Windows 10 BSI Report

Generated by the ATAPAuditor Module Version 4.14 by FB Pro GmbH. Get it in the Audit Test Automation Package. Are you seeing a lot of red sections? Check out our hardening solutions.

Based on:

This report was generated on 01/17/2022 14:01:24 on DESKTOP-UTMU75K.fb-pro.com with TAPHtmlReport version 1.8.

HostnameDESKTOP-UTMU75K.fb-pro.com
Build Number19043
Free disk space(GB) 100.1
Free physical memory (GB)4.972
Operating SystemMicrosoft Windows 10 Pro
Installation LanguageEnglish (United States)

Summary

A total of 1250 tests have been executed.

  1. True 994 test(s) ≙ 79.52%
  2. False 256 test(s) ≙ 20.48%
  3. Warning 0 test(s) ≙ 0.00%
  4. None 0 test(s) ≙ 0.00%
  5. Error 0 test(s) ≙ 0.00%

BSI Benchmarks SiSyPHuS Logging

A total of 51 tests have been executed in section BSI Benchmarks SiSyPHuS Logging.

  1. True 51 test(s) ≙ 100.00%
  2. False 0 test(s) ≙ 0.00%
  3. Warning 0 test(s) ≙ 0.00%
  4. None 0 test(s) ≙ 0.00%
  5. Error 0 test(s) ≙ 0.00%

BSI Benchmarks SiSyPHuS HD

A total of 379 tests have been executed in section BSI Benchmarks SiSyPHuS HD.

  1. True 313 test(s) ≙ 82.59%
  2. False 66 test(s) ≙ 17.41%
  3. Warning 0 test(s) ≙ 0.00%
  4. None 0 test(s) ≙ 0.00%
  5. Error 0 test(s) ≙ 0.00%

BSI Benchmarks SiSyPHuS ND

A total of 287 tests have been executed in section BSI Benchmarks SiSyPHuS ND.

  1. True 240 test(s) ≙ 83.62%
  2. False 47 test(s) ≙ 16.38%
  3. Warning 0 test(s) ≙ 0.00%
  4. None 0 test(s) ≙ 0.00%
  5. Error 0 test(s) ≙ 0.00%

BSI Benchmarks SiSyPHuS NE

A total of 258 tests have been executed in section BSI Benchmarks SiSyPHuS NE.

  1. True 212 test(s) ≙ 82.17%
  2. False 46 test(s) ≙ 17.83%
  3. Warning 0 test(s) ≙ 0.00%
  4. None 0 test(s) ≙ 0.00%
  5. Error 0 test(s) ≙ 0.00%

BSI Benchmarks SiM-08202 - BPOL

A total of 275 tests have been executed in section BSI Benchmarks SiM-08202 - BPOL.

  1. True 178 test(s) ≙ 64.73%
  2. False 97 test(s) ≙ 35.27%
  3. Warning 0 test(s) ≙ 0.00%
  4. None 0 test(s) ≙ 0.00%
  5. Error 0 test(s) ≙ 0.00%

Table of Contents

Click the link(s) below for quick access to a report section.

BSI Benchmarks SiSyPHuS Logging-

This section contains the BSI Benchmark results.

Registry Settings/Group Policies-

IdTaskMessageStatus
4.1.1Ensure 'Audit: Shut down system immediately if unable to log security audits' is set to 'Disabled'CompliantTrue
4.1.2Ensure 'Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings' is set to 'Enabled'CompliantTrue
4.2.1.1Ensure 'Windows Firewall: Domain: Logging: Name' is set to '%SystemRoot%\System32\logfiles\firewall\domainfw.log'CompliantTrue
4.2.1.2Ensure 'Windows Firewall: Domain: Logging: Size limit (KB)' is set to '16,384 KB or greater'CompliantTrue
4.2.1.3Ensure 'Windows Firewall: Domain: Logging: Log dropped packets' is set to 'Yes'CompliantTrue
4.2.1.4Ensure 'Windows Firewall: Domain: Logging: Log successful connections' is set to 'Yes'CompliantTrue
4.2.2.1Ensure 'Windows Firewall: Private: Logging: Name' is set to '%SystemRoot%\System32\logfiles\firewall\privatefw.log'CompliantTrue
4.2.2.2Ensure 'Windows Firewall: Private: Logging: Size limit (KB)' is set to '16,384 KB or greater'CompliantTrue
4.2.2.3Ensure 'Windows Firewall: Private: Logging: Log dropped packets' is set to 'Yes'CompliantTrue
4.2.2.4Ensure 'Windows Firewall: Private: Logging: Log successful connections' is set to 'Yes'CompliantTrue
4.2.3.1Ensure 'Windows Firewall: Public: Settings: Apply local firewall rules' is set to 'No'CompliantTrue
4.2.3.2Ensure 'Windows Firewall: Public: Settings: Apply local connection security rules' is set to 'No'CompliantTrue
4.2.3.3Ensure 'Windows Firewall: Public: Logging: Name' is set to '%SystemRoot%\System32\logfiles\firewall\publicfw.log'CompliantTrue
4.2.3.4Ensure 'Windows Firewall: Public: Logging: Size limit (KB)' is set to '16,384 KB or greater'CompliantTrue
4.3.1.1Ensure 'MSS: (WarningLevel) Percentage threshold for the security event log at which the system will generate a warning' is set to 'Enabled: 90% or less'CompliantTrue
4.3.2.1.1Ensure 'Application: Specify the maximum log file size (KB)' is set to 'Enabled: 32,768 or greater'CompliantTrue
4.3.2.1.2Ensure 'Application: Control Event Log behavior when the log file reaches its maximum size' is set to 'Disabled'CompliantTrue
4.3.2.2.1Ensure 'Setup: Specify the maximum log file size (KB)' is set to 'Enabled: 32,768 or greater'CompliantTrue
4.3.2.2.2Ensure 'Setup: Control Event Log behavior when the log file reaches its maximum size' is set to 'Disabled'CompliantTrue
4.3.2.3.1Ensure 'Security: Specify the maximum log file size (KB)' is set to 'Enabled: 196,608 or greater'CompliantTrue
4.3.2.3.2Ensure 'Security: Control Event Log behavior when the log file reaches its maximum size' is set to 'Disabled'CompliantTrue
4.3.2.4.1Ensure 'System: Specify the maximum log file size (KB)' is set to 'Enabled: 32,768 or greater'CompliantTrue
4.3.2.4.2Ensure 'System: Control Event Log behavior when the log file reaches its maximum size' is set to 'Disabled'CompliantTrue
4.3.3.1Ensure 'Include command line in process creation events' is set to 'Disabled'CompliantTrue
4.3.4.2Ensure 'Turn on PowerShell Script Block Logging' is set to 'Disabled'CompliantTrue
4.3.4.3Ensure 'Turn on PowerShell Transcription' is set to 'Disabled'CompliantTrue

Advanced Audit Policy Configuration-

IdTaskMessageStatus
5.1.1.1Ensure 'Audit Credential Validation' is set to 'Success and Failure'CompliantTrue
5.1.1.2Ensure 'Audit User Account Management' is set to 'Success and Failure'CompliantTrue
5.1.1.3Ensure 'Audit Account Lockout' is set to include 'Failure'CompliantTrue
5.1.1.4Ensure 'Audit Group Membership' is set to include 'Success'CompliantTrue
5.1.1.5Ensure 'Audit Logoff' is set to include 'Success'CompliantTrue
5.1.1.6Ensure 'Audit Logon' is set to 'Success and Failure'CompliantTrue
5.1.1.7Ensure 'Audit Other Logon/Logoff Events' is set to 'Success and Failure'CompliantTrue
5.1.1.8Ensure 'Audit Special Logon' is set to include 'Success'CompliantTrue
5.2.1.1Ensure 'Audit Other System Events' is set to 'Success and Failure'CompliantTrue
5.2.1.2Ensure 'Audit Security State Change' is set to include 'Success'CompliantTrue
5.2.1.3Ensure 'Audit Security System Extension' is set to include 'Success'CompliantTrue
5.2.1.4Ensure 'Audit System Integrity' is set to 'Success and Failure'CompliantTrue
5.2.1.5Ensure 'Audit File Share' is set to 'Success and Failure'CompliantTrue
5.2.1.6Ensure 'Audit Detailed File Share' is set to include 'Failure'CompliantTrue
5.2.1.7Ensure 'Audit Other Object Access Events' is set to 'Success and Failure'CompliantTrue
5.2.1.8Ensure 'Audit Removable Storage' is set to 'Success and Failure'CompliantTrue
5.2.1.9Ensure 'Audit PNP Activity' is set to include 'Success'CompliantTrue
5.3.1.1Ensure 'Audit Security Group Management' is set to include 'Success'CompliantTrue
5.3.1.2Ensure 'Audit Audit Policy Change' is set to include 'Success'CompliantTrue
5.3.1.3Ensure 'Audit Authentication Policy Change' is set to include 'Success'CompliantTrue
5.3.1.4Ensure 'Audit Authorization Policy Change' is set to include 'Success'CompliantTrue
5.3.1.5Ensure 'Audit MPSSVC Rule-Level Policy Change' is set to 'Success and Failure'CompliantTrue
5.3.1.6Ensure 'Audit Other Policy Change Events' is set to include 'Failure'CompliantTrue
5.5.1.1Ensure 'Audit Process Creation' is set to include 'Success'CompliantTrue
5.5.1.2Ensure 'Audit Sensitive Privilege Use' is set to 'Success and Failure'CompliantTrue

BSI Benchmarks SiSyPHuS HD-

This section contains the BSI Benchmark results.

