especially ones that send data to third parties, are poor security practice.

**Impact:** Users no longer see personalized Microsoft recommendations or Microsoft-account notifications.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Cloud Content\Turn off Microsoft consumer experiences** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\CloudContent" /v DisableWindowsConsumerFeatures /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## 18.10.14 Connect

### [Ensure A PIN Is Required For Wireless Display Pairing](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#a-pin-is-required-for-wireless-display-pairing)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.14

**Finding:** A PIN is not required for wireless display pairing.

Checks whether a PIN is required when pairing to a wireless display device.

This rule fails when `requirePinForPairing` is not one of `FIRST_TIME, ALWAYS`.

**Rationale:** Without a required pairing PIN, wireless display devices can be paired without authorization, increasing risk of misuse.

**Impact:** The pairing ceremony for new wireless display devices will require a PIN.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Connect\Require pin for pairing** and set it to **Enabled: First Time (or Always)**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Connect" /v RequirePinForPairing /t REG_DWORD /d 1 /f
```

Risk

Unprotected Principal

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## 18.10.15 Credential User Interface

### [Ensure Administrator Accounts Are Not Enumerated On Elevation](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#administrator-accounts-are-not-enumerated-on-elevation)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.15

**Finding:** Administrator accounts are enumerated during elevation.

Checks whether administrator accounts are listed when a user attempts to elevate an application.

This rule fails when `enumerateAdministrators` is not `false`.

**Rationale:** Displaying the administrator account list makes it slightly easier for a local attacker to target and crack those accounts.

**Impact:** None - this is the default behavior; users must always type a username and password to elevate.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Credential User Interface\Enumerate administrator accounts on elevation** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\CredUI" /v EnumerateAdministrators /t REG_DWORD /d 0 /f
```

Risk

Unprotected Principal

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure Security Questions For Local Accounts Are Prevented](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#security-questions-for-local-accounts-are-prevented)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.15

**Finding:** Security questions can be used to reset local account passwords.

Checks whether security questions can be used to reset local account passwords.

This rule fails when `noLocalPasswordResetQuestions` is not `true`.

**Rationale:** Security questions are often easily guessed or researched via social media, letting an attacker reset a local password and take over the account.

**Impact:** Local accounts cannot set up or use security questions to reset their passwords.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Credential User Interface\Prevent the use of security questions for local accounts** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v NoLocalPasswordResetQuestions /t REG_DWORD /d 1 /f
```

Risk

Unprotected Principal

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure The Password Reveal Button Is Not Displayed](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#the-password-reveal-button-is-not-displayed)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.15

**Finding:** The password reveal button is displayed in password entry fields.

Checks whether the password reveal button is shown in password entry experiences.

This rule fails when `disablePasswordReveal` is not `true`.

**Rationale:** The reveal button can display a typed password on screen, where a nearby observer could read it.

**Impact:** The password reveal button will not appear after a user types a password.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Credential User Interface\Do not display the password reveal button** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\CredUI" /v DisablePasswordReveal /t REG_DWORD /d 1 /f
```

Risk

Unprotected Principal

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

## 18.10.16 Data Collection and Preview Builds

### [Ensure Authenticated Proxy Usage For The Connected User Experience And Telemetry Service Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#authenticated-proxy-usage-for-the-connected-user-experience-and-telemetry-servic)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.16

**Finding:** The Connected User Experience and Telemetry service may use an authenticated proxy.

Checks whether the Connected User Experience and Telemetry service is blocked from automatically using an authenticated proxy.

This rule fails when `disableEnterpriseAuthProxy` is not `true`.

**Rationale:** Data should not be shared with third parties without explicit consent, as it may contain sensitive information.

**Impact:** The telemetry service is blocked from automatically using an authenticated proxy to send data to Microsoft.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Data Collection and Preview Builds\Configure Authenticated Proxy usage for the Connected User Experience and Telemetry service** and set it to **Enabled: Disable Authenticated Proxy usage**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DataCollection" /v DisableEnterpriseAuthProxy /t REG_DWORD /d 1 /f
```

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Diagnostic Data Is Limited To Required Or Off](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#diagnostic-data-is-limited-to-required-or-off)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.16

**Finding:** Diagnostic data is set above the required level.

Checks the amount of diagnostic and usage data the device reports to Microsoft.

This rule fails when `allowTelemetry` is not one of `SECURITY, BASIC`.

**Rationale:** Sending optional or full diagnostic data may transmit sensitive information to a third party without explicit consent.

**Impact:** The device sends at most the required diagnostic data (or none), limiting data shared with Microsoft.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Data Collection and Preview Builds\Allow Diagnostic Data** and set it to **Enabled: Diagnostic data off (or Send required diagnostic data)**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DataCollection" /v AllowTelemetry /t REG_DWORD /d 0 /f
```

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Diagnostic Log Collection Is Limited](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#diagnostic-log-collection-is-limited)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.16

**Finding:** Diagnostic log collection is not limited.

Checks whether the collection of additional diagnostic logs for troubleshooting is limited.

This rule fails when `limitDiagnosticLogCollection` is not `true`.

**Rationale:** Data should not be shared with third parties without explicit consent, as it may contain sensitive information.

**Impact:** Diagnostic logs and crash dumps will not be collected for transmission to Microsoft.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Data Collection and Preview Builds\Limit Diagnostic Log Collection** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DataCollection" /v LimitDiagnosticLogCollection /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Dump Collection Is Limited](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#dump-collection-is-limited)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.16

**Finding:** Dump collection is not limited.

Checks whether the type of memory dumps collected for troubleshooting is limited.

This rule fails when `limitDumpCollection` is not `true`.

**Rationale:** Data should not be shared with third parties without explicit consent, as memory dumps may contain sensitive information.

**Impact:** Error reporting is limited to kernel mini and user-mode triage dumps, reducing sensitive data sent to Microsoft.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Data Collection and Preview Builds\Limit Dump Collection** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DataCollection" /v LimitDumpCollection /t REG_DWORD /d 1 /f
```

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Feedback Notifications Are Not Shown](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#feedback-notifications-are-not-shown)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.16

**Finding:** Feedback notifications from Microsoft are shown.

Checks whether devices are prevented from showing Microsoft feedback questions.

This rule fails when `doNotShowFeedbackNotifications` is not `true`.

**Rationale:** Data should not be shared with third parties without explicit consent, as it may contain sensitive information.

**Impact:** Users no longer see feedback notifications through the Windows Feedback app.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Data Collection and Preview Builds\Do not show feedback notifications** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DataCollection" /v DoNotShowFeedbackNotifications /t REG_DWORD /d 1 /f
```

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure OneSettings Auditing Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#onesettings-auditing-is-enabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.16

**Finding:** OneSettings auditing is not enabled.

Checks whether Windows records attempts to connect with the OneSettings service to the Event Log.

This rule fails when `enableOneSettingsAuditing` is not `true`.

**Rationale:** Without these records it may be difficult to determine the root cause of problems or to detect unauthorized activity.

**Impact:** Windows records OneSettings connection attempts to the Privacy-Auditing operational log channel.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Data Collection and Preview Builds\Enable OneSettings Auditing** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DataCollection" /v EnableOneSettingsAuditing /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 8.5 Collect Detailed Audit Logs
- **NIST SP 800-53 Rev. 5**: AU-3 Content of Audit Records; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation; SI-4 System Monitoring
- **PCI DSS v4.0.1**: 9.4.5 Keep a log-based inventory of electronic media holding cardholder data; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.5 Record account creation, privilege elevation, and other credential changes

Risk

High Profile Threat

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

## 18.10.17 Delivery Optimization

### [Ensure Delivery Optimization Download Mode Is Not Set To Internet](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#delivery-optimization-download-mode-is-not-set-to-internet)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.17

**Finding:** Delivery Optimization download mode is set to Internet.

Checks the Delivery Optimization download method used for Windows Updates, apps, and app updates.

This rule fails when `doDownloadMode` is `INTERNET` (or is not set).

**Rationale:** Updates should come only from Microsoft or a trusted internal peer, not from arbitrary peers across the public Internet.

**Impact:** Machines will not download updates from peers on the Internet.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Delivery Optimization\Download Mode** and set it to **any value other than Enabled: Internet (3)**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeliveryOptimization" /v DODownloadMode /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 7.3 Perform Automated Operating System Patch Management
- **NIST SP 800-53 Rev. 5**: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation

Risk

External Attack Surface

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## 18.10.18 Desktop App Installer

### [Ensure App Installer Experimental Features Are Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#app-installer-experimental-features-are-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.18

**Finding:** App Installer experimental features are enabled.

Checks whether users can enable experimental features in the Windows Package Manager.

This rule fails when `enableExperimentalFeatures` is not `false`.

**Rationale:** Users should not have access to unfinished, experimental package-manager features.

**Impact:** Users cannot enable experimental winget features.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Desktop App Installer\Enable App Installer Experimental Features** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\AppInstaller" /v EnableExperimentalFeatures /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Insecure Application

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

### [Ensure App Installer Hash Override Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#app-installer-hash-override-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.18

**Finding:** App Installer hash override is enabled.

Checks whether users can override SHA256 security validation in the Windows Package Manager.

This rule fails when `enableHashOverride` is not `false`.

**Rationale:** Users should not be able to bypass package integrity (SHA256) validation.

**Impact:** Users cannot override the SHA256 security validation.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Desktop App Installer\Enable App Installer Hash Override** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\AppInstaller" /v EnableHashOverride /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Insecure Application

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

### [Ensure App Installer Local Archive Malware Scan Override Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#app-installer-local-archive-malware-scan-override-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.18

**Finding:** App Installer local archive malware scan override is enabled.

Checks whether malware scans can be overridden when installing a local archive file via winget.

This rule fails when `enableLocalArchiveMalwareScanOverride` is not `false`.

**Rationale:** Users should not be able to bypass malware scanning when installing archived packages.

**Impact:** Users cannot override malware scans when installing an archived file.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Desktop App Installer\Enable App Installer Local Archive Malware Scan Override** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\AppInstaller" /v EnableLocalArchiveMalwareScanOverride /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Insecure Application

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

### [Ensure App Installer Microsoft Store Source Certificate Validation Bypass Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#app-installer-microsoft-store-source-certificate-validation-bypass-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.18

**Finding:** App Installer Microsoft Store source certificate validation bypass is enabled.

Checks whether winget certificate-pinning validation of the Microsoft Store source can be bypassed.

This rule fails when `enableBypassCertificatePinningForMicrosoftStore` is not `false`.

**Rationale:** The Microsoft Store source must be validated so that a spoofed source cannot be substituted.

**Impact:** Source certificate validation cannot be bypassed when winget connects to the Microsoft Store.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Desktop App Installer\Enable App Installer Microsoft Store Source Certificate Validation Bypass** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\AppInstaller" /v EnableBypassCertificatePinningForMicrosoftStore /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Insecure Application

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

### [Ensure The App Installer Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#the-app-installer-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.18

**Finding:** The App Installer (Windows Package Manager) is enabled.

Checks whether standard users have access to the Windows Package Manager (winget).

This rule fails when `enableAppInstaller` is not `false`.

**Rationale:** The winget command-line tool can discover, install, and distribute software; standard users should not have access to such development tools.