Registry Settings/Group Policies-

IdTaskMessageStatus
1(ND, NE) Ensure 'Apply UAC restrictions to local accounts on network logons' is set to 'Enabled'. CompliantTrue
2(ND, NE) Ensure 'Configure SMB v1 client driver' is set to 'Enabled: Disable driver.CompliantTrue
3(ND, NE) Ensure 'Configure SMB v1 server' is set to 'Disabled'.CompliantTrue
4(ND, NE) Ensure 'Enable Structured Exception Handling OverwriteProtection (SEHOP)' is set to 'Enabled'.CompliantTrue
5(ND, NE) Ensure 'WDigest Authentication' is set to 'Disabled'.CompliantTrue
7(ND, NE) Ensure 'MSS: (EnableDeadGWDetect) Allow automatic detection of dead network gateways (could lead to DoS)' is set to 'Disabled'.Registry value not found.False
8(ND, NE) Ensure 'MSS: (AutoAdminLogon) Enable Automatic Logon(not recommended)' is set to 'Disabled'.CompliantTrue
9(ND, NE) Ensure 'MSS: (DisableIPSourceRouting IPv6) IP source routingprotection level (protects against packet spoofing)' is set to 'Enabled:Highest protection, source routing is completely disabled'.CompliantTrue
10(ND, NE) Ensure 'MSS: (DisableIPSourceRouting IPv6) IP source routing protection level (protects against packet spoofing)' is set to 'Enabled:Highest protection, source routing is completely disabled'.CompliantTrue
11(HD) Ensure 'MSS: (DisableSavePassword) Prevent the dial-up password from being saved' is set to 'Enabled'.CompliantTrue
12(ND, NE) Ensure 'MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes' is set to 'Disabled'.CompliantTrue
13(HD) Ensure 'MSS: (KeepAliveTime) How often keep-alive packets are sent in milliseconds' is set to 'Enabled: 300,000 or 5 minutes (recommended)'.CompliantTrue
14(ND, NE) Ensure 'MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers' is set to 'Enabled'.CompliantTrue
15(HD) Ensure 'MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses (could lead to DoS)' is set to 'Disabled'.CompliantTrue
16(ND, NE) Ensure 'MSS: (SafeDllSearchMode) Enable Safe DLL search mode (recommended)' is set to 'Enabled'.CompliantTrue
17(ND, NE) Ensure 'MSS: (ScreenSaverGracePeriod) The time in seconds before the screen saver grace period expires (0 recommended)' is set to 'Enabled: 5 or fewer seconds'CompliantTrue
18(HD) Ensure 'MSS: (TcpMaxDataRetransmissions IPv6) How many times unacknowledged data is retransmitted' is set to 'Enabled: 3'.CompliantTrue
19(HD) Ensure 'MSS: (TcpMaxDataRetransmissions) How many times unacknowledged data is retransmitted' is set to 'Enabled: 3.CompliantTrue
20(ND, NE) Ensure 'Turn off multicast name resolution' is set to 'Enabled'.CompliantTrue
21(ND, NE) Ensure 'NetBIOS node type' is set to 'P-node'.CompliantTrue
22(ND, NE) Ensure 'Enable insecure guest logons' is set to 'Disabled'.CompliantTrue
23(HD) Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' is set to 'Enabled'CompliantTrue
24_1(ND, NE) Ensure 'Hardened UNC Paths' is set to "Require Mutual Authentication=1, "Require Integrity=1" for the value names "\\*\NETLOGON" und "\\*\SYSVOL".CompliantTrue
24_2(ND, NE) Ensure 'Hardened UNC Paths' is set to "Require Mutual Authentication=1, "Require Integrity=1" for the value names "\\*\NETLOGON" und "\\*\SYSVOL".CompliantTrue
25(ND) Ensure 'Require domain users to elevate when setting a network's location' is set to 'Enabled'.CompliantTrue
26(ND) Ensure 'Prohibit installation and configuration of Network Bridge on your DNS domain network' is set to 'Enabled'. CompliantTrue
27(ND) Ensure 'Prohibit use of Internet Connection Sharing on your DNS domain network' is set to 'Enabled'.CompliantTrue
28(HD) Ensure 'Enable Font Providers' is set to 'Disabled'. CompliantTrue
29(HD) Ensure 'Turn on Responder (RSPNDR) driver' is set to 'Disabled'.CompliantTrue
30(HD) Ensure 'Turn on Mapper I/O (LLTDIO) driver' is set to 'Disabled'. CompliantTrue
31(HD) Ensure 'Configuration of wireless settings using Windows Connect Now' is set to 'Disabled'.CompliantTrue
32(HD) Ensure 'Prohibit access of the Windows Connect Now wizards' is set to 'Enabled'.CompliantTrue
33(ND, NE) Ensure 'Minimize the number of simultaneous connections to the Internet or a Windows Domain' is set to the value 'Enabled: 1 = Minimize the number of simultaneous connections'.Registry value not found.False
34(ND) Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled' CompliantTrue
35(ND, NE) Ensure 'Allow Windows to automatically connect to suggested open hotspots, to networks shared by contacts, and to hotspots offering paid services' is set to 'Disabled'.CompliantTrue
36(HD) Ensure 'Turn off notifications network usage' is set to 'Enabled'.CompliantTrue
37(ND, NE) Ensure 'Turn off toast notifications on the lock screen' is set to 'Enabled'. Registry value not found.False
38(HD) Ensure 'Turn off Help Experience Improvement Program' is set to 'Enabled'.Registry key not found.False
39(ND, NE) Ensure 'Turn off picture password sign-in' is set to 'Enabled'. CompliantTrue
40(ND, NE) Ensure 'Turn off app notifications on the lock screen' is set to 'Enabled'. CompliantTrue
41(ND, NE) Ensure 'Block user from showing account details on signin' is set to 'Enabled'.CompliantTrue
42(ND) Ensure 'Turn on convenience PIN sign-in' is set to 'Disabled'.CompliantTrue
43(ND) Ensure 'Enumerate local users on domain-joined computers' is set to 'Disabled'.CompliantTrue
44(ND, NE) Ensure 'Do not display network selection UI' is set to 'Enabled'.CompliantTrue
45(ND) Ensure 'Do not enumerate connected users on domain-joined computers' is set to 'Enabled'.CompliantTrue
46(ND, NE) Ensure 'Boot-Start Driver Initialization Policy' is set to 'Enabled: Good, unknown and bad but critical'.CompliantTrue
47(HD) Ensure 'Turn off the advertising ID' is set to 'Enabled'.CompliantTrue
48(HD) Ensure 'Allow upload of User Activities' is set to 'Disabled'.CompliantTrue
49(HD) Ensure 'Allow Clipboard synchronization across devices' is set to 'Disabled'.CompliantTrue
50(ND, NE) Ensure 'Encryption Oracle Remediation' is set to 'Enabled: Force Updated Clients'.CompliantTrue
51(ND) Ensure 'Remote host allows delegation of non-exportable credentials' is set to 'Enabled'.CompliantTrue
52(ND, NE) Ensure 'Require a password when a computer wakes (on battery)' is set to 'Enabled' .CompliantTrue
53(ND, NE) Ensure 'Require a password when a computer wakes (plugged in)' is set to 'Enabled'.CompliantTrue
54(ND, NE) Ensure 'Allow network connectivity during connected-standby (on battery)' is set to 'Disabled'.CompliantTrue
55(ND, NE) Ensure 'Allow network connectivity during connected-standby (plugged in)' is set to 'Disabled'.CompliantTrue
56(ND, NE) Ensure 'Allow standby states (S1-S3) when sleeping (on battery)' is set to 'Disabled'.CompliantTrue
57(ND, NE) Ensure 'Allow standby states (S1-S3) when sleeping (plugged in)' is set to 'Disabled'.CompliantTrue
58(HD) Ensure 'Disallow copying of user input methods to the system account for sign-in' is set to 'Enabled'.CompliantTrue
59(ND, NE) Ensure 'Prevent installation of devices that match any of these device IDs' is configured.Registry value not found.False
60(ND, NE) Ensure 'Prevent installation of devices using drivers that match these device setup classes' is configured.CompliantTrue
61(ND, NE) Ensure 'Continue experiences on this device' is set to 'Disabled'.CompliantTrue
62(ND) Ensure 'Turn off background refresh of Group Policy' is set to 'Disabled'.CompliantTrue
63(ND) Ensure 'Configure registry policy processing: Process even if the Group Policy objects have not changed' is set to 'Enabled: TRUE'. CompliantTrue
64(ND) Ensure 'Configure registry policy processing: Do not apply during periodic background processing' is set to 'Enabled: FALSE'.CompliantTrue
65(ND) Ensure 'Configure security policy processing: Process even if the Group Policy objects have not changed' is set to 'Enabled'.Registry key not found.False
66(HD) Ensure 'Turn off the "Order Prints" picture task' is set to 'Enabled'.CompliantTrue
67(HD) Ensure 'Turn off the "Publish to Web" task for files and folders' is set to 'Enabled'.CompliantTrue
68(ND, NE) Ensure 'Turn off downloading of print drivers over HTTP' is set to 'Enabled'.CompliantTrue
69(HD) Ensure 'Turn off printing over HTTP' is set to 'Enabled'.CompliantTrue
70(HD) Ensure 'Turn off Windows Error Reporting' is set to 'Enabled'.Registry key not found.False
71(HD) Ensure 'Turn off handwriting personalization data sharing' is set to 'Enabled'.CompliantTrue
72(HD) Ensure 'Turn off handwriting recognition error reporting' is set to 'Enabled'. CompliantTrue
73(HD) Ensure 'Turn off Search Companion content file updates' is set to 'Enabled'.CompliantTrue
74(ND, NE) Ensure 'Turn off Internet download for Web publishing and online ordering wizards' is set to 'Enabled'.CompliantTrue
75(HD) Ensure 'Turn off the Windows Messenger Customer Experience Improvement Program' is set to 'Enabled'. CompliantTrue
76(HD) Ensure 'Turn off Windows Customer Experience Improvement Program' is set to 'Enabled'.CompliantTrue
77(HD) Ensure 'Turn off Registration if URL connection is referring to Microsoft.com' is set to 'Enabled'. CompliantTrue
78(HD) Ensure 'Turn off Internet Connection Wizard if URL connection is referring to Microsoft.com' is set to 'Enabled'. CompliantTrue
79(HD) Ensure 'Turn off access to the Store' is set to 'Enabled'.CompliantTrue
80(HD) Ensure 'Support device authentication using certificate' is set to 'Enabled: Automatic'.CompliantTrue
81(ND, NE) Ensure 'Enumeration policy for external devices incompatible with Kernel DMA Protection' is set to 'Enabled: Block All'.CompliantTrue
82(HD) Ensure 'Microsoft Support Diagnostic Tool: Turn on MSDT interactive communication with support provider' is set to 'Disabled' .CompliantTrue
83(HD) Ensure 'Enable/Disable PerfTrack' is set to 'Disabled'.CompliantTrue
84(ND, NE) Ensure 'Restrict Unauthenticated RPC clients' is set to 'Enabled: Authenticated' .CompliantTrue
85(ND, NE) Ensure 'Enable RPC Endpoint Mapper Client Authentication' is set to 'Enabled'. CompliantTrue
86(ND, NE) Ensure 'Configure Solicited Remote Assistance' is set to 'Disabled'.CompliantTrue
87(ND, NE) Ensure 'Configure Offer Remote Assistance' is set to 'Disabled'.CompliantTrue
88(ND, NE) Ensure 'Ignore the default list of blocked TPM commands' is set to 'Disabled'.Registry key not found.False
89(ND, NE) Ensure 'Standard User Lockout Duration' is set to '30 minutes'.Registry value not found.False
90(ND, NE) Ensure 'Standard User Total Lockout Threshold' is set to '5'.Registry value not found.False
91(HD) Ensure 'Enable Windows NTP Client' is set to 'Enabled'. Registry key not found.False
92(HD) Ensure 'Enable Windows NTP Server' is set to 'Disabled'.Registry key not found.False
93(HD) Ensure 'Allow Online Tips' is set to 'Disabled'.CompliantTrue
94(ND, NE) Ensure 'Prevent enabling lock screen slide show' is set to 'Enabled'.CompliantTrue
95(ND, NE) Ensure 'Prevent enabling lock screen camera' is set to 'Enabled'.CompliantTrue
96(ND, NE) Ensure 'Force specific screen saver: Screen saver executable name' is set to 'Enabled: scrnsave.scr'.Registry key not found.False
97(ND, NE) Ensure 'Enable screen saver' is set to 'Enabled'.Registry key not found.False
98(ND, NE) Ensure 'Password protect the screen saver' is set to 'Enabled'.Registry key not found.False
99(ND, NE) Ensure 'Screen saver timeout' is set to 'Enabled: 900 seconds or fewer, but not 0'.Registry key not found.False
100_1(ND, NE) Ensure 'Turn off automatic learning' is set to 'Enabled'.Registry value not found.False
100_2(ND, NE) Ensure 'Turn off automatic learning' is set to 'Enabled'.Registry value not found.False
101(ND, NE) Ensure 'Allow users to enable online speech recognition services' is set to 'Disabled'.CompliantTrue
102(ND, NE) Ensure 'Notify antivirus programs when opening attachments' is set to 'Enabled'. Registry key not found.False
103(ND, NE) Ensure 'Do not preserve zone information in file attachments' is set to 'Disabled'.Registry key not found.False
104(HD) Ensure 'Block launching Universal Windows apps with Windows Runtime API access from hosted content.' is set to 'Enabled'. CompliantTrue
105(ND) Ensure 'Allow Microsoft accounts to be optional' is set to 'Enabled'.CompliantTrue
106(ND, NE) Ensure 'Enumerate administrator accounts on elevation' is set to 'Disabled'.CompliantTrue
107(ND, NE) Ensure 'Do not display the password reveal button' is set to 'Enabled'.CompliantTrue
108(HD) Ensure 'Allow a Windows app to share application data between users' is set to 'Disabled'. CompliantTrue
109(ND, NE) Ensure 'Configure enhanced anti-spoofing' is set to 'Enabled'.CompliantTrue
110(HD) Ensure 'Turn off all Windows spotlight features' is set to 'Enabled'. Registry value not found.False
111(HD) Ensure 'Do not use diagnostic data for tailored experiences' is set to 'Enabled'.Registry value not found.False
112(ND, NE) Ensure 'Do not suggest third-party content in Windows spotlight' is set to 'Enabled'.Registry value not found.False
113(ND, NE) Ensure 'Turn off Microsoft consumer experiences' is set to 'Enabled'.CompliantTrue
114(ND, NE) Ensure 'Configure Windows spotlight on lock screen' is set to Disabled'.Registry value not found.False
115(ND, NE) Ensure 'Turn off Data Execution Prevention for Explorer' is set to 'Disabled'.CompliantTrue
116(ND, NE) Ensure 'Turn off shell protocol protected mode' is set to 'Disabled'.CompliantTrue
117(ND, NE) Ensure 'Turn off heap termination on corruption' is set to 'Disabled'.CompliantTrue
118(ND, NE) Ensure 'Toggle user control over Insider builds' is set to 'Disabled'.CompliantTrue
119(ND, NE) Ensure 'Do not show feedback notifications' is set to 'Enabled'.CompliantTrue
120(ND, NE) Ensure 'Allow Telemetry' is set to 'Enabled: 0 – Security [Enterprise Only]'.CompliantTrue
121(ND, NE) Ensure 'Allow device name to be sent in Windows diagnostic data' is set to 'Disabled'.Registry value not found.False
122(HD) Ensure 'Configure Authenticated Proxy usage for the Connected User Experience and Telemetry service' is set to 'Enabled: Disable Authenticated Proxy usage'. CompliantTrue
123(HD) Ensure 'Allow Use of Camera' is set to 'Disabled'.Registry value is '1'. Expected: 0False
124(ND, NE) Ensure 'Block all consumer Microsoft account user authentication' is set to 'Enabled'.CompliantTrue
125(HD) Ensure 'Allow Message Service Cloud Sync' is set to 'Disabled'.CompliantTrue
126(ND, NE) Ensure 'Prevent users from sharing files within their profile.' is set to 'Enabled'.Registry key not found.False
127(ND, NE) Ensure 'Prevent the usage of OneDrive for file storage' is set to 'Enabled'.Registry key not found.False
128(HD) Ensure 'Turn off location' is set to 'Enabled'.CompliantTrue
129(HD) Ensure 'Turn off Push To Install service' is set to 'Enabled'.CompliantTrue
130(HD) Ensure 'Do not allow COM port redirection' is set to 'Enabled'.CompliantTrue
131(ND, NE) Ensure 'Do not allow drive redirection' is set to 'Enabled'.CompliantTrue
132(HD) Ensure 'Do not allow LPT port redirection' is set to 'Enabled'.CompliantTrue
133(HD) Ensure 'Do not allow supported Plug and Play device redirection' is set to 'Enabled'. CompliantTrue
134(ND, NE) Ensure 'Always prompt for password upon connection' is set to 'Enabled'.CompliantTrue
135(ND, NE) Ensure 'Require user authentication for remote connections by using Network Level Authentication' is set to 'Enabled'. CompliantTrue
136(ND, NE) Ensure 'Require secure RPC communication' is set to 'Enabled'.CompliantTrue
137(ND, NE) Ensure 'Set client connection encryption level' is set to 'Enabled: High Level'.CompliantTrue
138(ND, NE) Ensure 'Require use of specific security layer for remote (RDP) connections' is set to 'Enabled: SSL'. CompliantTrue
139(ND, NE) Ensure 'End session when time limits are reached' is set to 'Enabled'.Registry key not found.False
140(HD) Ensure 'Set time limit for active but idle Remote Desktop Services sessions' is set to 'Enabled: 15 minutes or less'. CompliantTrue
141(HD) Ensure 'Set time limit for disconnected sessions' is set to 'Enabled: 1 minute'.CompliantTrue
142(ND, NE) Ensure 'Do not use temporary folders per session' is set to 'Disabled'.Registry value not found.False
143(ND, NE) Ensure 'Do not delete temp folders upon exit' is set to 'Disabled'. CompliantTrue
144(HD) Ensure 'Allow users to connect remotely by using Remote Desktop Services' is set to 'Disabled'. CompliantTrue
145(ND, NE) Ensure 'Do not allow passwords to be saved' is set to 'Enabled'.CompliantTrue
146(ND, NE) Ensure 'Disallow Autoplay for non-volume devices' is set to 'Enabled'CompliantTrue
147(ND, NE) Ensure 'Turn off Autoplay' is set to 'Enabled: All drives'.CompliantTrue
148(ND, NE) Ensure 'Set the default behavior for AutoRun' is set to 'Enabled: Do not execute any autorun commands'. CompliantTrue
149(ND, NE) Ensure 'Prevent downloading of enclosures' is set to 'Enabled'.CompliantTrue
150(HD) Ensure 'Turn off KMS Client Online AVS Validation' is set to 'Enabled'. CompliantTrue
151(HD) Ensure 'Disable all apps from Microsoft Store' is set to 'Disabled'.Registry value not found.False
152(ND, NE) Ensure 'Turn off Automatic Download and Install of updates' is set to 'Disabled'. CompliantTrue
153(ND, NE) Ensure 'Turn off the offer to update to the latest version of Windows' is set to 'Enabled'.CompliantTrue
154(HD) Ensure 'Only display the private store within the Microsoft Store' is set to 'Enabled'.CompliantTrue
155(HD) Ensure 'Turn off the Store application' is set to 'Enabled'.CompliantTrue
156(HD) Ensure 'Allow Cloud Search' is set to 'Enabled: Disable Cloud Search'.CompliantTrue
157(ND, NE) Ensure 'Allow search and Cortana to use location' is set to 'Disabled'.CompliantTrue
158(ND, NE) Ensure 'Allow indexing of encrypted files' is set to 'Disabled'.CompliantTrue
159(ND, NE) Ensure 'Improve inking and typing recognition' is set to 'Disabled'. Registry key not found.False
160(ND, NE) Ensure 'Download Mode' is set to 'Enabled: Simple (99)' .Registry value is '1'. Expected: 99False
161(ND, NE) Ensure 'Require pin for pairing' is set to 'Enabled: Always'. CompliantTrue
162(ND, NE) Ensure 'Configure detection for potentially unwanted applications' is set to 'Enabled: Block'.CompliantTrue
163(ND, NE) Ensure 'Turn off Windows Defender Antivirus' is set to 'Disabled'.CompliantTrue
164(ND, NE) Ensure 'Configure Watson events' is set to 'Disabled'.CompliantTrue
165(ND, NE) Ensure 'Turn on behavior monitoring' is set to 'Enabled'.CompliantTrue
166(HD) Ensure 'Join Microsoft MAPS' is set to 'Disabled'.CompliantTrue
167(ND, NE) Ensure 'Configure local setting override for reporting to Microsoft MAPS' is set to 'Disabled'.CompliantTrue
168(ND, NE) Ensure 'Turn on e-mail scanning' is set to 'Enabled'.CompliantTrue
169(ND, NE) Ensure 'Scan removable drives' is set to 'Enabled'.CompliantTrue
170(ND, NE) Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block'.CompliantTrue
171(ND, NE) Ensure 'Configure Attack Surface Reduction rules' is set to 'Enabled'.CompliantTrue
172_1(ND, NE) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured'.CompliantTrue
172_2(ND, NE) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured'.CompliantTrue
172_3(ND, NE) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured'.CompliantTrue
172_4(ND, NE) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured'.CompliantTrue
172_5(ND, NE) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured'.CompliantTrue
172_6(ND, NE) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured'.CompliantTrue
172_7(ND, NE) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured'.CompliantTrue
172_8(ND, NE) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured'.CompliantTrue
172_9(ND, NE) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured'.CompliantTrue
172_10(ND, NE) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured'.CompliantTrue
172_11(ND, NE) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured'.CompliantTrue
173(ND, NE) Ensure 'Configure Windows Defender SmartScreen' is set to 'Enabled: Warn and prevent bypass'. CompliantTrue
174(ND, NE) Ensure 'Prevent bypassing Windows Defender SmartScreen prompts for sites' is set to 'Enabled'.CompliantTrue
175(ND, NE) Ensure 'Configure Windows Defender SmartScreen' is set to 'Enabled'.CompliantTrue
176(HD) Ensure 'Allow suggested apps in Windows Ink Workspace' is set to 'Disabled'.CompliantTrue
177(ND, NE) Ensure 'Allow Windows Ink Workspace' is set to 'Enabled: On, but disallow access above lock' OR 'Disabled'.CompliantTrue
178(ND, NE) Ensure 'Allow user control over installs' is set to 'Disabled'.CompliantTrue
179(HD) Ensure 'Prevent Internet Explorer security prompt for Windows Installer scripts' is set to 'Disabled'.CompliantTrue
180(ND, NE) Ensure 'Always install with elevated privileges' is set to 'Disabled'.CompliantTrue
181(ND, NE) Ensure 'Always install with elevated privileges' is set to 'Disabled'.Registry key not found.False
182(HD) Ensure 'Prevent Codec Download' is set to 'Enabled'.Registry key not found.False
184(HD) Ensure 'Turn on Script Execution' is set to 'Enabled: Allow only signed scripts'. Registry key not found.False
185(ND, NE) Ensure 'Configure Automatic Updates' is set to 'Enabled: 4 Auto download and schedule the install'. CompliantTrue
186(ND, NE) Ensure 'Configure Automatic Updates: Scheduled install day' is set to '0 - Every day'. CompliantTrue
187(ND, NE) Ensure 'No auto-restart with logged on users for scheduled automatic updates installations' is set to 'Disabled'.CompliantTrue
188(ND, NE) Ensure 'Remove access to "Pause updates" feature' is set to 'Enabled'.CompliantTrue
189(ND, NE) Ensure 'Sign-in last interactive user automatically after a system-initiated restart' is set to 'Disabled'. CompliantTrue
190(HD) Ensure 'Allow Remote Shell Access' is set to 'Disabled'.Registry value is '1'. Expected: 0False
191(ND, NE) Ensure 'Allow Basic authentication' is set to 'Disabled'.CompliantTrue
192(ND, NE) Ensure 'Disallow Digest authentication' is set to 'Enabled'. CompliantTrue
193(ND, NE) Ensure 'Allow unencrypted traffic' is set to 'Disabled'. CompliantTrue
194(ND, NE) Ensure 'Allow Basic authentication' is set to 'Disabled'.CompliantTrue
195(HD) Ensure 'Allow remote server management through WinRM' is set to 'Disabled'.Registry value not found.False
196(ND, NE) Ensure 'Disallow WinRM from storing RunAs credentials' is set to 'Enabled'.CompliantTrue
197(ND, NE) Ensure 'Allow unencrypted traffic' is set to 'Disabled'. CompliantTrue
198(ND, NE) Ensure 'Prevent users from modifying settings' is set to 'Enabled'.CompliantTrue
199(ND, NE) Ensure 'Enables or disables Windows Game Recording and Broadcasting' is set to 'Disabled'.CompliantTrue
209(ND, NE) Configure 'Interactive logon: Message title for users attempting to log on'.CompliantTrue
210(ND, NE) Ensure 'User Account Control: Admin Approval Mode for the Built-in Administrator account' is set to 'Enabled'.CompliantTrue
211(ND, NE) Ensure 'User Account Control: Run all administrators in Admin Approval Mode' is set to 'Enabled'. CompliantTrue
212(ND, NE) Ensure 'User Account Control: Detect application installations and prompt for elevation' is set to 'Enabled'. CompliantTrue
213(ND, NE) Ensure 'User Account Control: Switch to the secure desktop when prompting for elevation' is set to 'Enabled'.CompliantTrue
214(ND, NE) Ensure 'User Account Control: Virtualize file and registry write failures to per-user locations' is set to 'Enabled'.CompliantTrue
215(ND, NE) Ensure 'User Account Control: Only elevate UIAccess applications that are installed in secure locations' is set to 'Enabled'. CompliantTrue
216(ND, NE) Ensure 'User Account Control: Allow UIAccess applications to prompt for elevation without using the secure desktop' is set to 'Disabled'.CompliantTrue
217(ND, NE) Ensure 'User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode' is set to 'Prompt for consent on the secure desktop'.CompliantTrue
218(ND, NE) Ensure 'User Account Control: Behavior of the elevation prompt for standard users' is set to 'Prompt for credentials on the secure desktop'.Registry value is '3'. Expected: 1False
219(ND) Ensure 'Domain member: Disable machine account password changes' is set to 'Disabled'.CompliantTrue
220(ND) Ensure 'Domain member: Digitally sign secure channel data (when possible)' is set to 'Enabled'.CompliantTrue
221(ND) Ensure 'Domain member: Digitally encrypt secure channel data (when possible)' is set to 'Enabled'. CompliantTrue
222(ND) Ensure 'Domain member: Digitally encrypt or sign secure channel data (always)' is set to 'Enabled'. CompliantTrue
223(ND) Ensure 'Domain member: Maximum machine account password age' is set to '30 or fewer days, but not 0'. CompliantTrue
224(ND) Ensure 'Domain member: Require strong (Windows 2000 or later) session key' is set to 'Enabled'.CompliantTrue
225(HD) Ensure 'Devices: Prevent users from installing printer drivers' is set to 'Enabled'.CompliantTrue
226(ND, NE) Ensure 'Devices: Allowed to format and eject removable media' is set to 'Administrators and Interactive Users'.CompliantTrue
227(ND, NE) Ensure 'Interactive logon: Prompt user to change password before expiration' is set to 'between 5 and 14 days'.CompliantTrue
228(HD) Ensure 'Interactive logon: Number of previous logons to cache (in case domain controller is not available)' is set to '4 or fewer logon(s)'.CompliantTrue
229 Ensure 'Interactive logon: Machine inactivity limit' is set to '900 or fewer second(s), but not 0'. CompliantTrue
230(ND, NE) Ensure 'Interactive logon: Do not require CTRL+ALT+DEL' is set to 'Disabled'.CompliantTrue
231(ND, NE) Configure 'Interactive logon: Message text for users attempting to log on'.CompliantTrue
232(ND) Ensure 'Interactive logon: Machine account lockout threshold' is set to '10 or fewer invalid logon attempts, but not 0'. CompliantTrue
233(ND) Ensure 'Interactive logon: Smart card removal behavior' is set to 'Lock Workstation' or higher.CompliantTrue
234(ND, NE) Ensure 'Interactive logon: Don't display last signed-in' is setto 'Enabled'.CompliantTrue
239(ND, NE) Ensure 'Accounts: Limit local account use of blank passwords to console logon only' is set to 'Enabled'. CompliantTrue
240(ND, NE) Ensure 'Accounts: Block Microsoft accounts' is set to 'Users can't add or log on with Microsoft accounts'.CompliantTrue
241(ND, NE) Ensure 'Microsoft network client: Digitally sign communications (always)' is set to 'Enabled'.Registry value is '0'. Expected: 1False
242(ND, NE) Ensure 'Microsoft network client: Digitally sign communications (if server agrees)' is set to 'Enabled'.CompliantTrue
243(ND, NE) Ensure 'Microsoft network client: Send unencrypted password to third-party SMB servers' is set to 'Disabled'.CompliantTrue
244(ND, NE) Ensure 'Microsoft network server: Disconnect clients when logon hours expire' is set to 'Enabled'.CompliantTrue
245(ND, NE) Ensure 'Microsoft network server: Digitally sign communications (always)' is set to 'Enabled'.Registry value is '0'. Expected: 1False
246(ND, NE) Ensure 'Microsoft network server: Digitally sign communications (if client agrees)' is set to 'Enabled'. Registry value is '0'. Expected: 1False
247(ND, NE) Ensure 'Microsoft network server: Amount of idle time required before suspending session' is set to '15 or fewer minute(s)'. CompliantTrue
248(ND) Ensure 'Microsoft network server: Server SPN target name validation level' is set to 'Accept if provided by client' or higher.CompliantTrue
250(HD) Ensure 'Network security: Restrict NTLM: Outgoing NTLM traffic to remote servers' is set to 'Deny all'.Registry value not found.False
251(HD) Ensure 'Network security: Restrict NTLM: Incoming NTLM traffic' is set to 'Deny all accounts'.Registry value not found.False
252(ND) Ensure 'Network security: Configure encryption types allowed for Kerberos' is set to 'AES128_HMAC_SHA1, AES256_HMAC_SHA1, Future encryption types'.CompliantTrue
253(ND, NE) Ensure 'Network security: Do not store LAN Manager hash value on next password change' is set to 'Enabled'.CompliantTrue
254(ND, NE) Ensure 'Network security: LAN Manager authentication level' is set to 'Send NTLMv2 response only'.CompliantTrue
255(ND, NE) Ensure 'Network Security: Allow PKU2U authentication requests to this computer to use online identities' is set to 'Disabled'.CompliantTrue
256(ND, NE) Ensure 'Network security: Allow Local System to use computer identity for NTLM' is set to 'Enabled'. CompliantTrue
257(ND) Ensure 'Network security: Minimum session security for NTLM SSP based (including secure RPC) clients' is set to 'Require NTLMv2 session security, Require 128-bit encryption'. CompliantTrue
258(ND) Ensure 'Network security: Minimum session security for NTLM SSP based (including secure RPC) servers' is set to 'Require NTLMv2 session security, Require 128-bit encryption'.CompliantTrue
259(ND) Ensure 'Network security: LDAP client signing requirements' is set to 'Negotiate signing' or higher.CompliantTrue
260(ND, NE) Ensure 'Network security: Allow LocalSystem NULL session fallback' is set to 'Disabled'.CompliantTrue
261(ND, NE) Ensure 'Network access: Do not allow anonymous enumeration of SAM accounts' is set to 'Enabled'.CompliantTrue
262(ND) Ensure 'Network access: Do not allow anonymous enumeration of SAM accounts and shares' is set to 'Enabled'.CompliantTrue
263(ND) Ensure 'Network access: Allow anonymous SID/Name translation' is set to 'Disabled'.Registry value not found.False
264(ND, NE) Ensure 'Network access: Restrict anonymous access to Named Pipes and Shares' is set to 'Enabled'.CompliantTrue
265(ND, NE) Ensure 'Network access: Restrict clients allowed to make remote calls to SAM' is set to 'Administrators: Remote Access: Allow'.CompliantTrue
266(ND) Ensure 'Network access: Let Everyone permissions apply to anonymous users' is set to 'Disabled'. CompliantTrue
267(ND, NE) Ensure 'Network access: Shares that can be accessed anonymously' is set to 'None'.CompliantTrue
268(ND, NE) Ensure 'Network access: Sharing and security model for local accounts' is set to 'Classic - local users authenticate as themselves'. CompliantTrue
269(ND, NE) Ensure 'Network access: Named Pipes that can be accessed anonymously' is set to 'None'. CompliantTrue
270(ND, NE) Configure 'Network access: Remotely accessible registry paths and sub-paths'.CompliantTrue
271(ND, NE) Configure 'Network access: Remotely accessible registry paths'.CompliantTrue
272(ND, NE) Ensure 'Network access: Do not allow storage of passwords and credentials for network authentication' is set to 'Enabled'. CompliantTrue
273(HD) Ensure 'System settings: Optional subsystems' is set to 'None'. Registry value is ''. Expected: False
274(HD) Ensure 'System cryptography: Force strong key protection for user keys stored on the computer' is set to 'User is prompted when the key is first used'.CompliantTrue
275(ND, NE) Ensure 'System objects: Require case insensitivity for non-Windows subsystems' is set to 'Enabled'. CompliantTrue
276(ND, NE) Ensure 'System objects: Strengthen default permissions of internal system objects (e.g. Symbolic Links)' is set to 'Enabled'.CompliantTrue
316(HD) Ensure 'Remote Desktop Services UserMode Port Redirector (UmRdpService)' is set to 'Disabled'.CompliantTrue
317(ND, NE) Ensure 'Connected User Experiences and Telemetry' is set to 'Disabled'.Registry value not found.False
318(HD) Ensure 'Bluetooth Audio Gateway Service (BTAGService)' is set to 'Disabled'.Registry value is '3'. Expected: 4False
319(HD) Ensure 'Bluetooth Support Service (bthserv)' is set to 'Disabled'.Registry value is '3'. Expected: 4False
320(ND, NE) Ensure 'Computer Browser (Browser)' is set to 'Disabled' or 'Not Installed'.CompliantTrue
321(NE, ND) Ensure 'Internet Connection Sharing (ICS) (SharedAccess)' is set to 'Disabled'.CompliantTrue
322(HD) Ensure 'Geolocation Service (lfsvc)' is set to 'Disabled'.CompliantTrue
323(ND, NE) Ensure 'IIS Admin Service (IISADMIN)' is set to 'Disabled' or 'Not Installed'.CompliantTrue
324(NE, ND) Ensure 'Infrared monitor service (irmon)' is set to 'Disabled'.CompliantTrue
325(HD) Ensure 'Remote Desktop Configuration (SessionEnv)' is set to 'Disabled'.CompliantTrue
326(ND, NE) Ensure 'LxssManager (LxssManager)' is set to 'Disabled' or 'Not Installed'.CompliantTrue
327(HD) Ensure 'Downloaded Maps Manager (MapsBroker)' is set to 'Disabled'.CompliantTrue
328(ND, NE) Ensure 'Microsoft FTP Service (FTPSVC)' is set to 'Disabled' or 'Not Installed'.CompliantTrue
329(HD) Ensure 'Microsoft iSCSI Initiator Service (MSiSCSI)' is set to 'Disabled'.CompliantTrue
330(HD) Ensure 'Microsoft Store Install Service (InstallService)' is set to 'Disabled'.Registry value is '3'. Expected: 4False
331(ND, NE) Ensure 'OpenSSH SSH Server (sshd)' is set to 'Disabled' or 'Not Installed'.CompliantTrue
332(HD) Ensure 'Peer Name Resolution Protocol (PNRPsvc)' is set to 'Disabled'.CompliantTrue
333(HD) Ensure 'Peer Networking Grouping (p2psvc)' is set to 'Disabled'.CompliantTrue
334(HD) Ensure 'Peer Networking Identity Manager (p2pimsvc)' is set to 'Disabled'.CompliantTrue
335(HD) Ensure 'PNRP Machine Name Publication Service (PNRPAutoReg)' is set to 'Disabled'. CompliantTrue
336(HD) Ensure 'Remote Desktop Services (TermService)' is set to 'Disabled'.CompliantTrue
337(HD) Ensure 'Remote Registry (RemoteRegistry)' is set to 'Disabled'.CompliantTrue
338(ND, NE) Ensure 'Routing and Remote Access (RemoteAccess)' is set to 'Disabled'.CompliantTrue
339(ND, NE) Ensure 'Remote Procedure Call (RPC) Locator (RpcLocator)' is set to 'Disabled'.CompliantTrue
340(HD) Ensure 'Server (LanmanServer)' is set to 'Disabled'.CompliantTrue
341(ND, NE) Ensure 'Simple TCP/IP Services (simptcp)' is set to 'Disabled' or 'Not Installed'.CompliantTrue
342(HD) Ensure 'SNMP Service (SNMP)' is set to 'Disabled' or 'Not Installed'.CompliantTrue
343(ND, NE) Ensure 'SSDP Discovery (SSDPSRV)' is set to 'Disabled'.CompliantTrue
344(HD) Ensure 'Problem Reports and Solutions Control Panel Support (wercplsupport)' is set to 'Disabled'.CompliantTrue
345(ND, NE) Ensure 'UPnP Device Host (upnphost)' is set to 'Disabled'. CompliantTrue
346(HD) Ensure 'Link-Layer Topology Discovery Mapper (lltdsvc)' is set to 'Disabled'.CompliantTrue
347(HD) Ensure 'Remote Access Auto Connection Manager (RasAuto)' is set to 'Disabled'.CompliantTrue
348(ND, NE) Ensure 'Web Management Service (WMSvc)' is set to 'Disabled' or 'Not Installed'.CompliantTrue
349(ND, NE) Ensure 'Windows Media Player Network Sharing Service (WMPNetworkSvc)' is set to 'Disabled'.CompliantTrue
350(HD) Ensure 'Windows PushToInstall Service (PushToInstall)' is set to 'Disabled'.CompliantTrue
351(HD) Ensure 'Windows Mobile Hotspot Service (icssvc)' is set to 'Disabled'. CompliantTrue
352(HD) Ensure 'Windows Event Collector (Wecsvc)' is set to 'Disabled'. CompliantTrue
353(HD) Ensure 'Windows Error Reporting Service (WerSvc)' is set to 'Disabled'.CompliantTrue
354(HD) Ensure 'Windows Push Notifications System Service (WpnService)' is set to 'Disabled'. CompliantTrue
355(HD) Ensure 'Windows Remote Management (WS-Management) (WinRM)' is set to 'Disabled'.Registry value is '2'. Expected: 4False
356(ND, NE) Ensure 'World Wide Web Publishing Service (W3SVC)' is set to 'Disabled' or 'Not Installed'.CompliantTrue
357(ND, NE) Ensure 'Xbox Accessory Management Service (XboxGipSvc)' is set to 'Disabled'.CompliantTrue
358(ND, NE) Ensure 'Xbox Live Auth Manager (XblAuthManager)' is set to 'Disabled'.CompliantTrue
359(ND, NE) Ensure 'Xbox Live Networking Service (XboxNetApiSvc)' is set to 'Disabled'.CompliantTrue
360(ND, NE) Ensure 'Xbox Live Game Save (XblGameSave)' is set to 'Disabled'.CompliantTrue
361(ND) Ensure 'Windows Firewall: Domain: Outbound connections' is set to 'Allow (default)'.CompliantTrue
362(ND) Ensure 'Windows Firewall: Domain: Settings: Display a notification' is set to 'No'.CompliantTrue
363(ND) Ensure 'Windows Firewall: Domain: Inbound connections' is set to 'Block (default)'.CompliantTrue
364(ND) Ensure 'Windows Firewall: Domain: Firewall state' is set to 'On (recommended)'.CompliantTrue
365(ND, NE) Ensure 'Windows Firewall: Public: Outbound connections' is set to 'Allow (default)' .CompliantTrue
366(ND, NE) Ensure 'Windows Firewall: Public: Settings: Display a notification' is set to 'No'.CompliantTrue
367(ND, NE) Ensure 'Windows Firewall: Public: Inbound connections' is set to 'Block (default)'.CompliantTrue
368(ND, NE) Ensure 'Windows Firewall: Public: Firewall state' is set to 'On (recommended)'.CompliantTrue
369(ND, NE) Ensure 'Windows Firewall: Public: Settings: Apply local firewall rules' is set to 'No'.CompliantTrue
370(ND, NE) Ensure 'Windows Firewall: Public: Settings: Apply local connection security rules' is set to 'No'.CompliantTrue
371(ND, NE) Ensure 'Windows Firewall: Private: Outbound connections' is set to 'Allow (default)'.CompliantTrue
372(ND, NE) Ensure 'Windows Firewall: Private: Settings: Display a notification' is set to 'No'.CompliantTrue
373(ND, NE) Ensure 'Windows Firewall: Private: Inbound connections' is set to 'Block (default)'.CompliantTrue
374(ND, NE) Ensure 'Windows Firewall: Private: Firewall state' is set to 'On (recommended)'.CompliantTrue

User Rights Assignment-

IdTaskMessageStatus
277(ND, NE) Ensure 'Change the system time' is set to 'Administrators, LOCAL SERVICE'.CompliantTrue
278(ND, NE) Ensure 'Change the time zone' is set to 'Administrators, LOCAL SERVICE, Users'.CompliantTrue
279(ND, NE) Ensure 'Increase scheduling priority' is set to 'Administrators, Window Manager\Window Manager Group'. CompliantTrue
280(ND, NE) Ensure 'Deny log on as a batch job' to include 'ANONYMOUS LOGON, Guests'.The user 'SeDenyBatchLogonRight' setting does not contain the following users: NT AUTHORITY\ANONYMOUS LOGONFalse
281(HD) Configure 'Log on as a service'.The user right 'SeServiceLogonRight' contains following unexpected users: DESKTOP-UTMU75K\SQLServer2005SQLBrowserUser$DESKTOP-UTMU75K, NT SERVICE\ALL SERVICES, NT SERVICE\SQLTELEMETRY, NT SERVICE\SQLSERVERAGENT, NT SERVICE\MSSQLSERVER, NT VIRTUAL MACHINE\Virtual MachinesFalse
282(ND, NE) Ensure 'Deny log on as a service' to include 'ANONYMOUS LOGON, Guests'.The user 'SeDenyServiceLogonRight' setting does not contain the following users: NT AUTHORITY\ANONYMOUS LOGONFalse
283(HD) Ensure 'Log on as a batch job' is set to 'Administrators'.The user right 'SeBatchLogonRight' contains following unexpected users: BUILTIN\Backup Operators, BUILTIN\Performance Log UsersFalse
284(ND) Ensure 'Deny log on through Remote Desktop Services' to include 'ANONYMOUS LOGON, Guests, Local account'.The user right 'SeDenyRemoteInteractiveLogonRight' contains following unexpected users: NT AUTHORITY\Local account The user 'SeDenyRemoteInteractiveLogonRight' setting does not contain the following users: NT AUTHORITY\ANONYMOUS LOGON, LOCALFalse
285(ND, NE) Ensure 'Allow log on through Remote Desktop Services' is set to 'Administrators, Remote Desktop Users'. CompliantTrue
286(ND, NE) Ensure 'Impersonate a client after authentication' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE'. CompliantTrue
287(ND, NE) Ensure 'Adjust memory quotas for a process' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE'. The user right 'SeIncreaseQuotaPrivilege' contains following unexpected users: NT SERVICE\SQLSERVERAGENT, NT SERVICE\MSSQLSERVERFalse
288(ND, NE) Ensure 'Access Credential Manager as a trusted caller' is set to 'No One'.CompliantTrue
289(ND, NE) Ensure 'Access this computer from the network' is set to 'Administrators, Remote Desktop Users'. The user right 'SeNetworkLogonRight' contains following unexpected users: BUILTIN\Users, BUILTIN\Backup Operators The user 'SeNetworkLogonRight' setting does not contain the following users: BUILTIN\Remote Desktop UsersFalse
290(ND, NE) Ensure 'Debug programs' is set to 'Administrators'.CompliantTrue
291(ND, NE) Ensure 'Perform volume maintenance tasks' is set to 'Administrators'.CompliantTrue
292(ND, NE) Ensure 'Act as part of the operating system' is set to 'No One'.CompliantTrue
293(ND) Ensure 'Enable computer and user accounts to be trusted for delegation' is set to 'No One'.CompliantTrue
294(ND, NE) Ensure 'Replace a process level token' is set to 'LOCAL SERVICE, NETWORK SERVICE'.The user right 'SeAssignPrimaryTokenPrivilege' contains following unexpected users: NT SERVICE\SQLSERVERAGENT, NT SERVICE\MSSQLSERVERFalse
295(ND, NE) Ensure 'Create a pagefile' is set to 'Administrators'.CompliantTrue
296(ND, NE) Ensure 'Profile system performance' is set to 'Administrators, NT SERVICE\WdiServiceHost'. CompliantTrue
297(ND, NE) Ensure 'Profile single process' is set to 'Administrators'.CompliantTrue
298(ND, NE) Ensure 'Create a token object' is set to 'No One'.CompliantTrue
299(ND, NE) Ensure 'Create global objects' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE'.CompliantTrue
300(ND, NE) Ensure 'Create symbolic links' is set to 'Administrators'.The user right 'SeCreateSymbolicLinkPrivilege' contains following unexpected users: NT VIRTUAL MACHINE\Virtual MachinesFalse
301(ND, NE) Ensure 'Create permanent shared objects' is set to 'No One'. CompliantTrue
302(ND, NE) Ensure 'Force shutdown from a remote system' is set to 'Administrators'.CompliantTrue
303(ND, NE) Ensure 'Generate security audits' is set to 'LOCAL SERVICE, NETWORK SERVICE'.CompliantTrue
304(ND, NE) Ensure 'Shut down the system' is set to 'Administrators, Users'.The user right 'SeShutdownPrivilege' contains following unexpected users: BUILTIN\Backup OperatorsFalse
305(ND, NE) Ensure 'Load and unload device drivers' is set to 'Administrators'.CompliantTrue
306(ND, NE) Ensure 'Deny log on locally' to include 'ANONYMOUS LOGON, Guests'. The user 'SeDenyInteractiveLogonRight' setting does not contain the following users: NT AUTHORITY\ANONYMOUS LOGONFalse
307(ND, NE) Ensure 'Allow log on locally' is set to 'Administrators, Users'. The user right 'SeInteractiveLogonRight' contains following unexpected users: DESKTOP-UTMU75K\OldGuest, BUILTIN\Backup OperatorsFalse
308(ND, NE) Ensure 'Back up files and directories' is set to 'Administrators'.The user right 'SeBackupPrivilege' contains following unexpected users: BUILTIN\Backup OperatorsFalse
309(ND, NE) Ensure 'Lock pages in memory' is set to 'No One'.CompliantTrue
310(ND, NE) Ensure 'Take ownership of files or other objects' is set to 'Administrators' .CompliantTrue
311(ND, NE) Ensure 'Modify firmware environment values' is set to 'Administrators'. CompliantTrue
312(ND, NE) Ensure 'Modify an object label' is set to 'No One'.CompliantTrue
313(ND, NE) Ensure 'Manage auditing and security log' is set to 'Administrators'.CompliantTrue
314(ND, NE) Ensure 'Restore files and directories' is set to 'Administrators'. The user right 'SeRestorePrivilege' contains following unexpected users: BUILTIN\Backup OperatorsFalse
315(ND, NE) Ensure 'Deny access to this computer from the network' to include 'ANONYMOUS LOGON, Guest, Local account'. The user 'SeDenyNetworkLogonRight' setting does not contain the following users: NT AUTHORITY\ANONYMOUS LOGONFalse

Account Policies-

IdTaskMessageStatus
200(ND, NE) Ensure 'Store passwords using reversible encryption' is set to 'Disabled'.CompliantTrue
201(ND, NE) Ensure 'Password must meet complexity requirements' is set to 'Enabled'.CompliantTrue
202(ND, NE) Ensure 'Enforce password history' is set to '24 or more password(s)'.CompliantTrue
203(ND, NE) Ensure 'Maximum password age' is set to '365 or fewer days, but not 0'.CompliantTrue
204(ND, NE) Ensure 'Minimum password length' is set to '14 or more character(s)'.CompliantTrue
205(ND, NE) Ensure 'Minimum password age' is set to '1 or more day(s)' .CompliantTrue
206(ND) Ensure 'Account lockout duration' is set to '15 or more minute(s)'.CompliantTrue
207(ND) Ensure 'Account lockout threshold' is set to '10 or fewer invalid logon attempt(s), but not 0'.CompliantTrue
208(ND) Ensure 'Reset account lockout counter after' is set to '15 or more minute(s)'. CompliantTrue

BSI Benchmarks SiSyPHuS ND-

This section contains the BSI Benchmark results.