**Impact:** Users cannot use winget to discover, install, upgrade, remove, configure, or distribute apps.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Desktop App Installer\Enable App Installer** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\AppInstaller" /v EnableAppInstaller /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Insecure Application

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

### [Ensure The App Installer Ms-Appinstaller Protocol Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#the-app-installer-ms-appinstaller-protocol-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.18

**Finding:** The App Installer ms-appinstaller protocol is enabled.

Checks whether users can install packages from a website via the ms-appinstaller protocol link.

This rule fails when `enableMSAppInstallerProtocol` is not `false`.

**Rationale:** Clicking an unknown or malicious ms-appinstaller link on a website could install malware on the system.

**Impact:** Users cannot use the ms-appinstaller protocol to install apps by clicking a website link.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Desktop App Installer\Enable App Installer ms-appinstaller protocol** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\AppInstaller" /v EnableMSAppInstallerProtocol /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Insecure Application

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

### [Ensure Windows Package Manager Command Line Interfaces Are Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#windows-package-manager-command-line-interfaces-are-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.18

**Finding:** Windows Package Manager command line interfaces are enabled.

Checks whether users can drive the Windows Package Manager through a CLI (Windows CLI or PowerShell).

This rule fails when `enableWindowsPackageManagerCommandLineInterfaces` is not `false`.

**Rationale:** The winget command-line tool can discover, install, and distribute software; standard users should not have access to such development tools.

**Impact:** Users cannot use the Windows Package Manager through Windows CLI or PowerShell.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Desktop App Installer\Enable Windows Package Manager command line interfaces** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\AppInstaller" /v EnableWindowsPackageManagerCommandLineInterfaces /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Insecure Application

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

## 18.10.26 Event Log Service

### [Ensure The Application Event Log Maximum Size Is At Least 32,768 KB](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#the-application-event-log-maximum-size-is-at-least-32-768-kb)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.26.1

**Finding:** The Application event log maximum size is below 32,768 KB.

Checks the maximum size (KB) configured for the Application event log.

This rule fails when `eventLogApplicationMaxSize` is less than `32768`.

**Rationale:** Too small a log lets an attacker overwrite evidence of an attack by generating many extraneous events; a larger log retains more forensic history.

**Impact:** A larger maximum log size retains more events before the oldest entries are overwritten.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Event Log Service\Application\Specify the maximum log file size (KB)** and set it to **Enabled: 32,768 or greater**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\EventLog\Application" /v MaxSize /t REG_DWORD /d 32768 /f
```

Framework mappings

- **CIS Controls v8**: 8.3 Ensure Adequate Audit Log Storage
- **NIST SP 800-53 Rev. 5**: AU-4 Audit Log Storage Capacity; AU-5 Response to Audit Logging Process Failures

Risk

High Profile Threat

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

### [Ensure The Application Event Log Overwrites Events When Full](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#the-application-event-log-overwrites-events-when-full)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.26.1

**Finding:** The Application event log is configured to retain events instead of overwriting when full.

REG_SZ

This rule fails when `eventLogApplicationRetention` is not `false`.

**Rationale:** Checks Event Log behavior when the Application log reaches its maximum size; Disabled lets new events overwrite the oldest events rather than halting logging.

**Impact:** If new events stop being recorded it may be difficult or impossible to determine the root cause of problems or to detect an attacker's activity.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Event Log Service\Application\Control Event Log behavior when the log file reaches its maximum size** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\EventLog\Application" /v Retention /t None - this is the default behavior; new events overwrite old events when the log is full. /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 8.3 Ensure Adequate Audit Log Storage
- **NIST SP 800-53 Rev. 5**: AU-4 Audit Log Storage Capacity; AU-5 Response to Audit Logging Process Failures

Risk

High Profile Threat

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

### [Ensure The Security Event Log Maximum Size Is At Least 196,608 KB](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#the-security-event-log-maximum-size-is-at-least-196-608-kb)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.26.2

**Finding:** The Security event log maximum size is below 196,608 KB.

Checks the maximum size (KB) configured for the Security event log.

This rule fails when `eventLogSecurityMaxSize` is less than `196608`.

**Rationale:** Too small a log lets an attacker overwrite evidence of an attack by generating many extraneous events; a larger log retains more forensic history.

**Impact:** A larger maximum log size retains more events before the oldest entries are overwritten.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Event Log Service\Security\Specify the maximum log file size (KB)** and set it to **Enabled: 196,608 or greater**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\EventLog\Security" /v MaxSize /t REG_DWORD /d 196608 /f
```

Framework mappings

- **CIS Controls v8**: 8.3 Ensure Adequate Audit Log Storage
- **NIST SP 800-53 Rev. 5**: AU-4 Audit Log Storage Capacity; AU-5 Response to Audit Logging Process Failures

Risk

High Profile Threat

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

### [Ensure The Security Event Log Overwrites Events When Full](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#the-security-event-log-overwrites-events-when-full)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.26.2

**Finding:** The Security event log is configured to retain events instead of overwriting when full.

REG_SZ

This rule fails when `eventLogSecurityRetention` is not `false`.

**Rationale:** Checks Event Log behavior when the Security log reaches its maximum size; Disabled lets new events overwrite the oldest events rather than halting logging.

**Impact:** If new events stop being recorded it may be difficult or impossible to determine the root cause of problems or to detect an attacker's activity.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Event Log Service\Security\Control Event Log behavior when the log file reaches its maximum size** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\EventLog\Security" /v Retention /t None - this is the default behavior; new events overwrite old events when the log is full. /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 8.3 Ensure Adequate Audit Log Storage
- **NIST SP 800-53 Rev. 5**: AU-4 Audit Log Storage Capacity; AU-5 Response to Audit Logging Process Failures

Risk

High Profile Threat

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

### [Ensure The Setup Event Log Maximum Size Is At Least 32,768 KB](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#the-setup-event-log-maximum-size-is-at-least-32-768-kb)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.26.3

**Finding:** The Setup event log maximum size is below 32,768 KB.

Checks the maximum size (KB) configured for the Setup event log.

This rule fails when `eventLogSetupMaxSize` is less than `32768`.

**Rationale:** Too small a log lets an attacker overwrite evidence of an attack by generating many extraneous events; a larger log retains more forensic history.

**Impact:** A larger maximum log size retains more events before the oldest entries are overwritten.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Event Log Service\Setup\Specify the maximum log file size (KB)** and set it to **Enabled: 32,768 or greater**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\EventLog\Setup" /v MaxSize /t REG_DWORD /d 32768 /f
```

Framework mappings

- **CIS Controls v8**: 8.3 Ensure Adequate Audit Log Storage
- **NIST SP 800-53 Rev. 5**: AU-4 Audit Log Storage Capacity; AU-5 Response to Audit Logging Process Failures

Risk

High Profile Threat

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

### [Ensure The Setup Event Log Overwrites Events When Full](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#the-setup-event-log-overwrites-events-when-full)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.26.3

**Finding:** The Setup event log is configured to retain events instead of overwriting when full.

REG_SZ

This rule fails when `eventLogSetupRetention` is not `false`.

**Rationale:** Checks Event Log behavior when the Setup log reaches its maximum size; Disabled lets new events overwrite the oldest events rather than halting logging.

**Impact:** If new events stop being recorded it may be difficult or impossible to determine the root cause of problems or to detect an attacker's activity.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Event Log Service\Setup\Control Event Log behavior when the log file reaches its maximum size** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\EventLog\Setup" /v Retention /t None - this is the default behavior; new events overwrite old events when the log is full. /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 8.3 Ensure Adequate Audit Log Storage
- **NIST SP 800-53 Rev. 5**: AU-4 Audit Log Storage Capacity; AU-5 Response to Audit Logging Process Failures

Risk

High Profile Threat

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

### [Ensure The System Event Log Maximum Size Is At Least 32,768 KB](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#the-system-event-log-maximum-size-is-at-least-32-768-kb)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.26.4

**Finding:** The System event log maximum size is below 32,768 KB.

Checks the maximum size (KB) configured for the System event log.

This rule fails when `eventLogSystemMaxSize` is less than `32768`.

**Rationale:** Too small a log lets an attacker overwrite evidence of an attack by generating many extraneous events; a larger log retains more forensic history.

**Impact:** A larger maximum log size retains more events before the oldest entries are overwritten.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Event Log Service\System\Specify the maximum log file size (KB)** and set it to **Enabled: 32,768 or greater**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\EventLog\System" /v MaxSize /t REG_DWORD /d 32768 /f
```

Framework mappings

- **CIS Controls v8**: 8.3 Ensure Adequate Audit Log Storage
- **NIST SP 800-53 Rev. 5**: AU-4 Audit Log Storage Capacity; AU-5 Response to Audit Logging Process Failures

Risk

High Profile Threat

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

### [Ensure The System Event Log Overwrites Events When Full](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#the-system-event-log-overwrites-events-when-full)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.26.4

**Finding:** The System event log is configured to retain events instead of overwriting when full.

REG_SZ

This rule fails when `eventLogSystemRetention` is not `false`.

**Rationale:** Checks Event Log behavior when the System log reaches its maximum size; Disabled lets new events overwrite the oldest events rather than halting logging.

**Impact:** If new events stop being recorded it may be difficult or impossible to determine the root cause of problems or to detect an attacker's activity.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Event Log Service\System\Control Event Log behavior when the log file reaches its maximum size** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\EventLog\System" /v Retention /t None - this is the default behavior; new events overwrite old events when the log is full. /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 8.3 Ensure Adequate Audit Log Storage
- **NIST SP 800-53 Rev. 5**: AU-4 Audit Log Storage Capacity; AU-5 Response to Audit Logging Process Failures

Risk

High Profile Threat

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

## 18.10.29 File Explorer (formerly Windows Explorer)

### [Ensure Account-Based Insights And Recommended Files In File Explorer Are Turned Off](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#account-based-insights-and-recommended-files-in-file-explorer-are-turned-off)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.29

**Finding:** Account-based insights, recent, favorite, and recommended files are shown in File Explorer.

Checks whether File Explorer may request cloud file metadata for its homepage and Quick access views.

This rule fails when `disableGraphRecentItems` is not `true`.

**Rationale:** Data should not be shared with third parties without explicit consent, as it may contain sensitive information.

**Impact:** Account-activity-based insights and files will not appear in Recent, Recommended, or Favorites views.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\File Explorer\Turn off account-based insights, recent, favorite, and recommended files in File Explorer** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Explorer" /v DisableGraphRecentItems /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Data Execution Prevention For File Explorer Is Not Turned Off](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#data-execution-prevention-for-file-explorer-is-not-turned-off)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.29

**Finding:** Data Execution Prevention for File Explorer is turned off.

Checks whether Data Execution Prevention (DEP) for Windows Explorer is left enabled.

This rule fails when `noDataExecutionPreventionForExplorer` is not `false`.

**Rationale:** DEP is an important protection that limits the impact of certain malware against Explorer.

**Impact:** None - this is the default behavior; DEP continues to protect Explorer.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\File Explorer\Turn off Data Execution Prevention for Explorer** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Explorer" /v NoDataExecutionPrevention /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 10.5 Enable Anti-Exploitation Features
- **NIST SP 800-53 Rev. 5**: SI-16 Memory Protection

Risk

Vulnerability

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

### [Ensure Heap Termination On Corruption Is Not Turned Off](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#heap-termination-on-corruption-is-not-turned-off)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.29

**Finding:** Heap termination on corruption is turned off for File Explorer.

Checks whether heap termination on corruption is left active for File Explorer.