Registry Settings/Group Policies-

IdTaskMessageStatus
1(ND, NE) Ensure 'Apply UAC restrictions to local accounts on network logons' is set to 'Enabled'. CompliantTrue
2(ND, NE) Ensure 'Configure SMB v1 client driver' is set to 'Enabled: Disable driver.CompliantTrue
3(ND, NE) Ensure 'Configure SMB v1 server' is set to 'Disabled'.CompliantTrue
4(ND, NE) Ensure 'Enable Structured Exception Handling OverwriteProtection (SEHOP)' is set to 'Enabled'.CompliantTrue
5(ND, NE) Ensure 'WDigest Authentication' is set to 'Disabled'.CompliantTrue
6(ND, NE) Ensure 'LSA Protection' is set to 'Enabled'.Registry value not found.False
7(ND, NE) Ensure 'MSS: (EnableDeadGWDetect) Allow automatic detection of dead network gateways (could lead to DoS)' is set to 'Disabled'.Registry value not found.False
8(ND, NE) Ensure 'MSS: (AutoAdminLogon) Enable Automatic Logon(not recommended)' is set to 'Disabled'.CompliantTrue
9(ND, NE) Ensure 'MSS: (DisableIPSourceRouting IPv6) IP source routingprotection level (protects against packet spoofing)' is set to 'Enabled:Highest protection, source routing is completely disabled'.CompliantTrue
10(ND, NE) Ensure 'MSS: (DisableIPSourceRouting IPv6) IP source routingprotection level (protects against packet spoofing)' is set to 'Enabled:Highest protection, source routing is completely disabled'.CompliantTrue
12(ND, NE) Ensure 'MSS: (EnableICMPRedirect) Allow ICMP redirects tooverride OSPF generated routes' is set to 'Disabled'.CompliantTrue
14(ND, NE) Ensure 'MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers' is set to 'Enabled'.CompliantTrue
16(ND, NE) Ensure 'MSS: (SafeDllSearchMode) Enable Safe DLL search mode (recommended)' is set to 'Enabled'.CompliantTrue
17(ND, NE) Ensure 'MSS: (ScreenSaverGracePeriod) The time in seconds before the screen saver grace period expires (0 recommended)' is set to 'Enabled: 5 or fewer seconds'.CompliantTrue
20(ND, NE) Ensure 'Turn off multicast name resolution' is set to 'Enabled'.CompliantTrue
21(ND, NE) Ensure 'NetBIOS node type' is set to 'P-node'.CompliantTrue
22(ND, NE) Ensure 'Enable insecure guest logons' is set to 'Disabled'.CompliantTrue
24_1(ND, NE) Ensure 'Hardened UNC Paths' is set to "Require Mutual Authentication=1, "Require Integrity=1" for the value names "\\*\NETLOGON" und "\\*\SYSVOL".CompliantTrue
24_2(ND, NE) Ensure 'Hardened UNC Paths' is set to "Require Mutual Authentication=1, "Require Integrity=1" for the value names "\\*\NETLOGON" und "\\*\SYSVOL".CompliantTrue
25(ND) Ensure 'Require domain users to elevate when setting a network's location' is set to 'Enabled'.CompliantTrue
26(ND) Ensure 'Prohibit installation and configuration of Network Bridge on your DNS domain network' is set to 'Enabled'. CompliantTrue
27(ND) Ensure 'Prohibit use of Internet Connection Sharing on your DNS domain network' is set to 'Enabled'.CompliantTrue
33(ND, NE) Ensure 'Minimize the number of simultaneous connections to the Internet or a Windows Domain' is set to the value 'Enabled: 1 = Minimize the number of simultaneous connections'.Registry value not found.False
34(ND) Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled' CompliantTrue
35(ND, NE) Ensure 'Allow Windows to automatically connect to suggested open hotspots, to networks shared by contacts, and to hotspots offering paid services' is set to 'Disabled'.CompliantTrue
37(ND, NE) Ensure 'Turn off toast notifications on the lock screen' is set to 'Enabled'. Registry value not found.False
39(ND, NE) Ensure 'Turn off picture password sign-in' is set to 'Enabled'. CompliantTrue
40(ND, NE) Ensure 'Turn off app notifications on the lock screen' is set to 'Enabled'. CompliantTrue
41(ND, NE) Ensure 'Block user from showing account details on signin' is set to 'Enabled'.CompliantTrue
42(ND) Ensure 'Turn on convenience PIN sign-in' is set to 'Disabled'.CompliantTrue
43(ND) Ensure 'Enumerate local users on domain-joined computers' is set to 'Disabled'.CompliantTrue
44(ND, NE) Ensure 'Do not display network selection UI' is set to 'Enabled'.CompliantTrue
45(ND) Ensure 'Do not enumerate connected users on domain-joined computers' is set to 'Enabled'.CompliantTrue
46(ND, NE) Ensure 'Boot-Start Driver Initialization Policy' is set to 'Enabled: Good, unknown and bad but critical'.CompliantTrue
50(ND, NE) Ensure 'Encryption Oracle Remediation' is set to 'Enabled: Force Updated Clients'.CompliantTrue
51(ND) Ensure 'Remote host allows delegation of non-exportable credentials' is set to 'Enabled'.CompliantTrue
52(ND, NE) Ensure 'Require a password when a computer wakes (on battery)' is set to 'Enabled' .CompliantTrue
53(ND, NE) Ensure 'Require a password when a computer wakes (plugged in)' is set to 'Enabled'.CompliantTrue
54(ND, NE) Ensure 'Allow network connectivity during connected-standby (on battery)' is set to 'Disabled'.CompliantTrue
55(ND, NE) Ensure 'Allow network connectivity during connected-standby (plugged in)' is set to 'Disabled'.CompliantTrue
56(ND, NE) Ensure 'Allow standby states (S1-S3) when sleeping (on battery)' is set to 'Disabled'.CompliantTrue
57(ND, NE) Ensure 'Allow standby states (S1-S3) when sleeping (plugged in)' is set to 'Disabled'.CompliantTrue
59(ND, NE) Ensure 'Prevent installation of devices that match any of these device IDs' is configured.Registry value not found.False
60(ND, NE) Ensure 'Prevent installation of devices using drivers that match these device setup classes' is configured.CompliantTrue
61(ND, NE) Ensure 'Continue experiences on this device' is set to 'Disabled'.CompliantTrue
62(ND) Ensure 'Turn off background refresh of Group Policy' is set to 'Disabled'.CompliantTrue
63(ND) Ensure 'Configure registry policy processing: Process even if the Group Policy objects have not changed' is set to 'Enabled: TRUE'. CompliantTrue
64(ND) Ensure 'Configure registry policy processing: Do not apply during periodic background processing' is set to 'Enabled: FALSE'.CompliantTrue
65(ND) Ensure 'Configure security policy processing: Process even if the Group Policy objects have not changed' is set to 'Enabled'.Registry key not found.False
68(ND, NE) Ensure 'Turn off downloading of print drivers over HTTP' is set to 'Enabled'.CompliantTrue
74(ND, NE) Ensure 'Turn off Internet download for Web publishing and online ordering wizards' is set to 'Enabled'.CompliantTrue
81(ND, NE) Ensure 'Enumeration policy for external devices incompatible with Kernel DMA Protection' is set to 'Enabled: Block All'.CompliantTrue
84(ND, NE) Ensure 'Restrict Unauthenticated RPC clients' is set to 'Enabled: Authenticated' .CompliantTrue
85(ND, NE) Ensure 'Enable RPC Endpoint Mapper Client Authentication' is set to 'Enabled'. CompliantTrue
86(ND, NE) Ensure 'Configure Solicited Remote Assistance' is set to 'Disabled'.CompliantTrue
87(ND, NE) Ensure 'Configure Offer Remote Assistance' is set to 'Disabled'.CompliantTrue
88(ND, NE) Ensure 'Ignore the default list of blocked TPM commands' is set to 'Disabled'.Registry key not found.False
89(ND, NE) Ensure 'Standard User Lockout Duration' is set to '30 minutes'.Registry value not found.False
90(ND, NE) Ensure 'Standard User Total Lockout Threshold' is set to '5'.Registry value not found.False
94(ND, NE) Ensure 'Prevent enabling lock screen slide show' is set to 'Enabled'.CompliantTrue
95(ND, NE) Ensure 'Prevent enabling lock screen camera' is set to 'Enabled'.CompliantTrue
96(ND, NE) Ensure 'Force specific screen saver: Screen saver executable name' is set to 'Enabled: scrnsave.scr'.Registry key not found.False
97(ND, NE) Ensure 'Enable screen saver' is set to 'Enabled'.Registry key not found.False
98(ND, NE) Ensure 'Password protect the screen saver' is set to 'Enabled'.Registry key not found.False
99(ND, NE) Ensure 'Screen saver timeout' is set to 'Enabled: 900 seconds or fewer, but not 0'.Registry key not found.False
100_1(ND, NE) Ensure 'Turn off automatic learning' is set to 'Enabled'.Registry value not found.False
100_2(ND, NE) Ensure 'Turn off automatic learning' is set to 'Enabled'.Registry value not found.False
101(ND, NE) Ensure 'Allow users to enable online speech recognition services' is set to 'Disabled'.CompliantTrue
102(ND, NE) Ensure 'Notify antivirus programs when opening attachments' is set to 'Enabled'. Registry key not found.False
103(ND, NE) Ensure 'Do not preserve zone information in file attachments' is set to 'Disabled'.Registry key not found.False
105(ND) Ensure 'Allow Microsoft accounts to be optional' is set to 'Enabled'.CompliantTrue
106(ND, NE) Ensure 'Enumerate administrator accounts on elevation' is set to 'Disabled'.CompliantTrue
107(ND, NE) Ensure 'Do not display the password reveal button' is set to 'Enabled'.CompliantTrue
109(ND, NE) Ensure 'Configure enhanced anti-spoofing' is set to 'Enabled'.CompliantTrue
112(ND, NE) Ensure 'Do not suggest third-party content in Windows spotlight' is set to 'Enabled'.Registry value not found.False
113(ND, NE) Ensure 'Turn off Microsoft consumer experiences' is set to 'Enabled'.CompliantTrue
114(ND, NE) Ensure 'Configure Windows spotlight on lock screen' is set to Disabled'.Registry value not found.False
115(ND, NE) Ensure 'Turn off Data Execution Prevention for Explorer' is set to 'Disabled'.CompliantTrue
116(ND, NE) Ensure 'Turn off shell protocol protected mode' is set to 'Disabled'.CompliantTrue
117(ND, NE) Ensure 'Turn off heap termination on corruption' is set to 'Disabled'.CompliantTrue
118(ND, NE) Ensure 'Toggle user control over Insider builds' is set to 'Disabled'.CompliantTrue
119(ND, NE) Ensure 'Do not show feedback notifications' is set to 'Enabled'.CompliantTrue
120(ND, NE) Ensure 'Allow Telemetry' is set to 'Enabled: 0 – Security [Enterprise Only]'.CompliantTrue
121(ND, NE) Ensure 'Allow device name to be sent in Windows diagnostic data' is set to 'Disabled'.Registry value not found.False
124(ND, NE) Ensure 'Block all consumer Microsoft account user authentication' is set to 'Enabled'.CompliantTrue
126(ND, NE) Ensure 'Prevent users from sharing files within their profile.' is set to 'Enabled'.Registry key not found.False
127(ND, NE) Ensure 'Prevent the usage of OneDrive for file storage' is set to 'Enabled'.Registry key not found.False
131(ND, NE) Ensure 'Do not allow drive redirection' is set to 'Enabled'.CompliantTrue
134(ND, NE) Ensure 'Always prompt for password upon connection' is set to 'Enabled'.CompliantTrue
135(ND, NE) Ensure 'Require user authentication for remote connections by using Network Level Authentication' is set to 'Enabled'. CompliantTrue
136(ND, NE) Ensure 'Require secure RPC communication' is set to 'Enabled'.CompliantTrue
137(ND, NE) Ensure 'Set client connection encryption level' is set to 'Enabled: High Level'.CompliantTrue
138(ND, NE) Ensure 'Require use of specific security layer for remote (RDP) connections' is set to 'Enabled: SSL'. CompliantTrue
139(ND, NE) Ensure 'End session when time limits are reached' is set to 'Enabled'.Registry key not found.False
142(ND, NE) Ensure 'Do not use temporary folders per session' is set to 'Disabled'.Registry value not found.False
143(ND, NE) Ensure 'Do not delete temp folders upon exit' is set to 'Disabled'. CompliantTrue
145(ND, NE) Ensure 'Do not allow passwords to be saved' is set to 'Enabled'.CompliantTrue
146(ND, NE) Ensure 'Disallow Autoplay for non-volume devices' is set to'Enabled'.CompliantTrue
147(ND, NE) Ensure 'Turn off Autoplay' is set to 'Enabled: All drives'.CompliantTrue
148(ND, NE) Ensure 'Set the default behavior for AutoRun' is set to 'Enabled: Do not execute any autorun commands'. CompliantTrue
149(ND, NE) Ensure 'Prevent downloading of enclosures' is set to 'Enabled'.CompliantTrue
152(ND, NE) Ensure 'Turn off Automatic Download and Install of updates' is set to 'Disabled'. CompliantTrue
153(ND, NE) Ensure 'Turn off the offer to update to the latest version of Windows' is set to 'Enabled'.CompliantTrue
157(ND, NE) Ensure 'Allow search and Cortana to use location' is set to 'Disabled'.CompliantTrue
158(ND, NE) Ensure 'Allow indexing of encrypted files' is set to 'Disabled'.CompliantTrue
159(ND, NE) Ensure 'Improve inking and typing recognition' is set to 'Disabled'. Registry key not found.False
160(ND, NE) Ensure 'Download Mode' is set to 'Enabled: Simple (99)' .Registry value is '1'. Expected: 99False
161(ND, NE) Ensure 'Require pin for pairing' is set to 'Enabled: Always'. CompliantTrue
162(ND, NE) Ensure 'Configure detection for potentially unwanted applications' is set to 'Enabled: Block'.CompliantTrue
163(ND, NE) Ensure 'Turn off Windows Defender Antivirus' is set to 'Disabled'.CompliantTrue
164(ND, NE) Ensure 'Configure Watson events' is set to 'Disabled'.CompliantTrue
165(ND, NE) Ensure 'Turn on behavior monitoring' is set to 'Enabled'.CompliantTrue
167(ND, NE) Ensure 'Configure local setting override for reporting to Microsoft MAPS' is set to 'Disabled'.CompliantTrue
168(ND, NE) Ensure 'Turn on e-mail scanning' is set to 'Enabled'.CompliantTrue
169(ND, NE) Ensure 'Scan removable drives' is set to 'Enabled'.CompliantTrue
170(ND, NE) Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block'.CompliantTrue
171(ND, NE) Ensure 'Configure Attack Surface Reduction rules' is set to 'Enabled'.CompliantTrue
172_1(ND, NE) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured'.CompliantTrue
172_2(ND, NE) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured'.CompliantTrue
172_3(ND, NE) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured'.CompliantTrue
172_4(ND, NE) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured'.CompliantTrue
172_5(ND, NE) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured'.CompliantTrue
172_6(ND, NE) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured'.CompliantTrue
172_7(ND, NE) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured'.CompliantTrue
172_8(ND, NE) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured'.CompliantTrue
172_9(ND, NE) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured'.CompliantTrue
172_10(ND, NE) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured'.CompliantTrue
172_11(ND, NE) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured'.CompliantTrue
173(ND, NE) Ensure 'Configure Windows Defender SmartScreen' is set to 'Enabled: Warn and prevent bypass'. CompliantTrue
174(ND, NE) Ensure 'Prevent bypassing Windows Defender SmartScreen prompts for sites' is set to 'Enabled'.CompliantTrue
175(ND, NE) Ensure 'Configure Windows Defender SmartScreen' is set to 'Enabled'.CompliantTrue
177(ND, NE) Ensure 'Allow Windows Ink Workspace' is set to 'Enabled: On, but disallow access above lock' OR 'Disabled'.CompliantTrue
178(ND, NE) Ensure 'Allow user control over installs' is set to 'Disabled'.CompliantTrue
180(ND, NE) Ensure 'Always install with elevated privileges' is set to 'Disabled'.CompliantTrue
181(ND, NE) Ensure 'Always install with elevated privileges' is set to 'Disabled'.Registry key not found.False
183(ND, NE) Ensure 'Turn on Script Execution' is set to 'Enabled: Allow local scripts and remote signed scripts'.Registry key not found.False
185(ND, NE) Ensure 'Configure Automatic Updates' is set to 'Enabled: 4 Auto download and schedule the install'. CompliantTrue
186(ND, NE) Ensure 'Configure Automatic Updates: Scheduled install day' is set to '0 - Every day'. CompliantTrue
187(ND, NE) Ensure 'No auto-restart with logged on users for scheduled automatic updates installations' is set to 'Disabled'.CompliantTrue
188(ND, NE) Ensure 'Remove access to "Pause updates" feature' is set to 'Enabled'.CompliantTrue
189(ND, NE) Ensure 'Sign-in last interactive user automatically after a system-initiated restart' is set to 'Disabled'. CompliantTrue
191(ND, NE) Ensure 'Allow Basic authentication' is set to 'Disabled'.CompliantTrue
192(ND, NE) Ensure 'Disallow Digest authentication' is set to 'Enabled'. CompliantTrue
193(ND, NE) Ensure 'Allow unencrypted traffic' is set to 'Disabled'. CompliantTrue
194(ND, NE) Ensure 'Allow Basic authentication' is set to 'Disabled'.CompliantTrue
196(ND, NE) Ensure 'Disallow WinRM from storing RunAs credentials' is set to 'Enabled'.CompliantTrue
197(ND, NE) Ensure 'Allow unencrypted traffic' is set to 'Disabled'. CompliantTrue
198(ND, NE) Ensure 'Prevent users from modifying settings' is set to 'Enabled'.CompliantTrue
199(ND, NE) Ensure 'Enables or disables Windows Game Recording and Broadcasting' is set to 'Disabled'.CompliantTrue
209(ND, NE) Configure 'Interactive logon: Message title for users attempting to log on'.CompliantTrue
210(ND, NE) Ensure 'User Account Control: Admin Approval Mode for the Built-in Administrator account' is set to 'Enabled'.CompliantTrue
211(ND, NE) Ensure 'User Account Control: Run all administrators in Admin Approval Mode' is set to 'Enabled'. CompliantTrue
212(ND, NE) Ensure 'User Account Control: Detect application installations and prompt for elevation' is set to 'Enabled'. CompliantTrue
213(ND, NE) Ensure 'User Account Control: Switch to the secure desktop when prompting for elevation' is set to 'Enabled'.CompliantTrue
214(ND, NE) Ensure 'User Account Control: Virtualize file and registry write failures to per-user locations' is set to 'Enabled'.CompliantTrue
215(ND, NE) Ensure 'User Account Control: Only elevate UIAccess applications that are installed in secure locations' is set to 'Enabled'. CompliantTrue
216(ND, NE) Ensure 'User Account Control: Allow UIAccess applications to prompt for elevation without using the secure desktop' is set to 'Disabled'.CompliantTrue
217(ND, NE) Ensure 'User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode' is set to 'Prompt for consent on the secure desktop'.CompliantTrue
218(ND, NE) Ensure 'User Account Control: Behavior of the elevation prompt for standard users' is set to 'Prompt for credentials on the secure desktop'.Registry value is '3'. Expected: 1False
219(ND) Ensure 'Domain member: Disable machine account password changes' is set to 'Disabled'.CompliantTrue
220(ND) Ensure 'Domain member: Digitally sign secure channel data(when possible)' is set to 'Enabled'.CompliantTrue
221(ND) Ensure 'Domain member: Digitally encrypt secure channel data (when possible)' is set to 'Enabled'. CompliantTrue
222(ND) Ensure 'Domain member: Digitally encrypt or sign secure channel data (always)' is set to 'Enabled'. CompliantTrue
223(ND) Ensure 'Domain member: Maximum machine account password age' is set to '30 or fewer days, but not 0'. CompliantTrue
224(ND) Ensure 'Domain member: Require strong (Windows 2000 or later) session key' is set to 'Enabled'.CompliantTrue
226(ND, NE) Ensure 'Devices: Allowed to format and eject removable media' is set to 'Administrators and Interactive Users'.CompliantTrue
227(ND, NE) Ensure 'Interactive logon: Prompt user to change password before expiration' is set to 'between 5 and 14 days'.CompliantTrue
229 Ensure 'Interactive logon: Machine inactivity limit' is set to '900 or fewer second(s), but not 0'. CompliantTrue
230(ND, NE) Ensure 'Interactive logon: Do not require CTRL+ALT+DEL' is set to 'Disabled'.CompliantTrue
231(ND, NE) Configure 'Interactive logon: Message text for users attempting to log on'.CompliantTrue
232(ND) Ensure 'Interactive logon: Machine account lockout threshold' is set to '10 or fewer invalid logon attempts, but not 0'. CompliantTrue
233(ND) Ensure 'Interactive logon: Smart card removal behavior' is set to 'Lock Workstation' or higher.CompliantTrue
234(ND, NE) Ensure 'Interactive logon: Don't display last signed-in' is setto 'Enabled'.CompliantTrue
239(ND, NE) Ensure 'Accounts: Limit local account use of blank passwords to console logon only' is set to 'Enabled'. CompliantTrue
240(ND, NE) Ensure 'Accounts: Block Microsoft accounts' is set to 'Users can't add or log on with Microsoft accounts'.CompliantTrue
241(ND, NE) Ensure 'Microsoft network client: Digitally sign communications (always)' is set to 'Enabled'.Registry value is '0'. Expected: 1False
242(ND, NE) Ensure 'Microsoft network client: Digitally sign communications (if server agrees)' is set to 'Enabled'.CompliantTrue
243(ND, NE) Ensure 'Microsoft network client: Send unencrypted password to third-party SMB servers' is set to 'Disabled'.CompliantTrue
244(ND, NE) Ensure 'Microsoft network server: Disconnect clients when logon hours expire' is set to 'Enabled'.CompliantTrue
245(ND, NE) Ensure 'Microsoft network server: Digitally sign communications (always)' is set to 'Enabled'.Registry value is '0'. Expected: 1False
246(ND, NE) Ensure 'Microsoft network server: Digitally sign communications (if client agrees)' is set to 'Enabled'. Registry value is '0'. Expected: 1False
247(ND, NE) Ensure 'Microsoft network server: Amount of idle time required before suspending session' is set to '15 or fewer minute(s)'. CompliantTrue
248(ND) Ensure 'Microsoft network server: Server SPN target name validation level' is set to 'Accept if provided by client' or higher.CompliantTrue
252(ND) Ensure 'Network security: Configure encryption types allowed for Kerberos' is set to 'AES128_HMAC_SHA1, AES256_HMAC_SHA1, Future encryption types'.CompliantTrue
253(ND, NE) Ensure 'Network security: Do not store LAN Manager hash value on next password change' is set to 'Enabled'.CompliantTrue
254(ND, NE) Ensure 'Network security: LAN Manager authentication level' is set to 'Send NTLMv2 response only'.CompliantTrue
255(ND, NE) Ensure 'Network Security: Allow PKU2U authentication requests to this computer to use online identities' is set to 'Disabled'.CompliantTrue
256(ND, NE) Ensure 'Network security: Allow Local System to use computer identity for NTLM' is set to 'Enabled'. CompliantTrue
257(ND) Ensure 'Network security: Minimum session security for NTLM SSP based (including secure RPC) clients' is set to 'Require NTLMv2 session security, Require 128-bit encryption'. CompliantTrue
258(ND) Ensure 'Network security: Minimum session security for NTLM SSP based (including secure RPC) servers' is set to 'Require NTLMv2 session security, Require 128-bit encryption'.CompliantTrue
259(ND) Ensure 'Network security: LDAP client signing requirements' is set to 'Negotiate signing' or higher.CompliantTrue
260(ND, NE) Ensure 'Network security: Allow LocalSystem NULL session fallback' is set to 'Disabled'.CompliantTrue
261(ND, NE) Ensure 'Network access: Do not allow anonymous enumeration of SAM accounts' is set to 'Enabled'.CompliantTrue
262(ND) Ensure 'Network access: Do not allow anonymous enumeration of SAM accounts and shares' is set to 'Enabled'.CompliantTrue
263(ND) Ensure 'Network access: Allow anonymous SID/Name translation' is set to 'Disabled'.Registry value not found.False
264(ND, NE) Ensure 'Network access: Restrict anonymous access to Named Pipes and Shares' is set to 'Enabled'.CompliantTrue
265(ND, NE) Ensure 'Network access: Restrict clients allowed to make remote calls to SAM' is set to 'Administrators: Remote Access: Allow'.CompliantTrue
266(ND) Ensure 'Network access: Let Everyone permissions apply to anonymous users' is set to 'Disabled'. CompliantTrue
267(ND, NE) Ensure 'Network access: Shares that can be accessed anonymously' is set to 'None'.CompliantTrue
268(ND, NE) Ensure 'Network access: Sharing and security model for local accounts' is set to 'Classic - local users authenticate as themselves'. CompliantTrue
269(ND, NE) Ensure 'Network access: Named Pipes that can be accessed anonymously' is set to 'None'. CompliantTrue
270(ND, NE) Configure 'Network access: Remotely accessible registry paths and sub-paths'.CompliantTrue
271(ND, NE) Configure 'Network access: Remotely accessible registry paths'.CompliantTrue
272(ND, NE) Ensure 'Network access: Do not allow storage of passwords and credentials for network authentication' is set to 'Enabled'. CompliantTrue
275(ND, NE) Ensure 'System objects: Require case insensitivity for non-Windows subsystems' is set to 'Enabled'. CompliantTrue
276(ND, NE) Ensure 'System objects: Strengthen default permissions of internal system objects (e.g. Symbolic Links)' is set to 'Enabled'.CompliantTrue
317(ND, NE) Ensure 'Connected User Experiences and Telemetry' is set to 'Disabled'.Registry value not found.False
320(ND, NE) Ensure 'Computer Browser (Browser)' is set to 'Disabled' or 'Not Installed'.CompliantTrue
321(NE, ND) Ensure 'Internet Connection Sharing (ICS) (SharedAccess)' is set to 'Disabled'.CompliantTrue
323(ND, NE) Ensure 'IIS Admin Service (IISADMIN)' is set to 'Disabled' or 'Not Installed'.CompliantTrue
324(NE, ND) Ensure 'Infrared monitor service (irmon)' is set to 'Disabled'.CompliantTrue
326(ND, NE) Ensure 'LxssManager (LxssManager)' is set to 'Disabled' or 'Not Installed'.CompliantTrue
328(ND, NE) Ensure 'Microsoft FTP Service (FTPSVC)' is set to 'Disabled' or 'Not Installed'.CompliantTrue
331(ND, NE) Ensure 'OpenSSH SSH Server (sshd)' is set to 'Disabled' or 'Not Installed'.CompliantTrue
338(ND, NE) Ensure 'Routing and Remote Access (RemoteAccess)' is set to 'Disabled'.CompliantTrue
339(ND, NE) Ensure 'Remote Procedure Call (RPC) Locator (RpcLocator)' is set to 'Disabled'.CompliantTrue
341(ND, NE) Ensure 'Simple TCP/IP Services (simptcp)' is set to 'Disabled' or 'Not Installed'.CompliantTrue
343(ND, NE) Ensure 'SSDP Discovery (SSDPSRV)' is set to 'Disabled'.CompliantTrue
345(ND, NE) Ensure 'UPnP Device Host (upnphost)' is set to 'Disabled'. CompliantTrue
348(ND, NE) Ensure 'Web Management Service (WMSvc)' is set to 'Disabled' or 'Not Installed'.CompliantTrue
349(ND, NE) Ensure 'Windows Media Player Network Sharing Service (WMPNetworkSvc)' is set to 'Disabled'.CompliantTrue
351(HD) Ensure 'Windows Mobile Hotspot Service (icssvc)' is set to 'Disabled'. CompliantTrue
356(ND, NE) Ensure 'World Wide Web Publishing Service (W3SVC)' is set to 'Disabled' or 'Not Installed'.CompliantTrue
357(ND, NE) Ensure 'Xbox Accessory Management Service (XboxGipSvc)' is set to 'Disabled'.CompliantTrue
358(ND, NE) Ensure 'Xbox Live Auth Manager (XblAuthManager)' is set to 'Disabled'.CompliantTrue
359(ND, NE) Ensure 'Xbox Live Networking Service (XboxNetApiSvc)' is set to 'Disabled'.CompliantTrue
360(ND, NE) Ensure 'Xbox Live Game Save (XblGameSave)' is set to 'Disabled'.CompliantTrue
361(ND) Ensure 'Windows Firewall: Domain: Outbound connections' is set to 'Allow (default)'.CompliantTrue
362(ND) Ensure 'Windows Firewall: Domain: Settings: Display a notification' is set to 'No'.CompliantTrue
363(ND) Ensure 'Windows Firewall: Domain: Inbound connections' is set to 'Block (default)'.CompliantTrue
364(ND) Ensure 'Windows Firewall: Domain: Firewall state' is set to 'On (recommended)'.CompliantTrue
365(ND, NE) Ensure 'Windows Firewall: Public: Outbound connections' is set to 'Allow (default)' .CompliantTrue
366(ND, NE) Ensure 'Windows Firewall: Public: Settings: Display a notification' is set to 'No'.CompliantTrue
367(ND, NE) Ensure 'Windows Firewall: Public: Inbound connections' is set to 'Block (default)'.CompliantTrue
368(ND, NE) Ensure 'Windows Firewall: Public: Firewall state' is set to 'On (recommended)'.CompliantTrue
369(ND, NE) Ensure 'Windows Firewall: Public: Settings: Apply local firewall rules' is set to 'No'.CompliantTrue
370(ND, NE) Ensure 'Windows Firewall: Public: Settings: Apply local connection security rules' is set to 'No'.CompliantTrue
371(ND, NE) Ensure 'Windows Firewall: Private: Outbound connections' is set to 'Allow (default)'.CompliantTrue
372(ND, NE) Ensure 'Windows Firewall: Private: Settings: Display a notification' is set to 'No'.CompliantTrue
373(ND, NE) Ensure 'Windows Firewall: Private: Inbound connections' is set to 'Block (default)'.CompliantTrue
374(ND, NE) Ensure 'Windows Firewall: Private: Firewall state' is set to 'On (recommended)'.CompliantTrue