This rule fails when `noHeapTerminationOnCorruption` is not `false`.

**Rationale:** Allowing an application to keep running after its session is corrupt increases the system's risk posture.

**Impact:** None - this is the default behavior; heap termination on corruption remains enabled.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\File Explorer\Turn off heap termination on corruption** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Explorer" /v NoHeapTerminationOnCorruption /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Vulnerability

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

### [Ensure Shell Protocol Protected Mode Is Not Turned Off](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#shell-protocol-protected-mode-is-not-turned-off)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.29

**Finding:** Shell protocol protected mode is turned off.

Checks whether the shell protocol runs in protected mode, limiting applications to a restricted set of folders.

This rule fails when `preXPSP2ShellProtocolBehavior` is not `false`.

**Rationale:** Limiting which files and folders can be opened reduces the attack surface of the system.

**Impact:** None - this is the default behavior; the shell protocol stays in protected mode.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\File Explorer\Turn off shell protocol protected mode** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v PreXPSP2ShellProtocolBehavior /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Vulnerability

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

### [Ensure The Mark Of The Web Tag Is Applied To Files From Insecure Sources](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#the-mark-of-the-web-tag-is-applied-to-files-from-insecure-sources)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.29

**Finding:** The Mark of the Web tag is not applied to files copied from insecure sources.

Checks whether files sourced from insecure locations are tagged with Mark of the Web (MOTW).

This rule fails when `disableMotWOnInsecurePathCopy` is not `false`.

**Rationale:** MOTW ensures files from insecure locations are treated with extra caution; untagged files expose users to security risks.

**Impact:** None - this is the default behavior; files copied from insecure sources are tagged with MOTW.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\File Explorer\Do not apply the Mark of the Web tag to files copied from insecure sources** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Explorer" /v DisableMotWOnInsecurePathCopy /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 10.5 Enable Anti-Exploitation Features
- **NIST SP 800-53 Rev. 5**: SI-16 Memory Protection

Risk

Vulnerability

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

## 18.10.36 Location and Sensors

### [Ensure The Location Feature Is Turned Off](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#the-location-feature-is-turned-off)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.36

**Finding:** The location feature is turned on.

Checks whether the Windows location feature is turned off for the computer.

This rule fails when `disableLocation` is not `true`.

**Rationale:** Revealing device location to software is undesirable in high-security environments.

**Impact:** The location feature is off, and all programs are prevented from using location information.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Location and Sensors\Turn off location** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\LocationAndSensors" /v DisableLocation /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## 18.10.40 Messaging

### [Ensure Message Service Cloud Sync Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#message-service-cloud-sync-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.40

**Finding:** Message Service cloud sync is allowed.

Checks whether cellular text messages may be backed up to and restored from Microsoft's cloud.

This rule fails when `allowMessageSync` is not `false`.

**Rationale:** Data should not be shared with third parties without explicit consent, as messages may contain sensitive information.

**Impact:** Cellular text messages will not be backed up to or restored from Microsoft's cloud services.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Messaging\Allow Message Service Cloud Sync** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Messaging" /v AllowMessageSync /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## 18.10.41 Microsoft account

### [Ensure Consumer Microsoft Account User Authentication Is Blocked](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#consumer-microsoft-account-user-authentication-is-blocked)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.41

**Finding:** Consumer Microsoft account user authentication is permitted.

Checks whether apps and services may authenticate with consumer Microsoft accounts via the Windows OnlineID and WebAccountManager APIs.

This rule fails when `disableUserAuth` is not `true`.

**Rationale:** Blocking consumer Microsoft accounts lets an organization keep firm control of which identities are used and helps meet compliance requirements.

**Impact:** Apps and services cannot start new authentications with consumer Microsoft accounts via those APIs; direct browser/OAuth sign-ins are unaffected.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft accounts\Block all consumer Microsoft account user authentication** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\MicrosoftAccount" /v DisableUserAuth /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 5.6 Centralize Account Management
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management

Risk

Unprotected Principal

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## 18.10.43 Microsoft Defender Application Guard

### [Ensure Auditing Events In Microsoft Defender Application Guard Are Allowed](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#auditing-events-in-microsoft-defender-application-guard-are-allowed)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.43

**Finding:** Auditing events in Microsoft Defender Application Guard are not allowed.

Checks whether auditing events can be collected from Microsoft Defender Application Guard.

This rule fails when `auditApplicationGuard` is not `true`.

**Rationale:** Application Guard audit events can be valuable when investigating a security incident.

**Impact:** Application Guard audits system events; collected logs are reviewable through Microsoft Edge.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Application Guard\Allow auditing events in Microsoft Defender Application Guard** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\AppHVSI" /v AuditApplicationGuard /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 8.2 Collect Audit Logs
- **NIST SP 800-53 Rev. 5**: AU-2 Event Logging; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation
- **PCI DSS v4.0.1**: 5.3.4 Enable and retain anti-malware audit logs; 6.4.1 Assess or shield public-facing web applications against known attacks; 6.4.2 Deploy an automated solution that blocks attacks on public web apps; 10.2.1.1 Record every individual user's cardholder data access; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.3 Record any access made to audit records themselves; 10.2.1.4 Record failed logical access attempts; 10.2.1.5 Record account creation, privilege elevation, and other credential changes; 10.2.1.6 Record when audit logging is initialized, started, stopped, or paused; 10.2.1.7 Record the creation or removal of system-level objects; 10.2.2 Include user, event type, date, and time in each log entry

Risk

High Profile Threat

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

### [Ensure Camera And Microphone Access In Microsoft Defender Application Guard Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#camera-and-microphone-access-in-microsoft-defender-application-guard-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.43

**Finding:** Applications inside Microsoft Defender Application Guard can access the camera and microphone.

Checks whether apps inside the Application Guard container can access the device camera and microphone.

This rule fails when `allowCameraMicrophoneRedirection` is not `false`.

**Rationale:** Untrusted sites in the Application Guard container should not reach the camera or microphone, preventing capture of sensitive information.

**Impact:** Applications inside Application Guard cannot access the device camera or microphone.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Application Guard\Allow camera and microphone access in Microsoft Defender Application Guard** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\AppHVSI" /v AllowCameraMicrophoneRedirection /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Data Persistence For Microsoft Defender Application Guard Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#data-persistence-for-microsoft-defender-application-guard-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.43

**Finding:** Data persists across sessions in Microsoft Defender Application Guard.

Checks whether data persists across sessions in the Microsoft Defender Application Guard container.

This rule fails when `allowPersistence` is not `false`.

**Rationale:** Persistence undermines the sandbox: malicious content could remain active in the container between sessions.

**Impact:** None - this is the default behavior; Application Guard deletes container user data between sessions.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Application Guard\Allow data persistence for Microsoft Defender Application Guard** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\AppHVSI" /v AllowPersistence /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Insecure Application

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

### [Ensure Downloading And Saving Files To The Host From Microsoft Defender Application Guard Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#downloading-and-saving-files-to-the-host-from-microsoft-defender-application-gua)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.43

**Finding:** Files can be downloaded and saved to the host operating system from Microsoft Defender Application Guard.

Checks whether downloaded files may be saved from the Application Guard container to the host OS.

This rule fails when `saveFilesToHost` is not `false`.

**Rationale:** Potentially malicious files should not be copied from the sandbox to the host, which could put the host at risk.

**Impact:** None - this is the default behavior; users cannot save downloaded files from the container to the host.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Application Guard\Allow files to download and save to the host operating system from Microsoft Defender Application Guard** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\AppHVSI" /v SaveFilesToHost /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Insecure Application

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

### [Ensure Microsoft Defender Application Guard Clipboard Is Limited To Isolated-Session-To-Host](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#microsoft-defender-application-guard-clipboard-is-limited-to-isolated-session-to)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.43

**Finding:** The Microsoft Defender Application Guard clipboard is not limited to isolated-session-to-host only.

Checks how the clipboard behaves between the Application Guard container and the host.

This rule fails when `appHVSIClipboardSettings` is not `HOST_TO_GUARD`.

**Rationale:** Exposing the host clipboard to the container could leak sensitive information to a compromised session; limiting to container-to-host reduces that risk.

**Impact:** Application Guard sessions cannot read the host clipboard, but the host can read the container clipboard.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Application Guard\Configure Microsoft Defender Application Guard clipboard settings: Clipboard behavior setting** and set it to **Enabled: Enable clipboard operation from an isolated session to the host**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\AppHVSI" /v AppHVSIClipboardSettings /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Insecure Application

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

### [Ensure Microsoft Defender Application Guard Is Turned On In Managed Mode For Edge](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#microsoft-defender-application-guard-is-turned-on-in-managed-mode-for-edge)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.43

**Finding:** Microsoft Defender Application Guard is not turned on in Managed Mode for Microsoft Edge.

Checks whether application isolation through Microsoft Defender Application Guard is enabled for Microsoft Edge.

This rule fails when `allowAppHVSIProviderSet` is not `ENABLED_EDGE`.

**Rationale:** Application Guard uses virtualization-based isolation so that improper interactions and app vulnerabilities cannot compromise the kernel or other apps.

**Impact:** Application Guard will be turned on for Microsoft Edge.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Application Guard\Turn on Microsoft Defender Application Guard in Managed Mode** and set it to **Enabled: 1**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\AppHVSI" /v AllowAppHVSI_ProviderSet /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 10.5 Enable Anti-Exploitation Features
- **NIST SP 800-53 Rev. 5**: SI-16 Memory Protection

Risk

Insecure Application

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

## 18.10.49 News and interests

### [Ensure News And Interests On The Taskbar Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#news-and-interests-on-the-taskbar-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.49

**Finding:** News and interests on the taskbar is enabled.

Checks whether the news and interests feature is allowed on the taskbar.

This rule fails when `enableFeeds` is not `false`.

**Rationale:** News and interests may share data with third parties and can display inappropriate content, and should be treated as a security risk.

**Impact:** The news and interests feature on the taskbar will not be available on the device.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\News and interests\Enable news and interests on the taskbar** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Windows Feeds" /v EnableFeeds /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## 18.10.50 OneDrive (formerly SkyDrive)

### [Ensure Use Of OneDrive For File Storage Is Prevented](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#use-of-onedrive-for-file-storage-is-prevented)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.50

**Finding:** Use of OneDrive for file storage is permitted.

Checks whether apps and features are prevented from working with OneDrive via the Next Generation Sync Client.

This rule fails when `disableFileSyncNGSC` is not `true`.

**Rationale:** Preventing OneDrive use stops users from accidentally or intentionally uploading confidential corporate information to the cloud service.

**Impact:** Users cannot access OneDrive from the app or file picker, and files are not synced with the cloud.

#### Remediation

Navigate to **Computer Configuration\Policies\Administrative Templates\Windows Components\OneDrive\Prevent the usage of OneDrive for file storage** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\OneDrive" /v DisableFileSyncNGSC /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## 18.10.56 Push To Install

### [Ensure Turn Off Push To Install Service Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#turn-off-push-to-install-service-is-enabled)

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.56

**Finding:** Push To Install service is not turned off.

Checks whether the Push To Install service, which lets remotely initiated Store installs push apps to the device, is turned off.