User Rights Assignment-

IdTaskMessageStatus
277(ND, NE) Ensure 'Change the system time' is set to 'Administrators, LOCAL SERVICE'.CompliantTrue
278(ND, NE) Ensure 'Change the time zone' is set to 'Administrators, LOCAL SERVICE, Users'.CompliantTrue
279(ND, NE) Ensure 'Increase scheduling priority' is set to 'Administrators, Window Manager\Window Manager Group'.CompliantTrue
280(ND, NE) Ensure 'Deny log on as a batch job' to include 'ANONYMOUS LOGON, Guests'.The user 'SeDenyBatchLogonRight' setting does not contain the following users: NT AUTHORITY\ANONYMOUS LOGONFalse
282(ND, NE) Ensure 'Deny log on as a service' to include 'ANONYMOUS LOGON, Guests'.The user 'SeDenyServiceLogonRight' setting does not contain the following users: NT AUTHORITY\ANONYMOUS LOGONFalse
284(ND) Ensure 'Deny log on through Remote Desktop Services' to include 'ANONYMOUS LOGON, Guests, Local account'.The user right 'SeDenyRemoteInteractiveLogonRight' contains following unexpected users: NT AUTHORITY\Local account The user 'SeDenyRemoteInteractiveLogonRight' setting does not contain the following users: NT AUTHORITY\ANONYMOUS LOGON, LOCALFalse
285(ND, NE) Ensure 'Allow log on through Remote Desktop Services' is set to 'Administrators, Remote Desktop Users'. CompliantTrue
286(ND, NE) Ensure 'Impersonate a client after authentication' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE'. CompliantTrue
287(ND, NE) Ensure 'Adjust memory quotas for a process' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE'.The user right 'SeIncreaseQuotaPrivilege' contains following unexpected users: NT SERVICE\SQLSERVERAGENT, NT SERVICE\MSSQLSERVERFalse
288(ND, NE) Ensure 'Access Credential Manager as a trusted caller' is set to 'No One'.CompliantTrue
289(ND, NE) Ensure 'Access this computer from the network' is set to 'Administrators, Remote Desktop Users'. The user right 'SeNetworkLogonRight' contains following unexpected users: BUILTIN\Users, BUILTIN\Backup Operators The user 'SeNetworkLogonRight' setting does not contain the following users: BUILTIN\Remote Desktop UsersFalse
290(ND, NE) Ensure 'Debug programs' is set to 'Administrators'.CompliantTrue
291(ND, NE) Ensure 'Perform volume maintenance tasks' is set to 'Administrators'.CompliantTrue
292(ND, NE) Ensure 'Act as part of the operating system' is set to 'No One'.CompliantTrue
293(ND) Ensure 'Enable computer and user accounts to be trusted for delegation' is set to 'No One'.CompliantTrue
294(ND, NE) Ensure 'Replace a process level token' is set to 'LOCAL SERVICE, NETWORK SERVICE'.The user right 'SeAssignPrimaryTokenPrivilege' contains following unexpected users: NT SERVICE\SQLSERVERAGENT, NT SERVICE\MSSQLSERVERFalse
295(ND, NE) Ensure 'Create a pagefile' is set to 'Administrators'.CompliantTrue
296(ND, NE) Ensure 'Profile system performance' is set to 'Administrators, NT SERVICE\WdiServiceHost'. CompliantTrue
297(ND, NE) Ensure 'Profile single process' is set to 'Administrators'.CompliantTrue
298(ND, NE) Ensure 'Create a token object' is set to 'No One'.CompliantTrue
299(ND, NE) Ensure 'Create global objects' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE'.CompliantTrue
300(ND, NE) Ensure 'Create symbolic links' is set to 'Administrators'.The user right 'SeCreateSymbolicLinkPrivilege' contains following unexpected users: NT VIRTUAL MACHINE\Virtual MachinesFalse
301(ND, NE) Ensure 'Create permanent shared objects' is set to 'No One'. CompliantTrue
302(ND, NE) Ensure 'Force shutdown from a remote system' is set to 'Administrators'.CompliantTrue
303(ND, NE) Ensure 'Generate security audits' is set to 'LOCAL SERVICE, NETWORK SERVICE'.CompliantTrue
304(ND, NE) Ensure 'Shut down the system' is set to 'Administrators, Users'.The user right 'SeShutdownPrivilege' contains following unexpected users: BUILTIN\Backup OperatorsFalse
305(ND, NE) Ensure 'Load and unload device drivers' is set to 'Administrators'.CompliantTrue
306(ND, NE) Ensure 'Deny log on locally' to include 'ANONYMOUS LOGON, Guests'.The user 'SeDenyInteractiveLogonRight' setting does not contain the following users: NT AUTHORITY\ANONYMOUS LOGONFalse
307(ND, NE) Ensure 'Allow log on locally' is set to 'Administrators, Users'. The user right 'SeInteractiveLogonRight' contains following unexpected users: DESKTOP-UTMU75K\OldGuest, BUILTIN\Backup OperatorsFalse
308(ND, NE) Ensure 'Back up files and directories' is set to 'Administrators'.The user right 'SeBackupPrivilege' contains following unexpected users: BUILTIN\Backup OperatorsFalse
309(ND, NE) Ensure 'Lock pages in memory' is set to 'No One'.CompliantTrue
310(ND, NE) Ensure 'Take ownership of files or other objects' is set to 'Administrators' .CompliantTrue
311(ND, NE) Ensure 'Modify firmware environment values' is set to 'Administrators'. CompliantTrue
312(ND, NE) Ensure 'Modify an object label' is set to 'No One'.CompliantTrue
313(ND, NE) Ensure 'Manage auditing and security log' is set to 'Administrators'.CompliantTrue
314(ND, NE) Ensure 'Restore files and directories' is set to 'Administrators'. The user right 'SeRestorePrivilege' contains following unexpected users: BUILTIN\Backup OperatorsFalse
315(ND, NE) Ensure 'Deny access to this computer from the network' to include 'ANONYMOUS LOGON, Guest, Local account'. The user 'SeDenyNetworkLogonRight' setting does not contain the following users: NT AUTHORITY\ANONYMOUS LOGONFalse

Account Policies-

IdTaskMessageStatus
200(ND, NE) Ensure 'Store passwords using reversible encryption' is set to 'Disabled'.CompliantTrue
201(ND, NE) Ensure 'Password must meet complexity requirements' is set to 'Enabled'.CompliantTrue
202(ND, NE) Ensure 'Enforce password history' is set to '24 or more password(s)'.CompliantTrue
203(ND, NE) Ensure 'Maximum password age' is set to '365 or fewer days, but not 0'.CompliantTrue
204(ND, NE) Ensure 'Minimum password length' is set to '14 or more character(s)'.CompliantTrue
205(ND, NE) Ensure 'Minimum password age' is set to '1 or more day(s)' .CompliantTrue
206(ND) Ensure 'Account lockout duration' is set to '15 or more minute(s)'.CompliantTrue
207(ND) Ensure 'Account lockout threshold' is set to '10 or fewer invalid logon attempt(s), but not 0'.CompliantTrue
208(ND) Ensure 'Reset account lockout counter after' is set to '15 ormore minute(s)'. CompliantTrue

BSI Benchmarks SiSyPHuS NE-

This section contains the BSI Benchmark results.

Registry Settings/Group Policies-

IdTaskMessageStatus
1(ND, NE) Ensure 'Apply UAC restrictions to local accounts on network logons' is set to 'Enabled'. CompliantTrue
2(ND, NE) Ensure 'Configure SMB v1 client driver' is set to 'Enabled: Disable driver.CompliantTrue
3(ND, NE) Ensure 'Configure SMB v1 server' is set to 'Disabled'.CompliantTrue
4(ND, NE) Ensure 'Enable Structured Exception Handling Overwrite Protection (SEHOP)' is set to 'Enabled'.CompliantTrue
5(ND, NE) Ensure 'WDigest Authentication' is set to 'Disabled'.CompliantTrue
6(ND, NE) Ensure 'LSA Protection' is set to 'Enabled'.Registry value not found.False
7(ND, NE) Ensure 'MSS: (EnableDeadGWDetect) Allow automatic detection of dead network gateways (could lead to DoS)' is set to 'Disabled'.Registry value not found.False
8(ND, NE) Ensure 'MSS: (AutoAdminLogon) Enable Automatic Logon(not recommended)' is set to 'Disabled'.CompliantTrue
9(ND, NE) Ensure 'MSS: (DisableIPSourceRouting IPv6) IP source routing protection level (protects against packet spoofing)' is set to 'Enabled: Highest protection, source routing is completely disabled'.CompliantTrue
10(ND, NE) Ensure 'MSS: (DisableIPSourceRouting IPv6) IP source routing protection level (protects against packet spoofing)' is set to 'Enabled: Highest protection, source routing is completely disabled'.CompliantTrue
12(ND, NE) Ensure 'MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes' is set to 'Disabled'.CompliantTrue
14(ND, NE) Ensure 'MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers' is set to 'Enabled'.CompliantTrue
16(ND, NE) Ensure 'MSS: (SafeDllSearchMode) Enable Safe DLL search mode (recommended)' is set to 'Enabled'.CompliantTrue
17(ND, NE) Ensure 'MSS: (ScreenSaverGracePeriod) The time in seconds before the screen saver grace period expires (0 recommended)' is set to 'Enabled: 5 or fewer seconds'.CompliantTrue
20(ND, NE) Ensure 'Turn off multicast name resolution' is set to 'Enabled'.CompliantTrue
21(ND, NE) Ensure 'NetBIOS node type' is set to 'P-node'.CompliantTrue
22(ND, NE) Ensure 'Enable insecure guest logons' is set to 'Disabled'.CompliantTrue
24_1(ND, NE) Ensure 'Hardened UNC Paths' is set to "Require Mutual Authentication=1, "Require Integrity=1" for the value names "\\*\NETLOGON" und "\\*\SYSVOL".CompliantTrue
24_2(ND, NE) Ensure 'Hardened UNC Paths' is set to "Require Mutual Authentication=1, "Require Integrity=1" for the value names "\\*\NETLOGON" und "\\*\SYSVOL".CompliantTrue
33(ND, NE) Ensure 'Minimize the number of simultaneous connections to the Internet or a Windows Domain' is set to the value 'Enabled: 1 = Minimize the number of simultaneous connections'.Registry value not found.False
34(ND) Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled' CompliantTrue
35(ND, NE) Ensure 'Allow Windows to automatically connect to suggested open hotspots, to networks shared by contacts, and to hotspots offering paid services' is set to 'Disabled'.CompliantTrue
37(ND, NE) Ensure 'Turn off toast notifications on the lock screen' is set to 'Enabled'. Registry value not found.False
39(ND, NE) Ensure 'Turn off picture password sign-in' is set to 'Enabled'. CompliantTrue
40(ND, NE) Ensure 'Turn off app notifications on the lock screen' is set to 'Enabled'. CompliantTrue
41(ND, NE) Ensure 'Block user from showing account details on signin' is set to 'Enabled'.CompliantTrue
44(ND, NE) Ensure 'Do not display network selection UI' is set to 'Enabled'.CompliantTrue
46(ND, NE) Ensure 'Boot-Start Driver Initialization Policy' is set to 'Enabled: Good, unknown and bad but critical'.CompliantTrue
50(ND, NE) Ensure 'Encryption Oracle Remediation' is set to 'Enabled: Force Updated Clients'.CompliantTrue
52(ND, NE) Ensure 'Require a password when a computer wakes (on battery)' is set to 'Enabled' .CompliantTrue
53(ND, NE) Ensure 'Require a password when a computer wakes (plugged in)' is set to 'Enabled'.CompliantTrue
54(ND, NE) Ensure 'Allow network connectivity during connected-standby (on battery)' is set to 'Disabled'.CompliantTrue
55(ND, NE) Ensure 'Allow network connectivity during connected-standby (plugged in)' is set to 'Disabled'.CompliantTrue
56(ND, NE) Ensure 'Allow standby states (S1-S3) when sleeping (on battery)' is set to 'Disabled'.CompliantTrue
57(ND, NE) Ensure 'Allow standby states (S1-S3) when sleeping (plugged in)' is set to 'Disabled'.CompliantTrue
59(ND, NE) Ensure 'Prevent installation of devices that match any of these device IDs' is configured.Registry value not found.False
60(ND, NE) Ensure 'Prevent installation of devices using drivers that match these device setup classes' is configured.CompliantTrue
61(ND, NE) Ensure 'Continue experiences on this device' is set to 'Disabled'.CompliantTrue
68(ND, NE) Ensure 'Turn off downloading of print drivers over HTTP' is set to 'Enabled'.CompliantTrue
74(ND, NE) Ensure 'Turn off Internet download for Web publishing and online ordering wizards' is set to 'Enabled'.CompliantTrue
81(ND, NE) Ensure 'Enumeration policy for external devices incompatible with Kernel DMA Protection' is set to 'Enabled: Block All'.CompliantTrue
84(ND, NE) Ensure 'Restrict Unauthenticated RPC clients' is set to 'Enabled: Authenticated' .CompliantTrue
85(ND, NE) Ensure 'Enable RPC Endpoint Mapper Client Authentication' is set to 'Enabled'. CompliantTrue
86(ND, NE) Ensure 'Configure Solicited Remote Assistance' is set to 'Disabled'.CompliantTrue
87(ND, NE) Ensure 'Configure Offer Remote Assistance' is set to 'Disabled'.CompliantTrue
88(ND, NE) Ensure 'Ignore the default list of blocked TPM commands' is set to 'Disabled'.Registry key not found.False
89(ND, NE) Ensure 'Standard User Lockout Duration' is set to '30 minutes'.Registry value not found.False
90(ND, NE) Ensure 'Standard User Total Lockout Threshold' is set to '5'.Registry value not found.False
94(ND, NE) Ensure 'Prevent enabling lock screen slide show' is set to 'Enabled'.CompliantTrue
95(ND, NE) Ensure 'Prevent enabling lock screen camera' is set to 'Enabled'.CompliantTrue
96(ND, NE) Ensure 'Force specific screen saver: Screen saver executable name' is set to 'Enabled: scrnsave.scr'.Registry key not found.False
97(ND, NE) Ensure 'Enable screen saver' is set to 'Enabled'.Registry key not found.False
98(ND, NE) Ensure 'Password protect the screen saver' is set to 'Enabled'.Registry key not found.False
99(ND, NE) Ensure 'Screen saver timeout' is set to 'Enabled: 900 seconds or fewer, but not 0'.Registry key not found.False
100_1(ND, NE) Ensure 'Turn off automatic learning' is set to 'Enabled'.Registry value not found.False
100_2(ND, NE) Ensure 'Turn off automatic learning' is set to 'Enabled'.Registry value not found.False
101(ND, NE) Ensure 'Allow users to enable online speech recognition services' is set to 'Disabled'.CompliantTrue
102(ND, NE) Ensure 'Notify antivirus programs when opening attachments' is set to 'Enabled'. Registry key not found.False
103(ND, NE) Ensure 'Do not preserve zone information in file attachments' is set to 'Disabled'.Registry key not found.False
106(ND, NE) Ensure 'Enumerate administrator accounts on elevation' is set to 'Disabled'.CompliantTrue
107(ND, NE) Ensure 'Do not display the password reveal button' is set to 'Enabled'.CompliantTrue
109(ND, NE) Ensure 'Configure enhanced anti-spoofing' is set to 'Enabled'.CompliantTrue
112(ND, NE) Ensure 'Do not suggest third-party content in Windows spotlight' is set to 'Enabled'.Registry value not found.False
113(ND, NE) Ensure 'Turn off Microsoft consumer experiences' is set to 'Enabled'.CompliantTrue
114(ND, NE) Ensure 'Configure Windows spotlight on lock screen' is set to Disabled'.Registry value not found.False
115(ND, NE) Ensure 'Turn off Data Execution Prevention for Explorer' is set to 'Disabled'.CompliantTrue
116(ND, NE) Ensure 'Turn off shell protocol protected mode' is set to 'Disabled'.CompliantTrue
117(ND, NE) Ensure 'Turn off heap termination on corruption' is set to 'Disabled'.CompliantTrue
118(ND, NE) Ensure 'Toggle user control over Insider builds' is set to 'Disabled'.CompliantTrue
119(ND, NE) Ensure 'Do not show feedback notifications' is set to 'Enabled'.CompliantTrue
120(ND, NE) Ensure 'Allow Telemetry' is set to 'Enabled: 0 – Security [Enterprise Only]'.CompliantTrue
121(ND, NE) Ensure 'Allow device name to be sent in Windows diagnostic data' is set to 'Disabled'.Registry value not found.False
124(ND, NE) Ensure 'Block all consumer Microsoft account user authentication' is set to 'Enabled'.CompliantTrue
126(ND, NE) Ensure 'Prevent users from sharing files within their profile.' is set to 'Enabled'.Registry key not found.False
127(ND, NE) Ensure 'Prevent the usage of OneDrive for file storage' is set to 'Enabled'.Registry key not found.False
131(ND, NE) Ensure 'Do not allow drive redirection' is set to 'Enabled'.CompliantTrue
134(ND, NE) Ensure 'Always prompt for password upon connection' is set to 'Enabled'.CompliantTrue
135(ND, NE) Ensure 'Require user authentication for remote connections by using Network Level Authentication' is set to 'Enabled'. CompliantTrue
136(ND, NE) Ensure 'Require secure RPC communication' is set to 'Enabled'.CompliantTrue
137(ND, NE) Ensure 'Set client connection encryption level' is set to 'Enabled: High Level'.CompliantTrue
138(ND, NE) Ensure 'Require use of specific security layer for remote (RDP) connections' is set to 'Enabled: SSL'. CompliantTrue
139(ND, NE) Ensure 'End session when time limits are reached' is set to 'Enabled'.Registry key not found.False
142(ND, NE) Ensure 'Do not use temporary folders per session' is set to 'Disabled'.Registry value not found.False
143(ND, NE) Ensure 'Do not delete temp folders upon exit' is set to 'Disabled'. CompliantTrue
145(ND, NE) Ensure 'Do not allow passwords to be saved' is set to 'Enabled'.CompliantTrue
146(ND, NE) Ensure 'Disallow Autoplay for non-volume devices' is set to'Enabled'.CompliantTrue
147(ND, NE) Ensure 'Turn off Autoplay' is set to 'Enabled: All drives'.CompliantTrue
148(ND, NE) Ensure 'Set the default behavior for AutoRun' is set to 'Enabled: Do not execute any autorun commands'. CompliantTrue
149(ND, NE) Ensure 'Prevent downloading of enclosures' is set to 'Enabled'.CompliantTrue
152(ND, NE) Ensure 'Turn off Automatic Download and Install of updates' is set to 'Disabled'. CompliantTrue
153(ND, NE) Ensure 'Turn off the offer to update to the latest version of Windows' is set to 'Enabled'.CompliantTrue
157(ND, NE) Ensure 'Allow search and Cortana to use location' is set to 'Disabled'.CompliantTrue
158(ND, NE) Ensure 'Allow indexing of encrypted files' is set to 'Disabled'.CompliantTrue
159(ND, NE) Ensure 'Improve inking and typing recognition' is set to 'Disabled'. Registry key not found.False
160(ND, NE) Ensure 'Download Mode' is set to 'Enabled: Simple (99)' .Registry value is '1'. Expected: 99False
161(ND, NE) Ensure 'Require pin for pairing' is set to 'Enabled: Always'. CompliantTrue
162(ND, NE) Ensure 'Configure detection for potentially unwanted applications' is set to 'Enabled: Block'.CompliantTrue
163(ND, NE) Ensure 'Turn off Windows Defender Antivirus' is set to 'Disabled'.CompliantTrue
164(ND, NE) Ensure 'Configure Watson events' is set to 'Disabled'.CompliantTrue
165(ND, NE) Ensure 'Turn on behavior monitoring' is set to 'Enabled'.CompliantTrue
167(ND, NE) Ensure 'Configure local setting override for reporting to Microsoft MAPS' is set to 'Disabled'.CompliantTrue
168(ND, NE) Ensure 'Turn on e-mail scanning' is set to 'Enabled'.CompliantTrue
169(ND, NE) Ensure 'Scan removable drives' is set to 'Enabled'.CompliantTrue
170(ND, NE) Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block'.CompliantTrue
171(ND, NE) Ensure 'Configure Attack Surface Reduction rules' is set to 'Enabled'.CompliantTrue
172_1(ND, NE) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured'.CompliantTrue
172_2(ND, NE) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured'.CompliantTrue
172_3(ND, NE) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured'.CompliantTrue
172_4(ND, NE) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured'.CompliantTrue
172_5(ND, NE) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured'.CompliantTrue
172_6(ND, NE) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured'.CompliantTrue
172_7(ND, NE) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured'.CompliantTrue
172_8(ND, NE) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured'.CompliantTrue
172_9(ND, NE) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured'.CompliantTrue
172_10(ND, NE) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured'.CompliantTrue
172_11(ND, NE) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured'.CompliantTrue
173(ND, NE) Ensure 'Configure Windows Defender SmartScreen' is set to 'Enabled: Warn and prevent bypass'. CompliantTrue
174(ND, NE) Ensure 'Prevent bypassing Windows Defender SmartScreen prompts for sites' is set to 'Enabled'.CompliantTrue
175(ND, NE) Ensure 'Configure Windows Defender SmartScreen' is set to 'Enabled'.CompliantTrue
177(ND, NE) Ensure 'Allow Windows Ink Workspace' is set to 'Enabled: On, but disallow access above lock' OR 'Disabled'.CompliantTrue
178(ND, NE) Ensure 'Allow user control over installs' is set to 'Disabled'.CompliantTrue
180(ND, NE) Ensure 'Always install with elevated privileges' is set to 'Disabled'.CompliantTrue
181(ND, NE) Ensure 'Always install with elevated privileges' is set to 'Disabled'.Registry key not found.False
183(ND, NE) Ensure 'Turn on Script Execution' is set to 'Enabled: Allow local scripts and remote signed scripts'.Registry key not found.False
185(ND, NE) Ensure 'Configure Automatic Updates' is set to 'Enabled: 4 Auto download and schedule the install'. CompliantTrue
186(ND, NE) Ensure 'Configure Automatic Updates: Scheduled install day' is set to '0 - Every day'. CompliantTrue
187(ND, NE) Ensure 'No auto-restart with logged on users for scheduled automatic updates installations' is set to 'Disabled'.CompliantTrue
188(ND, NE) Ensure 'Remove access to "Pause updates" feature' is set to 'Enabled'.CompliantTrue
189(ND, NE) Ensure 'Sign-in last interactive user automatically after a system-initiated restart' is set to 'Disabled'. CompliantTrue
191(ND, NE) Ensure 'Allow Basic authentication' is set to 'Disabled'.CompliantTrue
192(ND, NE) Ensure 'Disallow Digest authentication' is set to 'Enabled'. CompliantTrue
193(ND, NE) Ensure 'Allow unencrypted traffic' is set to 'Disabled'. CompliantTrue
194(ND, NE) Ensure 'Allow Basic authentication' is set to 'Disabled'.CompliantTrue
196(ND, NE) Ensure 'Disallow WinRM from storing RunAs credentials' is set to 'Enabled'.CompliantTrue
197(ND, NE) Ensure 'Allow unencrypted traffic' is set to 'Disabled'. CompliantTrue
198(ND, NE) Ensure 'Prevent users from modifying settings' is set to 'Enabled'.CompliantTrue
199(ND, NE) Ensure 'Enables or disables Windows Game Recording and Broadcasting' is set to 'Disabled'.CompliantTrue
209(ND, NE) Configure 'Interactive logon: Message title for users attempting to log on'.CompliantTrue
210(ND, NE) Ensure 'User Account Control: Admin Approval Mode for the Built-in Administrator account' is set to 'Enabled'.CompliantTrue
211(ND, NE) Ensure 'User Account Control: Run all administrators in Admin Approval Mode' is set to 'Enabled'. CompliantTrue
212(ND, NE) Ensure 'User Account Control: Detect application installations and prompt for elevation' is set to 'Enabled'. CompliantTrue
213(ND, NE) Ensure 'User Account Control: Switch to the secure desktop when prompting for elevation' is set to 'Enabled'.CompliantTrue
214(ND, NE) Ensure 'User Account Control: Virtualize file and registry write failures to per-user locations' is set to 'Enabled'.CompliantTrue
215(ND, NE) Ensure 'User Account Control: Only elevate UIAccess applications that are installed in secure locations' is set to 'Enabled'. CompliantTrue
216(ND, NE) Ensure 'User Account Control: Allow UIAccess applications to prompt for elevation without using the secure desktop' is set to 'Disabled'.CompliantTrue
217(ND, NE) Ensure 'User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode' is set to 'Prompt for consent on the secure desktop'.CompliantTrue
218(ND, NE) Ensure 'User Account Control: Behavior of the elevation prompt for standard users' is set to 'Prompt for credentials on the secure desktop'.Registry value is '3'. Expected: 1False
226(ND, NE) Ensure 'Devices: Allowed to format and eject removable media' is set to 'Administrators and Interactive Users'.CompliantTrue
227(ND, NE) Ensure 'Interactive logon: Prompt user to change password before expiration' is set to 'between 5 and 14 days'.CompliantTrue
229 Ensure 'Interactive logon: Machine inactivity limit' is set to '900 or fewer second(s), but not 0'. CompliantTrue
230(ND, NE) Ensure 'Interactive logon: Do not require CTRL+ALT+DEL' is set to 'Disabled'.CompliantTrue
231(ND, NE) Configure 'Interactive logon: Message text for users attempting to log on'.CompliantTrue
234(ND, NE) Ensure 'Interactive logon: Don't display last signed-in' is setto 'Enabled'.CompliantTrue
239(ND, NE) Ensure 'Accounts: Limit local account use of blank passwords to console logon only' is set to 'Enabled'. CompliantTrue
240(ND, NE) Ensure 'Accounts: Block Microsoft accounts' is set to 'Users can't add or log on with Microsoft accounts'.CompliantTrue
241(ND, NE) Ensure 'Microsoft network client: Digitally sign communications (always)' is set to 'Enabled'.Registry value is '0'. Expected: 1False
242(ND, NE) Ensure 'Microsoft network client: Digitally sign communications (if server agrees)' is set to 'Enabled'.CompliantTrue
243(ND, NE) Ensure 'Microsoft network client: Send unencrypted password to third-party SMB servers' is set to 'Disabled'.CompliantTrue
244(ND, NE) Ensure 'Microsoft network server: Disconnect clients when logon hours expire' is set to 'Enabled'.CompliantTrue
245(ND, NE) Ensure 'Microsoft network server: Digitally sign communications (always)' is set to 'Enabled'.Registry value is '0'. Expected: 1False
246(ND, NE) Ensure 'Microsoft network server: Digitally sign communications (if client agrees)' is set to 'Enabled'. Registry value is '0'. Expected: 1False
247(ND, NE) Ensure 'Microsoft network server: Amount of idle time required before suspending session' is set to '15 or fewer minute(s)'. CompliantTrue
252(ND) Ensure 'Network security: Configure encryption types allowed for Kerberos' is set to 'AES128_HMAC_SHA1, AES256_HMAC_SHA1, Future encryption types'.CompliantTrue
253(ND, NE) Ensure 'Network security: Do not store LAN Manager hash value on next password change' is set to 'Enabled'.CompliantTrue
254(ND, NE) Ensure 'Network security: LAN Manager authentication level' is set to 'Send NTLMv2 response only'.CompliantTrue
255(ND, NE) Ensure 'Network Security: Allow PKU2U authentication requests to this computer to use online identities' is set to 'Disabled'.CompliantTrue
256(ND, NE) Ensure 'Network security: Allow Local System to use computer identity for NTLM' is set to 'Enabled'. CompliantTrue
257(ND) Ensure 'Network security: Minimum session security for NTLM SSP based (including secure RPC) clients' is set to 'Require NTLMv2 session security, Require 128-bit encryption'. CompliantTrue
258(ND) Ensure 'Network security: Minimum session security for NTLM SSP based (including secure RPC) servers' is set to 'Require NTLMv2 session security, Require 128-bit encryption'.CompliantTrue
259(ND) Ensure 'Network security: LDAP client signing requirements' is set to 'Negotiate signing' or higher.CompliantTrue
260(ND, NE) Ensure 'Network security: Allow LocalSystem NULL session fallback' is set to 'Disabled'.CompliantTrue
261(ND, NE) Ensure 'Network access: Do not allow anonymous enumeration of SAM accounts' is set to 'Enabled'.CompliantTrue
262(ND) Ensure 'Network access: Do not allow anonymous enumeration of SAM accounts and shares' is set to 'Enabled'.CompliantTrue
263(ND) Ensure 'Network access: Allow anonymous SID/Name translation' is set to 'Disabled'.Registry value not found.False
264(ND, NE) Ensure 'Network access: Restrict anonymous access to Named Pipes and Shares' is set to 'Enabled'.CompliantTrue
265(ND, NE) Ensure 'Network access: Restrict clients allowed to make remote calls to SAM' is set to 'Administrators: Remote Access: Allow'.CompliantTrue
266(ND) Ensure 'Network access: Let Everyone permissions apply to anonymous users' is set to 'Disabled'. CompliantTrue
267(ND, NE) Ensure 'Network access: Shares that can be accessed anonymously' is set to 'None'.CompliantTrue
268(ND, NE) Ensure 'Network access: Sharing and security model for local accounts' is set to 'Classic - local users authenticate as themselves'. CompliantTrue
269(ND, NE) Ensure 'Network access: Named Pipes that can be accessed anonymously' is set to 'None'. CompliantTrue
270(ND, NE) Configure 'Network access: Remotely accessible registry paths and sub-paths'.CompliantTrue
271(ND, NE) Configure 'Network access: Remotely accessible registry paths'.CompliantTrue
272(ND, NE) Ensure 'Network access: Do not allow storage of passwords and credentials for network authentication' is set to 'Enabled'. CompliantTrue
275(ND, NE) Ensure 'System objects: Require case insensitivity for non-Windows subsystems' is set to 'Enabled'. CompliantTrue
276(ND, NE) Ensure 'System objects: Strengthen default permissions of internal system objects (e.g. Symbolic Links)' is set to 'Enabled'.CompliantTrue
317(ND, NE) Ensure 'Connected User Experiences and Telemetry' is set to 'Disabled'.Registry value not found.False
320(ND, NE) Ensure 'Computer Browser (Browser)' is set to 'Disabled' or 'Not Installed'.CompliantTrue
321(NE, ND) Ensure 'Internet Connection Sharing (ICS) (SharedAccess)' is set to 'Disabled'.CompliantTrue
323(ND, NE) Ensure 'IIS Admin Service (IISADMIN)' is set to 'Disabled' or 'Not Installed'.CompliantTrue
324(NE, ND) Ensure 'Infrared monitor service (irmon)' is set to 'Disabled'.CompliantTrue
326(ND, NE) Ensure 'LxssManager (LxssManager)' is set to 'Disabled' or 'Not Installed'.CompliantTrue
328(ND, NE) Ensure 'Microsoft FTP Service (FTPSVC)' is set to 'Disabled' or 'Not Installed'.CompliantTrue
331(ND, NE) Ensure 'OpenSSH SSH Server (sshd)' is set to 'Disabled' or 'Not Installed'.CompliantTrue
338(ND, NE) Ensure 'Routing and Remote Access (RemoteAccess)' is set to 'Disabled'.CompliantTrue
339(ND, NE) Ensure 'Remote Procedure Call (RPC) Locator (RpcLocator)' is set to 'Disabled'.CompliantTrue
341(ND, NE) Ensure 'Simple TCP/IP Services (simptcp)' is set to 'Disabled' or 'Not Installed'.CompliantTrue
343(ND, NE) Ensure 'SSDP Discovery (SSDPSRV)' is set to 'Disabled'.CompliantTrue
345(ND, NE) Ensure 'UPnP Device Host (upnphost)' is set to 'Disabled'. CompliantTrue
348(ND, NE) Ensure 'Web Management Service (WMSvc)' is set to 'Disabled' or 'Not Installed'.CompliantTrue
349(ND, NE) Ensure 'Windows Media Player Network Sharing Service (WMPNetworkSvc)' is set to 'Disabled'.CompliantTrue
351(HD) Ensure 'Windows Mobile Hotspot Service (icssvc)' is set to 'Disabled'. CompliantTrue
356(ND, NE) Ensure 'World Wide Web Publishing Service (W3SVC)' is set to 'Disabled' or 'Not Installed'.CompliantTrue
357(ND, NE) Ensure 'Xbox Accessory Management Service (XboxGipSvc)' is set to 'Disabled'.CompliantTrue
358(ND, NE) Ensure 'Xbox Live Auth Manager (XblAuthManager)' is set to 'Disabled'.CompliantTrue
359(ND, NE) Ensure 'Xbox Live Networking Service (XboxNetApiSvc)' is set to 'Disabled'.CompliantTrue
360(ND, NE) Ensure 'Xbox Live Game Save (XblGameSave)' is set to 'Disabled'.CompliantTrue
365(ND, NE) Ensure 'Windows Firewall: Public: Outbound connections' is set to 'Allow (default)' .CompliantTrue
366(ND, NE) Ensure 'Windows Firewall: Public: Settings: Display a notification' is set to 'No'.CompliantTrue
367(ND, NE) Ensure 'Windows Firewall: Public: Inbound connections' is set to 'Block (default)'.CompliantTrue
368(ND, NE) Ensure 'Windows Firewall: Public: Firewall state' is set to 'On (recommended)'.CompliantTrue
369(ND, NE) Ensure 'Windows Firewall: Public: Settings: Apply local firewall rules' is set to 'No'.CompliantTrue
370(ND, NE) Ensure 'Windows Firewall: Public: Settings: Apply local connection security rules' is set to 'No'.CompliantTrue
371(ND, NE) Ensure 'Windows Firewall: Private: Outbound connections' is set to 'Allow (default)'.CompliantTrue
372(ND, NE) Ensure 'Windows Firewall: Private: Settings: Display a notification' is set to 'No'.CompliantTrue
373(ND, NE) Ensure 'Windows Firewall: Private: Inbound connections' is set to 'Block (default)'.CompliantTrue
374(ND, NE) Ensure 'Windows Firewall: Private: Firewall state' is set to 'On (recommended)'.CompliantTrue