This rule fails when `disablePushToInstall` is not `true`.

**Rationale:** The Push To Install service can be used to silently place applications on a device from a linked account, expanding what unattended software can appear.

**Impact:** Users can no longer remotely queue Store app installs to this device from another device.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Push To Install > Turn off Push To Install service** and set **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\PushToInstall" /v DisablePushToInstall /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 2.5 Allowlist Authorized Software
- **NIST SP 800-53 Rev. 5**: CM-7 Least Functionality; CM-10 Software Usage Restrictions
- **NIST SP 800-171 Rev. 2**: 3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; 3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
- **CMMC 2.0 Level 2**: CM.L2-3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; SC.L2-3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality

Risk

External Attack Surface

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

## 18.10.57 Remote Desktop Services (formerly Terminal Services)

### [Ensure Disable Cloud Clipboard Integration For Server To Client Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#disable-cloud-clipboard-integration-for-server-to-client-is-enabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.57.2

**Finding:** Cloud clipboard integration for server-to-client transfer is not disabled.

Checks whether cloud clipboard content is prevented from flowing from a Remote Desktop server back to the client.

This rule fails when `disableCloudClipboardIntegration` is not `true`.

**Rationale:** Cloud clipboard flow from an untrusted remote host to the client can leak sensitive data onto the local device.

**Impact:** Clipboard data synchronised through the cloud will not transfer from the server to the client.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Connection Client > Disable Cloud Clipboard integration for server-to-client data transfer** and set **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services\Client" /v DisableCloudClipboardIntegration /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Do Not Allow Passwords To Be Saved Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#do-not-allow-passwords-to-be-saved-is-enabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.57.2

**Finding:** Saving of Remote Desktop passwords is allowed.

Checks whether the Remote Desktop Connection client is prevented from saving connection passwords.

This rule fails when `disablePasswordSaving` is not `true`.

**Rationale:** Saved RDP passwords stored on the client can be recovered by an attacker and reused against remote hosts.

**Impact:** The Remote Desktop client no longer offers to save passwords; users must enter them each time.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Connection Client > Do not allow passwords to be saved** and set **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v DisablePasswordSaving /t REG_DWORD /d 1 /f
```

Risk

Insecure Use of Secrets

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure Allow Users To Connect Remotely By Using Remote Desktop Services Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#allow-users-to-connect-remotely-by-using-remote-desktop-services-is-disabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.57.3.2

**Finding:** Remote Desktop Services connections to this computer are allowed.

Checks whether inbound Remote Desktop Services connections to this computer are denied (the policy that allows remote connections is disabled).

This rule fails when `fDenyTSConnections` is not `true`.

**Rationale:** An exposed Remote Desktop listener is a frequent target for credential attacks and lateral movement.

**Impact:** Users cannot connect to this computer using Remote Desktop until the policy is re-enabled.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Connections > Allow users to connect remotely by using Remote Desktop Services** and set **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v fDenyTSConnections /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Exposure

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure Allow UI Automation Redirection Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#allow-ui-automation-redirection-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.57.3.3

**Finding:** UI Automation redirection is enabled for Remote Desktop.

Checks whether UI Automation redirection between a Remote Desktop session and the local device is disabled.

This rule fails when `enableUiaRedirection` is not `false`.

**Rationale:** UI Automation redirection lets accessibility automation cross the session boundary, which can be abused to drive or observe the remote or local desktop.

**Impact:** UI Automation clients cannot interact across the Remote Desktop session boundary.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Device and Resource Redirection > Allow UI Automation redirection** and set **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v EnableUiaRedirection /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure Do Not Allow Drive Redirection Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#do-not-allow-drive-redirection-is-enabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.57.3.3

**Finding:** Drive redirection is allowed in Remote Desktop sessions.

Checks whether mapping of local drives into a Remote Desktop session is prevented.

This rule fails when `fDisableCdm` is not `true`.

**Rationale:** Drive redirection lets files move freely between the session host and the client, a path for data theft and malware transfer.

**Impact:** Local drives are no longer mapped into Remote Desktop sessions.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Device and Resource Redirection > Do not allow drive redirection** and set **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v fDisableCdm /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Do Not Allow Location Redirection Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#do-not-allow-location-redirection-is-enabled)

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.57.3.3

**Finding:** Location redirection is allowed in Remote Desktop sessions.

Checks whether device location information is prevented from being redirected into a Remote Desktop session.

This rule fails when `fDisableLocationRedir` is not `true`.

**Rationale:** Redirected location data exposes the physical whereabouts of the client to the remote host.

**Impact:** Location information is no longer redirected into Remote Desktop sessions.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Device and Resource Redirection > Do not allow location redirection** and set **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v fDisableLocationRedir /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Do Not Allow LPT Port Redirection Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#do-not-allow-lpt-port-redirection-is-enabled)

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.57.3.3

**Finding:** LPT port redirection is allowed in Remote Desktop sessions.

Checks whether redirection of local LPT (parallel) ports into a Remote Desktop session is prevented.

This rule fails when `fDisableLPT` is not `true`.

**Rationale:** LPT port redirection widens the session's device surface with no legitimate need in most environments.

**Impact:** Local LPT ports are no longer available inside Remote Desktop sessions.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Device and Resource Redirection > Do not allow LPT port redirection** and set **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v fDisableLPT /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Do Not Allow Supported Plug And Play Device Redirection Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#do-not-allow-supported-plug-and-play-device-redirection-is-enabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.57.3.3

**Finding:** Supported Plug and Play device redirection is allowed in Remote Desktop sessions.

Checks whether redirection of supported Plug and Play devices into a Remote Desktop session is prevented.

This rule fails when `fDisablePNPRedir` is not `true`.

**Rationale:** PnP device redirection can bridge removable media and other peripherals into the session, enabling data movement and malware transfer.

**Impact:** Supported Plug and Play devices are no longer redirected into Remote Desktop sessions.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Device and Resource Redirection > Do not allow supported Plug and Play device redirection** and set **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v fDisablePNPRedir /t REG_DWORD /d 1 /f
```

Risk

External Attack Surface

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Do Not Allow WebAuthn Redirection Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#do-not-allow-webauthn-redirection-is-enabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.57.3.3

**Finding:** WebAuthn redirection is allowed in Remote Desktop sessions.

Checks whether WebAuthn (FIDO) authenticator redirection into a Remote Desktop session is prevented.

This rule fails when `fDisableWebAuthn` is not `true`.

**Rationale:** Redirecting WebAuthn authenticators lets the remote host use the client's security keys, weakening the trust boundary around strong authentication.

**Impact:** Local WebAuthn authenticators are no longer available to Remote Desktop sessions.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Device and Resource Redirection > Do not allow WebAuthn redirection** and set **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v fDisableWebAuthn /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Insecure Use of Secrets

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure Restrict Clipboard Transfer From Server To Client Is Set To Disable Clipboard Transfers](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#restrict-clipboard-transfer-from-server-to-client-is-set-to-disable-clipboard-tr)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.57.3.3

**Finding:** Clipboard transfer from a Remote Desktop server to the client is not disabled.

Checks whether clipboard content is blocked from being copied from a Remote Desktop session server to the connecting client.

This rule fails when `scClipLevel` is not `DISABLED`.

**Rationale:** Allowing the server to push clipboard data to the client can exfiltrate data from an untrusted remote host onto the local device.

**Impact:** Clipboard content originating on the Remote Desktop server can no longer be pasted on the client.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Device and Resource Redirection > Restrict clipboard transfer from server to client** and set **Enabled: Disable clipboard transfers from server to client**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v SCClipLevel /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Always Prompt For Password Upon Connection Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#always-prompt-for-password-upon-connection-is-enabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.57.3.9

**Finding:** Remote Desktop connections do not always prompt for a password.

Checks whether Remote Desktop always requires the user to enter a password when connecting.

This rule fails when `fPromptForPassword` is not `true`.

**Rationale:** If the client can supply a cached password automatically, an attacker at the client can connect without re-authenticating.

**Impact:** Users are always prompted for their password when establishing a Remote Desktop connection.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Security > Always prompt for password upon connection** and set **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v fPromptForPassword /t REG_DWORD /d 1 /f
```

Risk

Unprotected Principal

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure Require Secure RPC Communication Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#require-secure-rpc-communication-is-enabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.57.3.9

**Finding:** Secure RPC communication is not required for Remote Desktop.

Checks whether the Remote Desktop server requires authenticated and encrypted RPC requests.

This rule fails when `fEncryptRPCTraffic` is not `true`.

**Rationale:** Without secure RPC, unauthenticated or unencrypted management requests to the RD service are accepted, exposing it to interception and abuse.

**Impact:** Only RPC clients that support secure, encrypted requests can communicate with the Remote Desktop service.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Security > Require secure RPC communication** and set **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v fEncryptRPCTraffic /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 3.10 Encrypt Sensitive Data in Transit
- **NIST SP 800-53 Rev. 5**: AC-17 Remote Access; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
- **NIST SP 800-171 Rev. 2**: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- **CMMC 2.0 Level 2**: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- **PCI DSS v4.0.1**: 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography

Risk

External Exposure

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure Require Use Of Specific Security Layer For Remote Connections Is Set To SSL](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#require-use-of-specific-security-layer-for-remote-connections-is-set-to-ssl)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.57.3.9

**Finding:** Remote Desktop connections do not require the SSL security layer.

Checks whether Remote Desktop connections require the SSL (TLS) security layer for server authentication and session encryption.

This rule fails when `securityLayer` is not `SSL_TLS`.

**Rationale:** Native RDP encryption does not authenticate the server, leaving connections open to man-in-the-middle attacks; SSL/TLS provides server authentication.

**Impact:** Clients that cannot negotiate SSL/TLS will be unable to connect to the Remote Desktop host.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Security > Require use of specific security layer for remote (RDP) connections** and set **Enabled: SSL**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v SecurityLayer /t REG_DWORD /d 2 /f
```

Framework mappings

- **CIS Controls v8**: 3.10 Encrypt Sensitive Data in Transit
- **NIST SP 800-53 Rev. 5**: AC-17 Remote Access; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
- **NIST SP 800-171 Rev. 2**: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- **CMMC 2.0 Level 2**: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- **PCI DSS v4.0.1**: 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography

Risk

External Exposure

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure Require User Authentication For Remote Connections By Using Network Level Authentication Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#require-user-authentication-for-remote-connections-by-using-network-level-authen)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.57.3.9

**Finding:** Network Level Authentication is not required for Remote Desktop connections.

Checks whether Remote Desktop requires Network Level Authentication before a session is established.

This rule fails when `userAuthentication` is not `true`.

**Rationale:** NLA forces the user to authenticate before a full session is created, protecting the host from pre-authentication attacks and resource exhaustion.