User Rights Assignment-

IdTaskMessageStatus
277(ND, NE) Ensure 'Change the system time' is set to 'Administrators, LOCAL SERVICE'.CompliantTrue
278(ND, NE) Ensure 'Change the time zone' is set to 'Administrators, LOCAL SERVICE, Users'.CompliantTrue
279(ND, NE) Ensure 'Increase scheduling priority' is set to 'Administrators, Window Manager\Window Manager Group'.CompliantTrue
280(ND, NE) Ensure 'Deny log on as a batch job' to include 'ANONYMOUS LOGON, Guests'.The user 'SeDenyBatchLogonRight' setting does not contain the following users: NT AUTHORITY\ANONYMOUS LOGONFalse
282(ND, NE) Ensure 'Deny log on as a service' to include 'ANONYMOUS LOGON, Guests'.The user 'SeDenyServiceLogonRight' setting does not contain the following users: NT AUTHORITY\ANONYMOUS LOGONFalse
284(ND) Ensure 'Deny log on through Remote Desktop Services' to include 'ANONYMOUS LOGON, Guests, Local account'.The user right 'SeDenyRemoteInteractiveLogonRight' contains following unexpected users: NT AUTHORITY\Local account The user 'SeDenyRemoteInteractiveLogonRight' setting does not contain the following users: NT AUTHORITY\ANONYMOUS LOGON, LOCALFalse
285(ND, NE) Ensure 'Allow log on through Remote Desktop Services' is set to 'Administrators, Remote Desktop Users'. CompliantTrue
286(ND, NE) Ensure 'Impersonate a client after authentication' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE'. CompliantTrue
287(ND, NE) Ensure 'Adjust memory quotas for a process' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE'.The user right 'SeIncreaseQuotaPrivilege' contains following unexpected users: NT SERVICE\SQLSERVERAGENT, NT SERVICE\MSSQLSERVERFalse
288(ND, NE) Ensure 'Access Credential Manager as a trusted caller' is set to 'No One'.CompliantTrue
289(ND, NE) Ensure 'Access this computer from the network' is set to 'Administrators, Remote Desktop Users'. The user right 'SeNetworkLogonRight' contains following unexpected users: BUILTIN\Users, BUILTIN\Backup Operators The user 'SeNetworkLogonRight' setting does not contain the following users: BUILTIN\Remote Desktop UsersFalse
290(ND, NE) Ensure 'Debug programs' is set to 'Administrators'.CompliantTrue
291(ND, NE) Ensure 'Perform volume maintenance tasks' is set to 'Administrators'.CompliantTrue
292(ND, NE) Ensure 'Act as part of the operating system' is set to 'No One'.CompliantTrue
294(ND, NE) Ensure 'Replace a process level token' is set to 'LOCAL SERVICE, NETWORK SERVICE'.The user right 'SeAssignPrimaryTokenPrivilege' contains following unexpected users: NT SERVICE\SQLSERVERAGENT, NT SERVICE\MSSQLSERVERFalse
295(ND, NE) Ensure 'Create a pagefile' is set to 'Administrators'.CompliantTrue
296(ND, NE) Ensure 'Profile system performance' is set to 'Administrators, NT SERVICE\WdiServiceHost'. CompliantTrue
297(ND, NE) Ensure 'Profile single process' is set to 'Administrators'.CompliantTrue
298(ND, NE) Ensure 'Create a token object' is set to 'No One'.CompliantTrue
299(ND, NE) Ensure 'Create global objects' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE'.CompliantTrue
300(ND, NE) Ensure 'Create symbolic links' is set to 'Administrators'.The user right 'SeCreateSymbolicLinkPrivilege' contains following unexpected users: NT VIRTUAL MACHINE\Virtual MachinesFalse
301(ND, NE) Ensure 'Create permanent shared objects' is set to 'No One'. CompliantTrue
302(ND, NE) Ensure 'Force shutdown from a remote system' is set to 'Administrators'.CompliantTrue
303(ND, NE) Ensure 'Generate security audits' is set to 'LOCAL SERVICE, NETWORK SERVICE'.CompliantTrue
304(ND, NE) Ensure 'Shut down the system' is set to 'Administrators, Users'.The user right 'SeShutdownPrivilege' contains following unexpected users: BUILTIN\Backup OperatorsFalse
305(ND, NE) Ensure 'Load and unload device drivers' is set to 'Administrators'.CompliantTrue
306(ND, NE) Ensure 'Deny log on locally' to include 'ANONYMOUS LOGON, Guests'.The user 'SeDenyInteractiveLogonRight' setting does not contain the following users: NT AUTHORITY\ANONYMOUS LOGONFalse
307(ND, NE) Ensure 'Allow log on locally' is set to 'Administrators, Users'. The user right 'SeInteractiveLogonRight' contains following unexpected users: DESKTOP-UTMU75K\OldGuest, BUILTIN\Backup OperatorsFalse
308(ND, NE) Ensure 'Back up files and directories' is set to 'Administrators'.The user right 'SeBackupPrivilege' contains following unexpected users: BUILTIN\Backup OperatorsFalse
309(ND, NE) Ensure 'Lock pages in memory' is set to 'No One'.CompliantTrue
310(ND, NE) Ensure 'Take ownership of files or other objects' is set to 'Administrators' .CompliantTrue
311(ND, NE) Ensure 'Modify firmware environment values' is set to 'Administrators'. CompliantTrue
312(ND, NE) Ensure 'Modify an object label' is set to 'No One'.CompliantTrue
313(ND, NE) Ensure 'Manage auditing and security log' is set to 'Administrators'.CompliantTrue
314(ND, NE) Ensure 'Restore files and directories' is set to 'Administrators'. The user right 'SeRestorePrivilege' contains following unexpected users: BUILTIN\Backup OperatorsFalse
315(ND, NE) Ensure 'Deny access to this computer from the network' to include 'ANONYMOUS LOGON, Guest, Local account'. The user 'SeDenyNetworkLogonRight' setting does not contain the following users: NT AUTHORITY\ANONYMOUS LOGONFalse

Account Policies-

IdTaskMessageStatus
200(ND, NE) Ensure 'Store passwords using reversible encryption' is set to 'Disabled'.CompliantTrue
201(ND, NE) Ensure 'Password must meet complexity requirements' is set to 'Enabled'.CompliantTrue
202(ND, NE) Ensure 'Enforce password history' is set to '24 or more password(s)'.CompliantTrue
203(ND, NE) Ensure 'Maximum password age' is set to '365 or fewer days, but not 0'.CompliantTrue
204(ND, NE) Ensure 'Minimum password length' is set to '14 or more character(s)'.CompliantTrue
205(ND, NE) Ensure 'Minimum password age' is set to '1 or more day(s)' .CompliantTrue

BSI Benchmarks SiM-08202 - BPOL-

This section contains the BSI Benchmark results.

Registry Settings/Group Policies-

IdTaskMessageStatus
0003 Ensure 'Configure Automatic Updates' is set to 4Registry value not found.False
0004 Ensure 'Configure Automatic Updates' is set to 'Every Day'CompliantTrue
0005 Ensure 'Control Event Log behavior when the log file reaches its maximum size' is set to 'Disabled'CompliantTrue
0006 Ensure 'Specify the maximum log file size (KB)' is set to 'Enabled: 32768'CompliantTrue
0032Ensure 'Setup: Specify the maximum log file size (KB)' is set to 32768.Registry key not found.False
0037Ensure 'Allow enhanced PINs for startup' is set 'Enabled'.CompliantTrue
0038Ensure 'Allow Secure Boot for integrity validation' is set 'Enabled'.CompliantTrue
0039Ensure 'Allow Secure Boot for integrity validation' is set 'Enabled'.Registry value not found.False
0040Ensure 'No auto-restart with logged on users for scheduled automatic updates installations' is set 'Disabled'.CompliantTrue
0041Ensure 'Allow user control over installs' is set 'Disabled'.CompliantTrue
0043Ensure 'Enable Windows NTP Client' is set to 'Enabled'CompliantTrue
0065Ensure 'Enumerate administrator accounts on elevation' is set 'Disabled'.Registry value not found.False
0101 Ensure 'Restrict Unauthenticated RPC clients' is set 'Enabled'CompliantTrue
0109Ensure 'Allow Telemetry' is set to 0.Registry value is '1'. Expected: 0False
0110Ensure 'Do not show feedback notifications' is set to 1.CompliantTrue
0111Ensure 'Turn on MSDT interactive communication with support provider' is set to 'Disabled'.CompliantTrue
0112Ensure 'Toggle user control over Insider builds' is set to 'Disabled'.CompliantTrue
0113Ensure 'Turn off app notifications on the lock screen' is set to 'Enabled'.CompliantTrue
0114Ensure 'Turn off location' is set to 'Enabled'.CompliantTrue
0115Ensure 'Turn off Microsoft consumer experiences' is set to 'Enabled'.CompliantTrue
0116Ensure 'Turn off the Windows Messenger Customer Experience Improvement Program' is set to 'Enabled'.CompliantTrue
0117Ensure 'Turn off the Windows Customer Experience program' is set to 'Enabled'.Registry value is '0'. Expected: 1False
0118Ensure 'Turn off the Windows Error Reporting' is set to 'Enabled'.CompliantTrue
0119Ensure 'Windows Game Recording and Broadcasting' is set to 'Disabled'.CompliantTrue
82020121Ensure 'Allow Microsoft accounts to be optional' is set to 'Enabled'.CompliantTrue
0122Ensure 'Prevent the usage of OneDrive for file storage' is set to 'Enabled'.Registry key not found.False
0123Ensure 'Prevent using Localhost IP address for WebRTC' is set to 'Enabled'.CompliantTrue
0131Ensure 'Allow a Windows app to share application data between users' is set to 'Disabled'.CompliantTrue
0132Ensure 'Allow indexing of encrypted files' is set to 'Disabled'.CompliantTrue
0133Ensure 'Allow InPrivate browsing' is set to 'Disabled'.CompliantTrue
0135Ensure 'Allow Standby States (S1-S3) When Sleeping (On Battery)' is set to 'Disabled'.CompliantTrue
0136Ensure 'Allow Standby States (S1-S3) When Sleeping (Plugged In)' is set to 'Disabled'.CompliantTrue
0137Ensure 'Allow Windows to automatically connect to suggested open hotspots, to networks shared by contacts, and to hotspots offering paid services' is set to 'Disabled'.CompliantTrue
0138Ensure 'Always install with elevated privileges ' is set to 'Disabled'.CompliantTrue
0139Ensure 'Always prompt for password upon connection' is set to 'Enabled'.CompliantTrue
0140Ensure 'Boot-Start Driver Initialization Policy' is set to 'Enabled'.Registry value is '3'. Expected: 1False
0141Ensure 'Configuration of wireless settings using Windows Connect Now' is set to 'Disabled'.CompliantTrue
0142Ensure 'Configure Offer Remote Assistance' is set to 'Disabled'.CompliantTrue
0143Ensure 'Configure Password Manager' is set to 'Disabled'.Registry value not found.False
0144Ensure 'Configure Pop-up Blocker' is set to 'Enabled'.CompliantTrue
0145Ensure 'Configure registry policy processing' is set to 'Do not apply during periodic background processing (False)'.CompliantTrue
0146Ensure 'Configure registry policy processing' is set to 'Process even if the Group Policy objects have not changed (False)'.Registry value is '0'. Expected: 1False
0147Ensure 'Configure Solicited Remote Assistance' is set to 'Disabled'.CompliantTrue
0148Ensure 'Disallow Autoplay for non-volume devices' is set to 'Enabled'.Registry value is '1'. Expected: 0False
0149Ensure 'Disallow copying of user input methods to the system account for sign-in ' is set to 'Enabled'.CompliantTrue
0150Ensure 'Do not allow password expiration time longer than required by policy' is set to 'Enabled'.CompliantTrue
0151Ensure 'Do not allow passwords to be saved' is set to 'Enabled'.CompliantTrue
0152Ensure 'Do not allow supported Plug and Play device redirection' is set to 'Enabled'.CompliantTrue
0153Ensure 'Do not delete temp folders upon exit' set to 'Disabled'.Registry value is '1'. Expected: 0False
0154Ensure 'Do not display network selection UI' set to 'Enabled'.CompliantTrue
0155Ensure 'Do not enumerate connected users on domain-joined computers' set to 'Enabled'.CompliantTrue
0156Ensure 'Enable insecure guest logons' set to 'Disabled'.CompliantTrue
0157Ensure 'Enable local admin password management' set to 'Enabled'.CompliantTrue
0158Ensure 'Enable RPC Endpoint Mapper Client Authentication' set to 'Enabled'.CompliantTrue
0159Ensure 'Enable screen saver' set to 'Enabled'.Registry key not found.False
0160Ensure 'Enable Windows NTP Server' set to 'Disabled'.CompliantTrue
0161Ensure 'Enable/Disable PerfTrack' set to 'Disabled'.CompliantTrue
0163Ensure 'Enumerate local users on domain-joined computers' set to 'Disabled'.CompliantTrue
0164Ensure 'Include command line in process creation events' set to 'Disabled'.Registry key not found.False
0165Ensure 'Let Windows apps access account information' set to 'Enabled:Force Deny'.Registry value not found.False
0166Ensure 'Let Windows apps access call history' set to 'Enabled:Force Deny'.Registry value not found.False
0167Ensure 'Let Windows apps access contacts' set to 'Enabled:Force Deny'.Registry value not found.False
0168Ensure 'Let Windows apps access email' set to 'Enabled:Force Deny'.Registry value not found.False
0169Ensure 'Let Windows apps access location' set to 'Enabled:Force Deny'.Registry value not found.False
0170Ensure 'Let Windows apps access messaging' set to 'Enabled:Force Deny'.Registry value not found.False
0171Ensure 'Let Windows apps access motion' set to 'Enabled:Force Deny'.Registry value not found.False
0172Ensure 'Let Windows apps access notifications' set to 'Enabled:Force Deny'.Registry value not found.False
0173Ensure 'Let Windows apps access the calendar' set to 'Enabled:Force Deny'.Registry value not found.False
0174Ensure 'Let Windows apps access the camera' set to 'Enabled:Force Deny'.Registry value not found.False
0175Ensure 'Let Windows apps access the microphone' set to 'Enabled:Force Deny'.Registry value not found.False
0176Ensure 'Let Windows apps access trusted devices' set to 'Enabled:Force Deny'.Registry value not found.False
0177Ensure 'Let Windows apps control radios' set to 'Enabled:Force Deny'.Registry value not found.False
0178Ensure 'Let Windows apps make phone calls' set to 'Enabled:Force Deny'.Registry value not found.False
0179Ensure 'Let Windows apps sync with devices' set to 'Enabled:Force Deny'.Registry value not found.False
0185Ensure 'Minimize the number of simultaneous connections to the Internet or a Windows Domain' set to 'Enabled'.Registry value not found.False
0209Ensure 'Prevent downloading of enclosures' set to 'Enabled'.CompliantTrue
0210Ensure 'Prevent enabling lock screen camera' set to 'Enabled'.CompliantTrue
0211Ensure 'Prevent enabling lock screen slide show' set to 'Enabled'.CompliantTrue
0212Ensure 'Prevent installation of devices that match any of these device IDs' set to 'Enabled'.Registry value not found.False
0213Ensure 'Prevent installation of devices using drivers that match these device setup classes' set to 'Enabled'.CompliantTrue
0214Ensure 'Prevent Internet Explorer security prompt for Windows Installer scripts' set to 'Disabled'.CompliantTrue
0215Ensure 'Prevent the computer from joining a homegroup' set to 'Enalbed'.CompliantTrue
0216Ensure 'Prohibit access of the Windows Connect Now wizards' set to 'Enalbed'.CompliantTrue
0217Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' set to 'Enalbed'.CompliantTrue
0218Ensure 'Prohibit installation and configuration of Network Bridge on your DNS domain network' set to 'Enalbed'.Registry value is '0'. Expected: 1False
0220Ensure 'Require a password when a computer wakes (on battery)' set to 'Enalbed'.CompliantTrue
0221Ensure 'Require a password when a computer wakes (plugged in)' set to 'Enalbed'.CompliantTrue
0222Ensure 'Require additional authentication at startup' set to 'Enalbed'.CompliantTrue
0223Ensure 'Require domain users to elevate when setting a network's location' set to 'Enalbed'.CompliantTrue
0224Ensure 'Set the default behavior for AutoRun' set to 'Enalbed: Do not execute any autorun commands'.CompliantTrue
0225Ensure 'Sign-in last interactive user automatically after a system-initiated restart' set to 'Disabled'.CompliantTrue
0229Ensure 'Turn off background refresh of Group Policy' set to 'Disabled'.CompliantTrue
0230Ensure 'Turn off Data Execution Prevention for Explorer' set to 'Disabled'.CompliantTrue
0231Ensure 'Turn off downloading of print drivers over HTTP' set to 'Enabled'.CompliantTrue
0232Ensure 'Turn off handwriting personalization data sharing' set to 'Enabled'.CompliantTrue
0233Ensure 'Turn off handwriting recognition error reporting' set to 'Enabled'.CompliantTrue
0234Ensure 'Turn off heap termination on corruption' set to 'Disabled'.CompliantTrue
0235Ensure 'Turn off Internet Connection Wizard if URL connection is referring to Microsoft.com' set to 'Enabled'.CompliantTrue
0236Ensure 'Turn off Internet download for Web publishing and online ordering wizards' set to 'Enabled'.CompliantTrue
0237Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' set to 'Enabled'.CompliantTrue
0238Ensure 'Turn off picture password sign-in' set to 'Enabled'.CompliantTrue
0239Ensure 'Turn off printing over HTTP' set to 'Enabled'.CompliantTrue
0240Ensure 'Turn off Registration if URL connection is referring to Microsoft.com' set to 'Enabled'.CompliantTrue
0241Ensure 'Turn off Search Companion content file updates' set to 'Enabled'.CompliantTrue
0242Ensure 'Turn off shell protocol protected mode' set to 'Disabled'.CompliantTrue
0243Ensure 'Turn off the 'Order Prints' picture task' set to 'Enabled'.CompliantTrue
0244Ensure 'Turn off the 'Publish to Web' task for files and folders' set to 'Enabled'.CompliantTrue
0245Ensure 'Turn on convenience PIN sign-in' set to 'Disabled'.CompliantTrue
0246Ensure 'Turn on Mapper I/O (LLTDIO) driver' set to 'Disabled'.CompliantTrue
0247Ensure 'Turn on Responder (RSPNDR) driver' set to 'Disabled'.CompliantTrue
0248Ensure 'Turn On Virtualization Based Security' set to 'Enabled: Block untrusted fonts and log events'.CompliantTrue
0249Ensure 'Untrusted Font Blocking' set to 'Enabled'.Registry key not found.False
0250Ensure 'Configure enhanced anti-spoofing' set to 'Enabled'.CompliantTrue
0251Ensure 'WDigest Authentication' set to 'Enabled'.Registry value is '0'. Expected: 1False
0253Ensure 'Windows Firewall: Domain: Apply local firewall rules' set to 'Disabled'.Registry value not found.False
0254Ensure 'Windows Firewall: Domain: Display a notification' set to 'Disabled'.Registry value is '1'. Expected: 0False
0279Ensure 'Windows Firewall: Domain: Logging: Name' set to '%windir%\system32\logfiles\firewall\domainfirewall.log'.Registry value is '%SystemRoot%\System32\logfiles\firewall\domainfw.log'. Expected: %windir%\system32\logfiles\firewall\domainfirewall.logFalse
0280Ensure 'Windows Firewall: Public: Logging: Size limit (KB)' set to '16,384'.CompliantTrue
0281Ensure 'Windows Firewall: Public: Outbound connections' set to 'Allow'.Registry value is '0'. Expected: 1False
0282Ensure 'Block launching Windows Store apps with Windows RuntimeAPIaccessfromhostedcontent' set to 'Enabled'.CompliantTrue
0283Ensure 'Turn off KMS Client Online AVS Validation' set to 'Enabled'.CompliantTrue
0284Ensure 'Do not display the password reveal button' set to 'Enabled'.CompliantTrue
0285Ensure 'Join Microsoft MAPS' set to 'Disabled'.Registry value not found.False
0286Ensure 'Configure search suggestions in Address bar' set to 'Disabled'.CompliantTrue
0287Ensure 'Configure Windows SmartScreen' set to 'Enabled: Require approval from an administrator before running downloaded unknown software'.Registry value is '1'. Expected: 2False
0288Ensure 'Don't allow SmartScreen Filter warning overrides for unverified files' set to 'Enabled'.CompliantTrue
0289Ensure 'Don't allow SmartScreen Filter warning overrides' set to 'Enabled'.CompliantTrue
0290Ensure 'Prevent managing SmartScreen Filter' set to 'Enabled: On'.Registry value not found.False
0291Ensure 'Prevent managing SmartScreen Filter' set to 'Enabled: On'.CompliantTrue
0292Ensure 'Turn on SmartScreen Filter scan' set to 'Enabled'.CompliantTrue
0293Ensure 'Allow Cortana' set to 'Disabled'.CompliantTrue
0294Ensure 'Allow search and Cortana to use location' set to 'Disabled'.CompliantTrue
0295Ensure 'Disable all apps from Microsoft Store' set to 'Enabled'.Registry value not found.False
0296Ensure 'Disable pre-release features or settings' set to 'Disabled'.Registry value not found.False
0297Ensure 'Turn off access to the Store' set to 'Enabled'.CompliantTrue
0298Ensure 'Turn off Automatic Download and Install of updates' set to 'Enabled'.Registry value is '4'. Expected: 2False
0299Ensure 'Turn off the offer to update to the latest version of Windows' set to 'Enabled'.CompliantTrue
0300Ensure 'Turn off the Store application' set to 'Enabled'.CompliantTrue
0301Ensure 'Allow Basic authentication' set to 'Disabled'.CompliantTrue
0302Ensure 'Allow unencrypted traffic' set to 'Disabled'.CompliantTrue
0304Ensure 'Allow Remote Shell Access' set to 'Disabled'.Registry value is '1'. Expected: 0False
0306Ensure 'Allow users to connect remotely by using Remote Desktop Services' set to 'Disabled'.CompliantTrue
0307Ensure 'Disallow Digest authentication' set to 'Enabled'.CompliantTrue
0308Ensure 'Disallow WinRM from storing RunAs credentials' set to 'Enabled'.CompliantTrue
0309Ensure 'Do not allow COM port redirection' set to 'Enabled'.CompliantTrue
0310Ensure 'Do not allow drive redirection' set to 'Enabled'.CompliantTrue
0311Ensure 'Do not allow LPT port redirection' set to 'Enabled'.CompliantTrue
0312Ensure 'Do not use temporary folders per session' set to 'Disabled'.Registry value not found.False
0313Ensure 'Apply UAC restrictions to local accounts on network logons' set to 'Enabled'.CompliantTrue
0323Ensure 'Allow access to BitLocker-protected fixed data drives from earlier versions of Windows' set to 'Disabled'.Registry value is ''. Expected: False
0324Ensure 'Allow access to BitLocker-protected removable data drives from earlier versions of Windows' set to 'Disabled'.Registry value is ''. Expected: False
0325Ensure 'Choose drive encryption method and cipher strength (Windows 10 [Version 1511] and later)' set to 'XTS-AES 256-bit'.Registry value not found.False
0328Ensure 'Choose how BitLocker-protected fixed drives can be recovered' set to 'Enabled'.CompliantTrue
0329Ensure 'Choose how BitLocker-protected operating system drives can be recovered' set to 'Enabled'.CompliantTrue
0330Ensure 'Choose how BitLocker-protected removable drives can be recovered' set to 'Enabled'.Registry value not found.False
0331Ensure 'Configure minimum PIN length for startup' set to 'Enabled' and 'minimum characters' set to 10.Registry value not found.False
0332Ensure 'Configure use of hardware-based encryption for fixed data drives' set to 'Enabled'.CompliantTrue
0333Ensure 'Configure use of hardware-based encryption for operating system drives' set to 'Enabled'.CompliantTrue
0334Ensure 'Configure use of hardware-based encryption for removable data drives' set to 'Enabled'.CompliantTrue
0335Ensure 'Configure use of passwords for fixed data drives' set to 'Disabled'.CompliantTrue
0336Ensure 'Configure use of passwords for operating system drives' set to 'Disabled'.CompliantTrue
0337Ensure 'Configure use of passwords for removable data drives' set to 'Disabled'.Registry value not found.False
0338Ensure 'Configure use of smart cards on fixed data drives' set to 'Enabled'.CompliantTrue
0339Ensure 'Configure use of smart cards on removable data drives' set to 'Enabled'.CompliantTrue
0340Ensure 'Deny write access to removable drives not protected by BitLocker' set to 'Enabled'.CompliantTrue
82020342Ensure 'Choose how BitLocker-protected fixed drives can be recovered' set to 'Save BitLocker recovery information to AD DS for fixed data drives'.CompliantTrue
0343Ensure 'Choose how BitLocker-protected operating system drives can be recovered' set to 'Save BitLocker recovery information to AD DS for operating system drives'.CompliantTrue
0344Ensure 'Choose how BitLocker-protected removable drives can be recovered' set to 'Save BitLocker recovery information to AD DS for removable data drives'.CompliantTrue
0345Ensure 'Require additional authentication at startup' set to 'Do not allow startup key and PIN with TPM'.Registry value not found.False
0346Ensure 'Choose how BitLocker-protected fixed drives can be recovered' set to 'Allow data recovery agent'.CompliantTrue
0347Ensure 'Choose how BitLocker-protected operating system drives can be recovered' set to 'Allow data recovery agent'.CompliantTrue
0348Ensure 'Choose how BitLocker-protected removable drives can be recovered' set to 'Allow data recovery agent'.CompliantTrue
0349Ensure 'Configure use of hardware-based encryption for fixed data drives' set to 'Use BitLocker software-based encryption when hardware encryption is not available'.CompliantTrue
0350Ensure 'Configure use of hardware-based encryption for operating system drives' set to 'Use BitLocker software-based encryption when hardware encryption is not available'.CompliantTrue
0351Ensure 'Configure use of hardware-based encryption for removable data drives' set to 'Use BitLocker software-based encryption when hardware encryption is not available'.CompliantTrue
0352Ensure 'Configure use of smart cards on fixed data drives' set to 'Require use of smart cards on fixed data drives'.CompliantTrue
0353Ensure 'Configure use of smart cards on removable data drives' set to 'Require use of smart cards on removable data drives'.CompliantTrue
0354Ensure 'Deny write access to removable drives not protected by BitLocker' set to 'Do not allow write access to devices configured in another organization'.Registry value is '0'. Expected: 1False
0355Ensure 'Password Settings' set to 'Large letters + small letters + numbers + specials'.CompliantTrue
0358Ensure 'Require additional authentication at startup' set to 'Allow BitLocker without a compatible TPM'.CompliantTrue
0359Ensure 'Choose how BitLocker-protected operating system drives can be recovered' set to 'Omit recovery options from the BitLocker setup wizard'.CompliantTrue
0360Ensure 'Choose how BitLocker-protected fixed drives can be recovered' set to 'Omit recovery options from the BitLocker setup wizard (Test)'.CompliantTrue
0361Ensure 'Choose how BitLocker-protected removable drives can be recovered' set to 'Omit recovery options from the BitLocker setup wizard (True)'.CompliantTrue
0362Ensure 'Require additional authentication at startup' set to 'Do not allow startup key with TPM'.Registry value not found.False
0363Ensure 'Choose how BitLocker-protected fixed drives can be recovered' set to 'Allow 48-digit recovery password'.CompliantTrue
0364Ensure 'Choose how BitLocker-protected operating system drives can be recovered' set to 'Require 48-digit recovery password '.Registry value is '2'. Expected: 1False
0365Ensure 'Choose how BitLocker-protected removable drives can be recovered' set to 'Do not allow 48-digit recovery password'.Registry value not found.False
0366Ensure 'Configure use of hardware-based encryption for fixed data drives' set to 'Restrict encryption algorithms and cipher suites allowed for hardware-based encryption'.CompliantTrue
0367Ensure 'Configure use of hardware-based encryption for operating system drives' set to 'Restrict encryption algorithms and cipher suites allowed for hardware-based encryption (False)'.CompliantTrue
0368Ensure 'Configure use of hardware-based encryption for removable data drives' set to 'Restrict encryption algorithms and cipher suites allowed for hardware-based encryption (False)'.CompliantTrue
0369Ensure 'Configure use of hardware-based encryption for removable data drives' set to 'Password Length' and set to greater or equal 15.Registry value is '14'. Expected: x >= 15False
0370Ensure 'Prevent installation of devices that match any of these device IDs' set to 'Also apply to matching devices that are already installed. (True) '.Registry value not found.False
0371Ensure 'Prevent installation of devices using drivers that match these device setup classes' set to 'Also apply to matching devices that are already installed. (True) '.CompliantTrue
0372Ensure 'Require additional authentication at startup' set to 'Do not allow TPM'.Registry value not found.False
0373Ensure 'Choose how BitLocker-protected removable drives can be recovered' set to 'Do not enable BitLocker until recovery information is stored to AD DS for removable data drives (False)'.CompliantTrue
0374Ensure 'Choose how BitLocker-protected operating system drives can be recovered' set to 'Do not enable BitLocker until recovery information is stored to AD DS for operating system drives (Enabled)'.CompliantTrue
0375Ensure 'Choose how BitLocker-protected fixed drives can be recovered' set to 'Backup recovery passwords and key packages'.CompliantTrue
0376Ensure 'Choose how BitLocker-protected operating system drives can be recovered' set to 'Store recovery passwords and key packages'.CompliantTrue
0377Ensure 'Choose how BitLocker-protected removable drives can be recovered' set to 'Backup recovery passwords and key packages'.CompliantTrue
0378Ensure 'Choose how BitLocker-protected operating system drives can be recovered' set to 'Do not allow 256-bit recovery key'.CompliantTrue
0380Ensure 'Choose how BitLocker-protected removable drives can be recovered' set to 'Do not allow 256-bit recovery key'.CompliantTrue
0384Ensure 'Password Age' set to less or equal 42.Registry value is '20'. Expected: 42False
0385Ensure 'Require additional authentication at startup' set to 'Require startup PIN with TPM'.Registry value not found.False
0386Ensure 'Turn on PowerShell Transcription' set to 'Disabled'.CompliantTrue
0387Ensure 'Turn on PowerShell Script Block Logging' set to 'Enabled'.Registry value is '0'. Expected: 1False
0388Ensure 'Require secure RPC communication' set to 'Enabled'.CompliantTrue
0389Ensure 'Set client connection encryption level' set to 'Enabled: High Level'.CompliantTrue
0390Ensure 'Set time limit for active but idle Remote Desktop Services sessions' set to 'Enabled: 5 minutes'.Registry value is '900000'. Expected: 300000False
0391Ensure 'Set time limit for disconnected sessions' set to 'Enabled: 1 minute'.CompliantTrue