**Impact:** Only clients that support Network Level Authentication can connect to the Remote Desktop host.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Security > Require user authentication for remote connections by using Network Level Authentication** and set **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v UserAuthentication /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 3.10 Encrypt Sensitive Data in Transit
- **NIST SP 800-53 Rev. 5**: AC-17 Remote Access; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
- **NIST SP 800-171 Rev. 2**: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- **CMMC 2.0 Level 2**: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- **PCI DSS v4.0.1**: 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography

Risk

External Exposure

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure Set Client Connection Encryption Level Is Set To High Level](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#set-client-connection-encryption-level-is-set-to-high-level)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.57.3.9

**Finding:** Remote Desktop client connection encryption level is below High.

Checks whether Remote Desktop connections encrypt all traffic in both directions using 128-bit keys.

This rule fails when `minEncryptionLevel` is not `HIGH`.

**Rationale:** Weaker encryption levels leave part of the session traffic recoverable by an attacker on the network.

**Impact:** Clients that cannot support 128-bit encryption will be unable to connect to the Remote Desktop host.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Security > Set client connection encryption level** and set **Enabled: High Level**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v MinEncryptionLevel /t REG_DWORD /d 3 /f
```

Framework mappings

- **CIS Controls v8**: 3.10 Encrypt Sensitive Data in Transit
- **NIST SP 800-53 Rev. 5**: AC-17 Remote Access; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
- **NIST SP 800-171 Rev. 2**: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- **CMMC 2.0 Level 2**: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- **PCI DSS v4.0.1**: 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Set Time Limit For Active But Idle Remote Desktop Services Sessions Is 15 Minutes Or Less](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#set-time-limit-for-active-but-idle-remote-desktop-services-sessions-is-15-minute)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.57.3.10

**Finding:** Active but idle Remote Desktop sessions have no limit or exceed 15 minutes.

Checks the maximum time an active but idle Remote Desktop session may remain before it is disconnected.

This rule fails when `maxIdleTime` is `0` (Never) or greater than `900000000000` ns (15 minutes).

**Rationale:** An idle session left open indefinitely can be hijacked by anyone with access to the client, and consumes host resources.

**Impact:** Idle Remote Desktop sessions are disconnected after the configured time limit.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Session Time Limits > Set time limit for active but idle Remote Desktop Services sessions** and set **Enabled: 15 minutes or less, but not Never (0)**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v MaxIdleTime /t REG_DWORD /d 900000 /f
```

Risk

Unprotected Principal

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure Temporary Folders Are Deleted Upon Remote Desktop Session Exit](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#temporary-folders-are-deleted-upon-remote-desktop-session-exit)

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.57.3.11

**Finding:** Per-session temporary folders are retained after Remote Desktop session exit.

Checks whether per-session temporary folders are deleted when a Remote Desktop session ends.

This rule fails when `deleteTempDirsOnExit` is not `true`.

**Rationale:** Retained per-session temp folders can leave sensitive working data on disk for later recovery.

**Impact:** Per-session temporary folders are cleared when each Remote Desktop session ends.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Temporary folders > Do not delete temp folders upon exit (set to Disabled)** and set **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v DeleteTempDirsOnExit /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 3.4 Enforce Data Retention
- **NIST SP 800-53 Rev. 5**: AU-11 Audit Record Retention; SI-12 Information Management and Retention
- **PCI DSS v4.0.1**: 3.2.1 Minimize stored account data via defined retention and secure deletion rules

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## 18.10.58 RSS Feeds

### [Ensure Prevent Downloading Of Enclosures Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#prevent-downloading-of-enclosures-is-enabled)

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.58

**Finding:** Downloading of RSS feed enclosures is allowed.

Checks whether the automatic download of RSS/Atom feed enclosures (attachments) is prevented.

This rule fails when `disableEnclosureDownload` is not `true`.

**Rationale:** Feed enclosures can silently pull attacker-supplied files onto the device without user interaction.

**Impact:** Enclosures attached to RSS feeds are no longer downloaded automatically.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > RSS Feeds > Prevent downloading of enclosures** and set **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer\Feeds" /v DisableEnclosureDownload /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 9.4 Restrict Unnecessary or Unauthorized Browser and Email Client Extensions
- **NIST SP 800-53 Rev. 5**: CM-10 Software Usage Restrictions; CM-11 User-installed Software; SC-18 Mobile Code
- **PCI DSS v4.0.1**: 2.2.4 Enable only required services and remove unneeded functionality

Risk

External Attack Surface

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

## 18.10.59 Search

### [Ensure Allow Cloud Search Is Set To Disable Cloud Search](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#allow-cloud-search-is-set-to-disable-cloud-search)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.59

**Finding:** Cloud Search is enabled for Windows Search.

Checks whether Windows Search is prevented from sending queries and content to cloud services.

This rule fails when `allowCloudSearch` is present and not `DISABLED`.

**Rationale:** Cloud Search transmits local search queries and content to Microsoft cloud services, a privacy and data-exposure concern in sensitive environments.

**Impact:** Windows Search returns only local results and does not query cloud content.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Search > Allow Cloud Search** and set **Enabled: Disable Cloud Search**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Windows Search" /v AllowCloudSearch /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Allow Cortana Above Lock Screen Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#allow-cortana-above-lock-screen-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.59

**Finding:** Cortana is allowed above the lock screen.

Checks whether Cortana can be used from the lock screen without signing in.

This rule fails when `allowCortanaAboveLock` is not `false`.

**Rationale:** An assistant available above the lock screen lets an unauthenticated person interact with the device and potentially disclose information.

**Impact:** Cortana is unavailable on the lock screen until the user signs in.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Search > Allow Cortana above lock screen** and set **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Windows Search" /v AllowCortanaAboveLock /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Principal

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure Allow Cortana Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#allow-cortana-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.59

**Finding:** Cortana is allowed.

Checks whether the Cortana voice assistant is disabled.

This rule fails when `allowCortana` is not `false`.

**Rationale:** Cortana sends queries and contextual data to cloud services and expands the input surface of the device.

**Impact:** Cortana is turned off; users cannot use its assistant features.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Search > Allow Cortana** and set **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Windows Search" /v AllowCortana /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Allow Indexing Of Encrypted Files Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#allow-indexing-of-encrypted-files-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.59

**Finding:** Indexing of encrypted files is allowed.

Checks whether the search indexer is prevented from indexing encrypted files and stores.

This rule fails when `allowIndexingEncryptedStoresOrItems` is not `false`.

**Rationale:** Indexing encrypted content copies plaintext-derived index data outside the protected store, undermining the encryption.

**Impact:** Encrypted files are excluded from the search index and will not appear in indexed search results.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Search > Allow indexing of encrypted files** and set **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Windows Search" /v AllowIndexingEncryptedStoresOrItems /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Allow Search And Cortana To Use Location Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#allow-search-and-cortana-to-use-location-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.59

**Finding:** Search and Cortana are allowed to use device location.

Checks whether Search and Cortana are prevented from accessing the device's location.

This rule fails when `allowSearchToUseLocation` is not `false`.

**Rationale:** Location access by search components leaks the device's physical whereabouts to local and cloud features.

**Impact:** Search and Cortana no longer use the device location for results.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Search > Allow search and Cortana to use location** and set **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Windows Search" /v AllowSearchToUseLocation /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Allow Search Highlights Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#allow-search-highlights-is-disabled)

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.59

**Finding:** Search highlights are allowed.

Checks whether dynamic search highlights, which fetch content into the search box from the internet, are disabled.

This rule fails when `enableDynamicContentInWSB` is not `false`.

**Rationale:** Search highlights pull remote content and telemetry into the search experience, adding an untrusted content channel.

**Impact:** The search box no longer displays dynamic highlight content.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Search > Allow search highlights** and set **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Windows Search" /v EnableDynamicContentInWSB /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## 18.10.63 Software Protection Platform

### [Ensure Turn Off KMS Client Online AVS Validation Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#turn-off-kms-client-online-avs-validation-is-enabled)

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.63

**Finding:** KMS Client Online AVS Validation is not turned off.

Checks whether the KMS client is prevented from contacting Microsoft's Activation and Validation Service online.

This rule fails when `noGenTicket` is not `true`.

**Rationale:** Blocking the online validation call removes an outbound connection to Microsoft that is unnecessary for KMS-activated enterprise hosts.

**Impact:** The KMS client no longer performs the online AVS validation call.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Software Protection Platform > Turn off KMS Client Online AVS Validation** and set **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\Software Protection Platform" /v NoGenTicket /t REG_DWORD /d 1 /f
```

Risk

External Attack Surface

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## 18.10.66 Store

### [Ensure Disable All Apps From Microsoft Store Is Configured](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#disable-all-apps-from-microsoft-store-is-configured)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.66

**Finding:** Microsoft Store apps are not restricted per policy.

Checks whether the Microsoft Store app-restriction policy is applied so that unmanaged Store apps are constrained.

This rule fails when `disableStoreApps` is not `true`.

**Rationale:** Unrestricted Store apps let users install software outside of IT control, broadening the software attack surface.

**Impact:** Microsoft Store apps are constrained according to the configured Store policy.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Store > Disable all apps from Microsoft Store (set to Disabled)** and set **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\WindowsStore" /v DisableStoreApps /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 2.5 Allowlist Authorized Software
- **NIST SP 800-53 Rev. 5**: CM-7 Least Functionality; CM-10 Software Usage Restrictions
- **NIST SP 800-171 Rev. 2**: 3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; 3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
- **CMMC 2.0 Level 2**: CM.L2-3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; SC.L2-3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality

Risk

Insecure Application

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

### [Ensure Turn Off Automatic Download And Install Of Updates Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#turn-off-automatic-download-and-install-of-updates-is-disabled)

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.66

**Finding:** Automatic download and install of Store app updates is not turned off.

Checks whether automatic download and installation of Microsoft Store app updates is turned off.

This rule fails when `autoDownload` is not `NEVER`.

**Rationale:** Uncontrolled automatic Store updates can introduce unvetted changes to installed apps.

**Impact:** Microsoft Store app updates are not downloaded or installed automatically; updates must be initiated manually.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Store > Turn off Automatic Download and Install of updates** and set **Enabled: Never download**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\WindowsStore" /v AutoDownload /t REG_DWORD /d 4 /f
```

Framework mappings

- **CIS Controls v8**: 7.3 Perform Automated Operating System Patch Management
- **NIST SP 800-53 Rev. 5**: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation

Risk

Reliability Impact

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

### [Ensure Turn Off The Offer To Update To The Latest Version Of Windows Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#turn-off-the-offer-to-update-to-the-latest-version-of-windows-is-enabled)

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.66

**Finding:** The Store offer to update to the latest version of Windows is not turned off.

Checks whether the Microsoft Store is prevented from offering an in-place upgrade to the latest Windows version.

This rule fails when `disableOSUpgrade` is not `true`.

**Rationale:** An unmanaged Store-driven OS upgrade can move a device to an unvalidated Windows release outside change control.

**Impact:** Users are no longer offered a Windows version upgrade through the Microsoft Store.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Store > Turn off the offer to update to the latest version of Windows** and set **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\WindowsStore" /v DisableOSUpgrade /t REG_DWORD /d 1 /f
```

Risk

Reliability Impact

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

### [Ensure Turn Off The Store Application Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#turn-off-the-store-application-is-enabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.66

**Finding:** The Microsoft Store application is not turned off.

Checks whether access to the Microsoft Store application is removed.

This rule fails when `removeWindowsStore` is not `true`.

**Rationale:** The Store lets users acquire and run applications outside IT control, expanding the software attack surface.

**Impact:** The Microsoft Store application is inaccessible to users on the device.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Store > Turn off the Store application** and set **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\WindowsStore" /v RemoveWindowsStore /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 2.5 Allowlist Authorized Software
- **NIST SP 800-53 Rev. 5**: CM-7 Least Functionality; CM-10 Software Usage Restrictions
- **NIST SP 800-171 Rev. 2**: 3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; 3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
- **CMMC 2.0 Level 2**: CM.L2-3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; SC.L2-3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality

Risk

Insecure Application

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

## 18.10.72 Widgets

### [Ensure Allow Widgets Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#allow-widgets-is-disabled)

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.72

**Finding:** Widgets are allowed.

Checks whether the Widgets board (news and interests feed) is disabled.

This rule fails when `allowNewsAndInterests` is not `false`.

**Rationale:** The Widgets feed pulls remote content and telemetry into the desktop, adding an untrusted content channel.

**Impact:** The Widgets board is turned off and its taskbar entry is removed.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Widgets > Allow widgets** and set **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Dsh" /v AllowNewsAndInterests /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## 18.10.73 Windows AI

### [Ensure Allow Recall To Be Enabled Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#allow-recall-to-be-enabled-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.73

**Finding:** Windows Recall is allowed to be enabled.

Checks whether the Windows Recall feature, which periodically snapshots the screen, is prevented from being enabled.

This rule fails when `allowRecallEnablement` is not `false`.

**Rationale:** Recall stores a searchable history of on-screen content, creating a rich local trove of sensitive data that an attacker could harvest.

**Impact:** Users cannot enable the Windows Recall feature on the device.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows AI > Allow Recall to be enabled** and set **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsAI" /v AllowRecallEnablement /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## 18.10.77 Windows Defender SmartScreen

### [Ensure Enhanced Phishing Protection Automatic Data Collection Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#enhanced-phishing-protection-automatic-data-collection-is-enabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.77.1

**Finding:** Enhanced Phishing Protection automatic data collection is disabled.

Checks whether Enhanced Phishing Protection collects additional context from suspicious sites or apps for security analysis.

This rule fails when `captureThreatWindow` is not `true`.

**Rationale:** Automatic data collection improves detection of phishing and unsafe credential entry across the device.

**Impact:** Enhanced Phishing Protection captures additional threat context when a suspicious event is detected.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Defender SmartScreen > Enhanced Phishing Protection > Automatic Data Collection** and set **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WTDS\Components" /v CaptureThreatWindow /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 10.5 Enable Anti-Exploitation Features
- **NIST SP 800-53 Rev. 5**: SI-16 Memory Protection

Risk

High Profile Threat

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure Enhanced Phishing Protection Notify Malicious Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#enhanced-phishing-protection-notify-malicious-is-enabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.77.1

**Finding:** Enhanced Phishing Protection malicious-site notifications are disabled.

Checks whether users are warned when they enter their password on a known malicious site or app.

This rule fails when `notifyMalicious` is not `true`.

**Rationale:** Warning on malicious credential entry is a key defence against phishing and credential theft.

**Impact:** Users receive a warning when they attempt to use their password on a site or app flagged as malicious.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Defender SmartScreen > Enhanced Phishing Protection > Notify Malicious** and set **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WTDS\Components" /v NotifyMalicious /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 10.5 Enable Anti-Exploitation Features
- **NIST SP 800-53 Rev. 5**: SI-16 Memory Protection

Risk

High Profile Threat

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure Enhanced Phishing Protection Notify Password Reuse Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#enhanced-phishing-protection-notify-password-reuse-is-enabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.77.1

**Finding:** Enhanced Phishing Protection password-reuse notifications are disabled.

Checks whether users are warned when they reuse their work or school password on other sites or apps.

This rule fails when `notifyPasswordReuse` is not `true`.

**Rationale:** Password reuse spreads the impact of a single compromised credential; warning users curbs the practice.

**Impact:** Users are warned when they reuse their protected password elsewhere.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Defender SmartScreen > Enhanced Phishing Protection > Notify Password Reuse** and set **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WTDS\Components" /v NotifyPasswordReuse /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 10.5 Enable Anti-Exploitation Features
- **NIST SP 800-53 Rev. 5**: SI-16 Memory Protection

Risk

Insecure Use of Secrets

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure Enhanced Phishing Protection Notify Unsafe App Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#enhanced-phishing-protection-notify-unsafe-app-is-enabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.77.1

**Finding:** Enhanced Phishing Protection unsafe-app notifications are disabled.

Checks whether users are warned when they type their password into an application considered unsafe.

This rule fails when `notifyUnsafeApp` is not `true`.

**Rationale:** Entering a password into an untrusted app is a common credential-theft vector; the warning intercepts it.

**Impact:** Users receive a warning when they enter their password into an app flagged as unsafe.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Defender SmartScreen > Enhanced Phishing Protection > Notify Unsafe App** and set **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WTDS\Components" /v NotifyUnsafeApp /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 10.5 Enable Anti-Exploitation Features
- **NIST SP 800-53 Rev. 5**: SI-16 Memory Protection

Risk

High Profile Threat

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure Enhanced Phishing Protection Service Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#enhanced-phishing-protection-service-is-enabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.77.1

**Finding:** The Enhanced Phishing Protection service is disabled.

Checks whether the Enhanced Phishing Protection service is turned on.

This rule fails when `serviceEnabled` is not `true`.

**Rationale:** The service underpins all phishing and password-protection warnings; if it is off, none of them apply.

**Impact:** The Enhanced Phishing Protection service runs and enforces the configured phishing protections.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Defender SmartScreen > Enhanced Phishing Protection > Service Enabled** and set **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WTDS\Components" /v ServiceEnabled /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 10.5 Enable Anti-Exploitation Features
- **NIST SP 800-53 Rev. 5**: SI-16 Memory Protection

Risk

High Profile Threat

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure Configure Windows Defender SmartScreen Is Set To Warn And Prevent Bypass](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#configure-windows-defender-smartscreen-is-set-to-warn-and-prevent-bypass)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.77.2

**Finding:** Windows Defender SmartScreen is not set to warn and prevent bypass.

Checks whether Windows Defender SmartScreen is turned on for File Explorer and configured to block, rather than merely warn about, unrecognized applications.

This rule fails when `enableSmartScreen` is not `WARN_PREVENT_BYPASS` or `shellSmartScreenLevel` is not `BLOCK`.

**Rationale:** SmartScreen in warn-only mode lets users click through the warning and run malicious downloads; preventing bypass stops execution of unrecognized apps.

**Impact:** Users cannot override the SmartScreen warning to run unrecognized applications.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > File Explorer > Configure Windows Defender SmartScreen** and set **Enabled: Warn and prevent bypass**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v EnableSmartScreen /t REG_DWORD /d 1 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\System" /v ShellSmartScreenLevel /t REG_SZ /d Block /f
```

Framework mappings

- **CIS Controls v8**: 10.5 Enable Anti-Exploitation Features
- **NIST SP 800-53 Rev. 5**: SI-16 Memory Protection

Risk

High Profile Threat

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

## 18.10.79 Windows Game Recording and Broadcasting

### [Ensure Windows Game Recording And Broadcasting Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#windows-game-recording-and-broadcasting-is-disabled)

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.79

**Finding:** Windows Game Recording and Broadcasting is enabled.

Checks whether the Game DVR recording and broadcasting feature is disabled.

This rule fails when `allowGameDVR` is not `false`.

**Rationale:** Game DVR can capture on-screen content and stream it, an unnecessary capability that could record sensitive information.

**Impact:** Game recording and broadcasting features are turned off.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Game Recording and Broadcasting > Enables or disables Windows Game Recording and Broadcasting** and set **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\GameDVR" /v AllowGameDVR /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## 18.10.80 Windows Hello for Business

### [Ensure Enable Enhanced Sign In Security With Supported Peripherals Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#enable-enhanced-sign-in-security-with-supported-peripherals-is-enabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.80

**Finding:** Enhanced Sign-in Security with supported peripherals is not enabled.

Checks whether Enhanced Sign-in Security uses hardware-isolated biometric processing on supported peripherals.

This rule fails when `enableESSwithSupportedPeripherals` is not `ENABLED`.

**Rationale:** Enhanced Sign-in Security isolates biometric operations from the rest of the OS, hardening Windows Hello against tampering of biometric input.

**Impact:** Biometric sign-in uses hardware-isolated processing when supported peripheral hardware is present.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Hello for Business > Enable ESS with Supported Peripherals** and set **Enabled: 1**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Microsoft\Policies\PassportForWork\Biometrics" /v EnableESSwithSupportedPeripherals /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 10.5 Enable Anti-Exploitation Features
- **NIST SP 800-53 Rev. 5**: SI-16 Memory Protection

Risk

Unprotected Principal

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

## 18.10.81 Windows Ink Workspace

### [Ensure Allow Suggested Apps In Windows Ink Workspace Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#allow-suggested-apps-in-windows-ink-workspace-is-disabled)

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.81

**Finding:** Suggested apps in Windows Ink Workspace are allowed.

Checks whether app suggestions in the Windows Ink Workspace are disabled.

This rule fails when `allowSuggestedAppsInWindowsInkWorkspace` is not `false`.

**Rationale:** App suggestions surface and advertise store content in the workspace, an unnecessary remote content channel.

**Impact:** The Windows Ink Workspace no longer shows suggested apps.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Ink Workspace > Allow suggested apps in Windows Ink Workspace** and set **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\WindowsInkWorkspace" /v AllowSuggestedAppsInWindowsInkWorkspace /t REG_DWORD /d 0 /f
```

Risk

External Attack Surface

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

### [Ensure Allow Windows Ink Workspace Is Disabled Or On Without Access Above The Lock Screen](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#allow-windows-ink-workspace-is-disabled-or-on-without-access-above-the-lock-scre)

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.81

**Finding:** Windows Ink Workspace is accessible above the lock screen.

Checks whether the Windows Ink Workspace is either disabled or, if enabled, made inaccessible from the lock screen.

This rule fails when `allowWindowsInkWorkspace` is not `DISABLED` and not `ON_NO_INK_BELOW_LOCK` (i.e. it is fully `ON`).

**Rationale:** Ink features available above the lock screen let an unauthenticated person interact with the device before signing in.

**Impact:** If enabled, the Ink Workspace is available only after sign-in; it cannot be reached from the lock screen.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Ink Workspace > Allow Windows Ink Workspace** and set **Enabled: On, but disallow access above lock** or **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\WindowsInkWorkspace" /v AllowWindowsInkWorkspace /t REG_DWORD /d 1 /f
```

Risk

Unprotected Principal

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## 18.10.82 Windows Installer

### [Ensure Allow User Control Over Installs Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#allow-user-control-over-installs-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.82

**Finding:** User control over Windows Installer installs is allowed.

Checks whether users are prevented from changing installation options that are normally reserved for administrators.

This rule fails when `enableUserControl` is not `false`.

**Rationale:** Allowing user control over installs lets non-administrators alter protected install settings, potentially installing software insecurely.