User Rights Assignment-

IdTaskMessageStatus
0044 Ensure 'SeTrustedCredManAccessPrivilege' is set to 'Enabled'The user 'SeTrustedCredManAccessPrivilege' setting does not contain the following users: NULL SIDFalse
0045 Ensure 'SeNetworkLogonRight' is set to 'Administrator, Users'The user right 'SeNetworkLogonRight' contains following unexpected users: BUILTIN\Backup OperatorsFalse
0046 Ensure 'SeTcbPrivilege' is set to 'None'The user 'SeTcbPrivilege' setting does not contain the following users: NULL SIDFalse
0047 Ensure ’Adjust memory quotas for a process’ set to ’Administrators, LOCAL SERVICE, NETWORK SERVICE’The user right 'SeIncreaseQuotaPrivilege' contains following unexpected users: NT SERVICE\SQLSERVERAGENT, NT SERVICE\MSSQLSERVERFalse
0048 Ensure 'Allow log on locally' set to 'Administrators, Users'The user right 'SeInteractiveLogonRight' contains following unexpected users: DESKTOP-UTMU75K\OldGuest, BUILTIN\Backup OperatorsFalse
0049 Ensure 'SeBackupPrivilege' is set to 'Administrator'The user right 'SeBackupPrivilege' contains following unexpected users: BUILTIN\Backup OperatorsFalse
0050 Ensure 'SeSystemtimePrivilege' is set to 'Administrator, LOCAL SERVICE'CompliantTrue
0051 Ensure 'SeTimeZonePrivilege' is set to 'Administrator, LOCAL SERVICE'The user right 'SeTimeZonePrivilege' contains following unexpected users: BUILTIN\UsersFalse
0052 Ensure 'SeCreatePagefilePrivilege' is set to 'Administrator, LOCAL SERVICE'The user 'SeCreatePagefilePrivilege' setting does not contain the following users: NT AUTHORITY\LOCAL SERVICEFalse
0053 Ensure 'SeCreateTokenPrivilege' is set to 'None'The user 'SeCreateTokenPrivilege' setting does not contain the following users: NULL SIDFalse
0054 Ensure 'SeCreateGlobalPrivilege' is set to 'Administrator, SERVICE, LOCAL SERVICE, NETWORK SERVICE'CompliantTrue
0055 Ensure 'SeCreatePermanentPrivilege' is set to 'None'The user 'SeCreatePermanentPrivilege' setting does not contain the following users: NULL SIDFalse
0056 Ensure 'SeCreateSymbolicLinkPrivilege' is set to 'Administrator'The user right 'SeCreateSymbolicLinkPrivilege' contains following unexpected users: NT VIRTUAL MACHINE\Virtual MachinesFalse
0057 Ensure 'SeDebugPrivilege' is set to 'Administrator'CompliantTrue
0064 Ensure 'SeEnableDelegationPrivilege' is set to 'None'The user 'SeEnableDelegationPrivilege' setting does not contain the following users: NULL SIDFalse
0066 Ensure 'SeRemoteShutdownPrivilege' is set to 'Administrator'CompliantTrue
0067 Ensure 'SeAuditPrivilege' is set to 'LOCAL SERVICE, NETWORK SERVICE'CompliantTrue
0068 Ensure 'SeImpersonatePrivilege' is set to 'Administrator, LOCAL SERVICE, NETWORK SERVICE'The user right 'SeImpersonatePrivilege' contains following unexpected users: NT AUTHORITY\SERVICEFalse
0069 Ensure 'SeIncreaseBasePriorityPrivilege' is set to 'Administrator'The user right 'SeIncreaseBasePriorityPrivilege' contains following unexpected users: Window Manager\Window Manager GroupFalse
0085 Ensure 'SeRelabelPrivilege' is set to 'None'The user 'SeRelabelPrivilege' setting does not contain the following users: NULL SIDFalse
0086 Ensure 'SeSystemEnvironmentPrivilege' is set to 'Administrator'CompliantTrue
0087 Ensure 'SeManageVolumePrivilege' is set to 'Administrator'CompliantTrue
0088 Ensure 'SeProfileSingleProcessPrivilege' is set to 'Administrator'CompliantTrue
0089 Ensure 'SeSystemProfilePrivilege' is set to 'Administrator, NT SERVICE/WdiServiceHost'CompliantTrue
0090 Ensure 'SeRestorePrivilege' is set to 'Administrator'The user right 'SeRestorePrivilege' contains following unexpected users: BUILTIN\Backup OperatorsFalse
0091 Ensure 'SeShutdownPrivilege' is set to 'Administrator, Users'The user right 'SeShutdownPrivilege' contains following unexpected users: BUILTIN\Backup OperatorsFalse
0094 Ensure 'SeTakeOwnershipPrivilege' is set to 'Administrator'CompliantTrue
0104 Ensure 'SeDenyNetworkLogonRight' is set to 'Local account, Guest'The user right 'SeDenyNetworkLogonRight' contains following unexpected users: LOCAL The user 'SeDenyNetworkLogonRight' setting does not contain the following users: NT AUTHORITY\Local accountFalse
0105 Ensure 'SeDenyBatchLogonRight' is set to 'Guest'CompliantTrue
0106 Ensure 'SeDenyServiceLogonRight' is set to 'Guest'CompliantTrue
0107 Ensure 'SeDenyInteractiveLogonRight' is set to 'Guest'CompliantTrue
0108 Ensure 'SeDenyRemoteInteractiveLogonRight' is set to 'Local account, Guest'CompliantTrue
0180 Ensure 'Load and unload device drivers' is set to 'Administrator'CompliantTrue
0181 Ensure 'Lock pages in memory' is set to 'No one'The user 'SeLockMemoryPrivilege' setting does not contain the following users: NULL SIDFalse
0182 Ensure 'Log on as a batch job' is set to 'Administrator'The user right 'SeBatchLogonRight' contains following unexpected users: BUILTIN\Backup Operators, BUILTIN\Performance Log UsersFalse
0183 Ensure 'Log on as a service' is set to 'No one'The user right 'SeServiceLogonRight' contains following unexpected users: DESKTOP-UTMU75K\SQLServer2005SQLBrowserUser$DESKTOP-UTMU75K, NT SERVICE\ALL SERVICES, NT SERVICE\SQLTELEMETRY, NT SERVICE\SQLSERVERAGENT, NT SERVICE\MSSQLSERVER, NT VIRTUAL MACHINE\Virtual Machines The user 'SeServiceLogonRight' setting does not contain the following users: NULL SIDFalse
0184 Ensure 'Manage auditing and security log' is set to 'Administrator'CompliantTrue
0219 Ensure 'Replace a process level token' is set to 'Local Service, Network Service'The user right 'SeAssignPrimaryTokenPrivilege' contains following unexpected users: NT SERVICE\SQLSERVERAGENT, NT SERVICE\MSSQLSERVERFalse
0303 Ensure 'Allow log on through Remote Desktop Services' is set to 'Remote Desktop User'The user right 'SeRemoteInteractiveLogonRight' contains following unexpected users: BUILTIN\AdministratorsFalse

Account Policies-

IdTaskMessageStatus
0001 Ensure 'Maximum password age' is set to between 1 and 42'MaximumPasswordAge' currently set to: 60. Expected: x <= 42 and x >= 1False
0002 Ensure 'Password must meet complexity requirements' is set to 'Enabled'CompliantTrue
0100 Ensure 'Reset account lockout counter after' is set greater or equal 15CompliantTrue
0102 Ensure 'Account lockout duration' is set to '15 or more minute(s)'CompliantTrue
0103Ensure 'Account lockout threshold' is set greater or equal 1 and less or equal 10CompliantTrue
0162 Ensure 'Enforce password history' is set greater or equal 24CompliantTrue
0186 Ensure 'Minimum password age' is set to greater or equal 1CompliantTrue
0187 Ensure 'Minimum password length' is set to greater or equal 14CompliantTrue

Advanced Audit Policy Configuration-

IdTaskMessageStatus
0008 Ensure 'Audit Application Group Management' is set to 'Success and Failure'CompliantTrue
0011 Ensure 'Audit Other Account Management Events' is set to 'Success and Failure'Set to: No AuditingFalse
0012 Ensure 'Audit Security Group Management' is set to 'SuccessAndFailure'Set to: SuccessFalse
0013 Ensure 'Audit account management' is set to 'SuccessAndFailure'CompliantTrue
0014 Ensure 'Advanced security audit policy settings' is set to 'SuccessAndNotFailure'Set to: SuccessFalse
0015 Ensure 'Audit Process Creation' is set to 'SuccessAndNotFailure'Set to: SuccessFalse
0016 Ensure 'Audit Other Logon/Logoff Events' is set to 'SuccessAndFailure'CompliantTrue
0017 Ensure 'Audit Account Lockout' is set to 'SuccessAndNotFailure'Set to: FailureFalse
0018 Ensure 'How to track users logon/logoff' is set to 'SuccessAndNotFailure'CompliantTrue
0019 Ensure 'Audit Policy: Logon-Logoff: Logon' is set to 'SuccessAndFailure'CompliantTrue
0020 Ensure 'Audit Policy: Logon-Logoff: Special Logon' is set to 'Enabled'CompliantTrue
0021 Ensure 'Audit Policy: Object Access:Removable Storage' is set to 'SuccessAndFailure'CompliantTrue
0022 Ensure 'Audit Policy: Policy Change: Audit Policy Change' is set to 'SuccessAndFailure'Set to: SuccessFalse
0023 Ensure 'Audit Policy: Policy Change: Authentication Policy Change' is set to 'SuccessAndFailure'Set to: SuccessFalse
0025 Ensure 'Audit Policy: System: IPsecDriver' is set to 'SuccessAndFailure'CompliantTrue
0026 Ensure 'Audit Policy: System: OtherSystem Events' is set to 'SuccessAndFailure'CompliantTrue
0027 Ensure 'Audit Policy: System: Security State Change' is set to 'SuccessAndFailure'Set to: SuccessFalse
0028 Ensure 'Audit Policy: System: Security System Extension' is set to 'SuccessAndFailure'Set to: SuccessFalse
0029 Ensure 'Audit Policy: System: System Integrity' is set to 'SuccessAndFailure'CompliantTrue