**Impact:** Users cannot override administrator-controlled Windows Installer options.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Installer > Allow user control over installs** and set **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer" /v EnableUserControl /t REG_DWORD /d 0 /f
```

Risk

Insecure Application

MITRE ATT&CK tactic

Privilege Escalation ([TA0004](https://attack.mitre.org/tactics/TA0004/))

### [Ensure Always Install With Elevated Privileges Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#always-install-with-elevated-privileges-is-disabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.82

**Finding:** Windows Installer always installs with elevated privileges.

Checks whether Windows Installer is prevented from installing packages with full system privileges for standard users.

This rule fails when `alwaysInstallElevated` is not `false`.

**Rationale:** This setting lets any user run installer packages as SYSTEM, a well-known local privilege-escalation path.

**Impact:** Windows Installer packages run with the invoking user's privileges rather than elevated system rights.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Installer > Always install with elevated privileges** and set **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer" /v AlwaysInstallElevated /t REG_DWORD /d 0 /f
```

Risk

Insecure Application

MITRE ATT&CK tactic

Privilege Escalation ([TA0004](https://attack.mitre.org/tactics/TA0004/))

### [Ensure Prevent Internet Explorer Security Prompt For Windows Installer Scripts Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#prevent-internet-explorer-security-prompt-for-windows-installer-scripts-is-disab)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.82

**Finding:** The Internet Explorer security prompt for Windows Installer scripts is suppressed.

Checks whether scripted (web-hosted) Windows Installer installs still trigger the security prompt rather than running silently.

This rule fails when `safeForScripting` is not `false`.

**Rationale:** Suppressing the prompt lets web pages silently launch installer packages, enabling drive-by software installation.

**Impact:** Scripted Windows Installer installs continue to raise the standard security prompt.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Installer > Prevent Internet Explorer security prompt for Windows Installer scripts** and set **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer" /v SafeForScripting /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 2.5 Allowlist Authorized Software
- **NIST SP 800-53 Rev. 5**: CM-7 Least Functionality; CM-10 Software Usage Restrictions
- **NIST SP 800-171 Rev. 2**: 3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; 3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
- **CMMC 2.0 Level 2**: CM.L2-3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; SC.L2-3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality

Risk

Insecure Application

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

## 18.10.83 Windows Logon Options

### [Ensure Sign In And Lock Last Interactive User Automatically After A Restart Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#sign-in-and-lock-last-interactive-user-automatically-after-a-restart-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.83

**Finding:** The last interactive user is automatically signed in and locked after an update restart.

Checks whether automatic sign-in and lock of the last interactive user after an update-driven restart is disabled.

This rule fails when `disableAutomaticRestartSignOn` is not `true`.

**Rationale:** Automatic restart sign-on caches the user's credentials to re-establish the session, exposing them if the device is captured during the reboot window.

**Impact:** After an update restart the device returns to the sign-in screen instead of auto-signing-in the last user.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Logon Options > Sign-in and lock last interactive user automatically after a restart (set to Disabled)** and set **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v DisableAutomaticRestartSignOn /t REG_DWORD /d 1 /f
```

Risk

Unprotected Principal

MITRE ATT&CK tactic

Persistence ([TA0003](https://attack.mitre.org/tactics/TA0003/))

### [Ensure Transmission Of The User Password In MPR Notifications Sent By Winlogon Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#transmission-of-the-user-password-in-mpr-notifications-sent-by-winlogon-is-disab)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.83

**Finding:** The user's password is transmitted in MPR notifications sent by winlogon.

Checks whether winlogon is prevented from including the user's plaintext password in the MPR notifications it sends to network providers.

This rule fails when `enableMPRNotifications` is not `false`.

**Rationale:** Including the password in MPR notifications exposes the credential to any registered network provider, including malicious ones.

**Impact:** Winlogon no longer includes the user's password in MPR notifications; providers relying on it lose that data.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Logon Options > Configure the transmission of the user's password in the content of MPR notifications sent by winlogon** and set **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v EnableMPRNotifications /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Insecure Use of Secrets

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

## 18.10.88 Windows PowerShell

### [Ensure Turn On PowerShell Script Block Logging Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#turn-on-powershell-script-block-logging-is-enabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.88

**Finding:** PowerShell script block logging is disabled.

Checks whether PowerShell records the content of executed script blocks to the event log.

This rule fails when `enableScriptBlockLogging` is not `true`.

**Rationale:** Script block logging captures obfuscated and in-memory PowerShell attacker activity that would otherwise leave no trace, aiding detection and investigation.

**Impact:** The content of executed PowerShell script blocks is written to the operational event log.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows PowerShell > Turn on PowerShell Script Block Logging** and set **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging" /v EnableScriptBlockLogging /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 8.8 Collect Command-Line Audit Logs
- **NIST SP 800-53 Rev. 5**: AC-6 Least Privilege; AU-2 Event Logging

Risk

High Profile Threat

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

### [Ensure Turn On PowerShell Transcription Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#turn-on-powershell-transcription-is-enabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.88

**Finding:** PowerShell transcription is disabled.

Checks whether PowerShell writes a transcript of input and output for each session to a log file.

This rule fails when `enableTranscripting` is not `true`.

**Rationale:** Session transcripts provide a durable record of interactive and scripted PowerShell activity for incident response.

**Impact:** PowerShell sessions produce transcript files capturing commands and their output.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows PowerShell > Turn on PowerShell Transcription** and set **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\PowerShell\Transcription" /v EnableTranscripting /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 8.8 Collect Command-Line Audit Logs
- **NIST SP 800-53 Rev. 5**: AC-6 Least Privilege; AU-2 Event Logging

Risk

High Profile Threat

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

## 18.10.90 Windows Remote Management (WinRM)

### [Ensure WinRM Client Allow Basic Authentication Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#winrm-client-allow-basic-authentication-is-disabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.90.1

**Finding:** The WinRM client allows Basic authentication.

Checks whether the WinRM client is prevented from using Basic authentication.

This rule fails when `winRMClientAllowBasic` is not `false`.

**Rationale:** Basic authentication sends credentials with trivial encoding; over WinRM it exposes them to interception.

**Impact:** The WinRM client can no longer authenticate to remote hosts using Basic authentication.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Remote Management (WinRM) > WinRM Client > Allow Basic authentication** and set **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WinRM\Client" /v AllowBasic /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 3.10 Encrypt Sensitive Data in Transit
- **NIST SP 800-53 Rev. 5**: AC-17 Remote Access; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
- **NIST SP 800-171 Rev. 2**: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- **CMMC 2.0 Level 2**: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- **PCI DSS v4.0.1**: 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography

Risk

Insecure Use of Secrets

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure WinRM Client Allow Unencrypted Traffic Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#winrm-client-allow-unencrypted-traffic-is-disabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.90.1

**Finding:** The WinRM client allows unencrypted traffic.

Checks whether the WinRM client is prevented from sending unencrypted management traffic.

This rule fails when `winRMClientAllowUnencryptedTraffic` is not `false`.

**Rationale:** Unencrypted WinRM traffic exposes commands and credentials to network eavesdropping and tampering.

**Impact:** The WinRM client only communicates over encrypted channels.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Remote Management (WinRM) > WinRM Client > Allow unencrypted traffic** and set **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WinRM\Client" /v AllowUnencryptedTraffic /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 3.10 Encrypt Sensitive Data in Transit
- **NIST SP 800-53 Rev. 5**: AC-17 Remote Access; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
- **NIST SP 800-171 Rev. 2**: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- **CMMC 2.0 Level 2**: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- **PCI DSS v4.0.1**: 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography

Risk

External Exposure

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure WinRM Client Disallow Digest Authentication Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#winrm-client-disallow-digest-authentication-is-enabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.90.1

**Finding:** The WinRM client allows Digest authentication.

Checks whether the WinRM client is prevented from using Digest authentication.

This rule fails when `winRMClientAllowDigest` is not `false`.

**Rationale:** Digest authentication over WinRM is weak and can expose credentials to relay and interception attacks.

**Impact:** The WinRM client can no longer use Digest authentication.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Remote Management (WinRM) > WinRM Client > Disallow Digest authentication** and set **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WinRM\Client" /v AllowDigest /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 3.10 Encrypt Sensitive Data in Transit
- **NIST SP 800-53 Rev. 5**: AC-17 Remote Access; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
- **NIST SP 800-171 Rev. 2**: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- **CMMC 2.0 Level 2**: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- **PCI DSS v4.0.1**: 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography

Risk

Insecure Use of Secrets

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure Allow Remote Server Management Through WinRM Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#allow-remote-server-management-through-winrm-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.90.2

**Finding:** Remote server management through WinRM is allowed.

Checks whether the WinRM service is prevented from automatically listening for and accepting remote management requests.

This rule fails when `winRMServiceAllowAutoConfig` is not `false`.

**Rationale:** An always-listening WinRM service is a remote entry point that can be leveraged for lateral movement.

**Impact:** The WinRM service does not automatically configure a listener for remote management.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Remote Management (WinRM) > WinRM Service > Allow remote server management through WinRM** and set **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WinRM\Service" /v AllowAutoConfig /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Exposure

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure Disallow WinRM From Storing RunAs Credentials Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#disallow-winrm-from-storing-runas-credentials-is-enabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.90.2

**Finding:** WinRM is allowed to store RunAs credentials.

Checks whether the WinRM service is prevented from storing RunAs credentials for plug-ins.

This rule fails when `winRMServiceDisableRunAs` is not `true`.

**Rationale:** Stored RunAs credentials can be extracted from the host and reused, enabling credential theft.

**Impact:** WinRM plug-ins can no longer store RunAs credentials on the host.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Remote Management (WinRM) > WinRM Service > Disallow WinRM from storing RunAs credentials** and set **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WinRM\Service" /v DisableRunAs /t REG_DWORD /d 1 /f
```

Risk

Insecure Use of Secrets

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure WinRM Service Allow Basic Authentication Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#winrm-service-allow-basic-authentication-is-disabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.90.2

**Finding:** The WinRM service allows Basic authentication.

Checks whether the WinRM service is prevented from accepting Basic authentication.

This rule fails when `winRMServiceAllowBasic` is not `false`.

**Rationale:** Accepting Basic authentication lets remote clients present credentials with trivial encoding, exposing them to interception.

**Impact:** The WinRM service rejects Basic authentication from remote clients.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Remote Management (WinRM) > WinRM Service > Allow Basic authentication** and set **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WinRM\Service" /v AllowBasic /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 3.10 Encrypt Sensitive Data in Transit
- **NIST SP 800-53 Rev. 5**: AC-17 Remote Access; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
- **NIST SP 800-171 Rev. 2**: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- **CMMC 2.0 Level 2**: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- **PCI DSS v4.0.1**: 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography

Risk

Insecure Use of Secrets

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure WinRM Service Allow Unencrypted Traffic Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#winrm-service-allow-unencrypted-traffic-is-disabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.90.2

**Finding:** The WinRM service allows unencrypted traffic.

Checks whether the WinRM service is prevented from accepting unencrypted management traffic.

This rule fails when `winRMServiceAllowUnencryptedTraffic` is not `false`.

**Rationale:** Unencrypted WinRM traffic exposes commands and credentials to network eavesdropping and tampering.

**Impact:** The WinRM service only accepts management traffic over encrypted channels.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Remote Management (WinRM) > WinRM Service > Allow unencrypted traffic** and set **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WinRM\Service" /v AllowUnencryptedTraffic /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 3.10 Encrypt Sensitive Data in Transit
- **NIST SP 800-53 Rev. 5**: AC-17 Remote Access; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
- **NIST SP 800-171 Rev. 2**: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- **CMMC 2.0 Level 2**: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- **PCI DSS v4.0.1**: 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography

Risk

External Exposure

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## 18.10.91 Windows Remote Shell

### [Ensure Allow Remote Shell Access Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#allow-remote-shell-access-is-disabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.91

**Finding:** Remote shell access is allowed.

Checks whether remote shell (WinRS) access to the computer is disabled.

This rule fails when `allowRemoteShellAccess` is not `false`.

**Rationale:** Remote shell access provides an interactive command channel to the host that can be abused for lateral movement and command execution.

**Impact:** Remote WinRS shell connections to the computer are refused.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Remote Shell > Allow Remote Shell Access** and set **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WinRM\Service\WinRS" /v AllowRemoteShellAccess /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Exposure

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## 18.10.92 Windows Sandbox

### [Ensure Allow Clipboard Sharing With Windows Sandbox Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#allow-clipboard-sharing-with-windows-sandbox-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.92

**Finding:** Clipboard sharing with Windows Sandbox is allowed.

Checks whether clipboard sharing between the host and Windows Sandbox is disabled.

This rule fails when `allowClipboardRedirection` is not `false`.

**Rationale:** A shared clipboard bridges data between the untrusted sandbox and the host, undermining the isolation the sandbox provides.

**Impact:** The clipboard is not shared between the host and Windows Sandbox.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Sandbox > Allow clipboard sharing with Windows Sandbox** and set **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Sandbox" /v AllowClipboardRedirection /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Allow Mapping Folders Into Windows Sandbox Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#allow-mapping-folders-into-windows-sandbox-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.92

**Finding:** Mapping folders into Windows Sandbox is allowed.

Checks whether host folders can be mapped into Windows Sandbox with write access.

This rule fails when `allowWriteToMappedFolders` is not `false`.

**Rationale:** Mapped folders let files move between the untrusted sandbox and the host filesystem, undermining the sandbox isolation.

**Impact:** Host folders can no longer be mapped with write access into Windows Sandbox.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Sandbox > Allow mapping folders into Windows Sandbox** and set **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Sandbox" /v AllowWriteToMappedFolders /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Allow Networking In Windows Sandbox Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#allow-networking-in-windows-sandbox-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.92

**Finding:** Networking in Windows Sandbox is allowed.

Checks whether network access from within Windows Sandbox is disabled.

This rule fails when `allowNetworking` is not `false`.

**Rationale:** Network access lets untrusted code in the sandbox reach the internal network and external command channels.

**Impact:** Windows Sandbox instances run without network connectivity.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Sandbox > Allow networking in Windows Sandbox** and set **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Sandbox" /v AllowNetworking /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Exposure

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## 18.10.93 Windows Security

### [Ensure Prevent Users From Modifying Exploit Protection Settings Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#prevent-users-from-modifying-exploit-protection-settings-is-enabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.93.2

**Finding:** Users are allowed to modify Exploit Protection settings.

Checks whether standard users are prevented from changing Exploit Protection settings in the Windows Security app.

This rule fails when `disallowExploitProtectionOverride` is not `true`.

**Rationale:** If users can weaken Exploit Protection, malware or an unwitting user can disable key exploit mitigations.

**Impact:** Users can no longer modify Exploit Protection settings; only administrators via policy can change them.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Security > App and browser protection > Prevent users from modifying settings** and set **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender Security Center\App and Browser protection" /v DisallowExploitProtectionOverride /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 10.5 Enable Anti-Exploitation Features
- **NIST SP 800-53 Rev. 5**: SI-16 Memory Protection

Risk

High Profile Threat

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

## 18.10.94 Windows Update

### [Ensure No Auto Restart With Logged On Users For Scheduled Automatic Updates Installations Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#no-auto-restart-with-logged-on-users-for-scheduled-automatic-updates-installatio)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.94.1

**Finding:** Automatic-update installations wait for logged-on users instead of restarting to complete.

Checks whether scheduled automatic-update installations are allowed to restart the computer rather than waiting indefinitely for a logged-on user.

This rule fails when `noAutoRebootWithLoggedOnUsers` is not `false`.

**Rationale:** Suppressing the restart leaves update installations incomplete, so critical security fixes are not applied until the user chooses to reboot.

**Impact:** Scheduled automatic-update installations restart the computer to complete, after warning logged-on users.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Update > Legacy Policies > No auto-restart with logged on users for scheduled automatic updates installations** and set **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v NoAutoRebootWithLoggedOnUsers /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 7.3 Perform Automated Operating System Patch Management
- **NIST SP 800-53 Rev. 5**: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation

Risk

Reliability Impact

MITRE ATT&CK tactic

Impact ([TA0040](https://attack.mitre.org/tactics/TA0040/))

### [Ensure Configure Automatic Updates Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#configure-automatic-updates-is-enabled)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.94.2

**Finding:** Automatic Updates are not configured (turned off).

Checks whether Automatic Updates are enabled so the device downloads and installs updates on a schedule.

This rule fails when `noAutoUpdate` is not `false`.

**Rationale:** Disabled automatic updates leave known vulnerabilities unpatched, exposing the device to exploitation.

**Impact:** The device automatically downloads and installs Windows updates on the configured schedule.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Update > Manage end user experience > Configure Automatic Updates** and set **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v NoAutoUpdate /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 7.3 Perform Automated Operating System Patch Management
- **NIST SP 800-53 Rev. 5**: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation

Risk

Vulnerability

MITRE ATT&CK tactic

Impact ([TA0040](https://attack.mitre.org/tactics/TA0040/))

### [Ensure Configure Automatic Updates Scheduled Install Day Is Set To Every Day](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#configure-automatic-updates-scheduled-install-day-is-set-to-every-day)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.94.2

**Finding:** The Automatic Updates scheduled install day is not set to every day.

Checks whether scheduled automatic-update installation is set to occur every day rather than on a single weekday.

This rule fails when `scheduledInstallDay` is not `EVERY_DAY`.

**Rationale:** Installing updates every day minimises the window in which a released fix is available but not yet applied.

**Impact:** Scheduled automatic-update installations run every day rather than only on one weekday.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Update > Manage end user experience > Configure Automatic Updates** and set **Enabled: 0 - Every day (Scheduled install day)**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v ScheduledInstallDay /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 7.3 Perform Automated Operating System Patch Management
- **NIST SP 800-53 Rev. 5**: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation

Risk

Vulnerability

MITRE ATT&CK tactic

Impact ([TA0040](https://attack.mitre.org/tactics/TA0040/))

### [Ensure Enable Features Introduced Via Servicing That Are Off By Default Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#enable-features-introduced-via-servicing-that-are-off-by-default-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.94.2

**Finding:** Features introduced via servicing that are off by default may be turned on.

Checks whether features that ship turned-off within monthly quality updates are prevented from being enabled automatically.

This rule fails when `allowTemporaryEnterpriseFeatureControl` is not `false`.

**Rationale:** Allowing off-by-default serviced features to turn on introduces unvalidated functionality outside of planned feature updates.

**Impact:** New features delivered off-by-default in quality updates remain off until explicitly enabled.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Update > Manage end user experience > Enable features introduced via servicing that are off by default** and set **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /v AllowTemporaryEnterpriseFeatureControl /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 7.3 Perform Automated Operating System Patch Management
- **NIST SP 800-53 Rev. 5**: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation

Risk

Reliability Impact

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

### [Ensure Remove Access To Pause Updates Feature Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#remove-access-to-pause-updates-feature-is-enabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.94.2

**Finding:** Access to the Pause updates feature is available to users.

Checks whether the user-facing option to pause Windows updates is removed.

This rule fails when `setDisablePauseUXAccess` is not `true`.

**Rationale:** If users can pause updates, they can delay critical security fixes indefinitely, leaving the device exposed.

**Impact:** The Pause updates option is removed from the Windows Update settings UI.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Update > Manage end user experience > Remove access to "Pause updates" feature** and set **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /v SetDisablePauseUXAccess /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 7.3 Perform Automated Operating System Patch Management
- **NIST SP 800-53 Rev. 5**: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation

Risk

Vulnerability

MITRE ATT&CK tactic

Impact ([TA0040](https://attack.mitre.org/tactics/TA0040/))

### [Ensure Enable Optional Updates Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#enable-optional-updates-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.94.4

**Finding:** Optional updates are enabled.

Checks whether the device is prevented from receiving optional updates, including Controlled Feature Rollouts.

This rule fails when `setAllowOptionalContent` is not `false`.

**Rationale:** Optional updates and gradual feature rollouts deliver unvalidated changes outside the planned update cycle.

**Impact:** The device does not receive optional updates or Controlled Feature Rollouts.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Update > Manage updates offered from Windows Update > Enable optional updates** and set **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /v SetAllowOptionalContent /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 7.3 Perform Automated Operating System Patch Management
- **NIST SP 800-53 Rev. 5**: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation

Risk

Reliability Impact

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

### [Ensure Manage Preview Builds Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#manage-preview-builds-is-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.94.4

**Finding:** Windows Insider preview builds are not blocked.

Checks whether installation of Windows Insider preview builds is blocked.

This rule fails when `managePreviewBuilds` is not `DISABLE`.

**Rationale:** Preview builds are pre-release and unsupported for production, carrying stability and security risk.

**Impact:** Windows Insider preview builds cannot be installed on the device.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Update > Manage updates offered from Windows Update > Manage preview builds** and set **Enabled: Disable preview builds**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /v ManagePreviewBuildsPolicyValue /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 2.5 Allowlist Authorized Software
- **NIST SP 800-53 Rev. 5**: CM-7 Least Functionality; CM-10 Software Usage Restrictions
- **NIST SP 800-171 Rev. 2**: 3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; 3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
- **CMMC 2.0 Level 2**: CM.L2-3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software; SC.L2-3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception)
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality

Risk

Reliability Impact

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

### [Ensure Select When Quality Updates Are Received Is Set To Zero Days](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/windows-components.html#select-when-quality-updates-are-received-is-set-to-zero-days)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.10.94.4

**Finding:** Quality updates are deferred by more than zero days.

Checks whether the quality-update deferral policy is configured with a deferral period of zero days, so security fixes are received without delay.

This rule fails when `deferQualityUpdates` is not `true` or `deferQualityUpdatesPeriodInDays` is not `0`.

**Rationale:** Deferring quality updates delays the delivery of security fixes, leaving known vulnerabilities unpatched for the deferral period.

**Impact:** Quality updates are received as soon as they are released, with no deferral.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Update > Manage updates offered from Windows Update > Select when Quality Updates are received** and set **Enabled: 0 days**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /v DeferQualityUpdates /t REG_DWORD /d 1 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /v DeferQualityUpdatesPeriodInDays /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 7.3 Perform Automated Operating System Patch Management
- **NIST SP 800-53 Rev. 5**: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation

Risk

Vulnerability

MITRE ATT&CK tactic

Impact ([TA0040](https://attack.mitre.org/tactics/TA0040/))

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
