Windows 11 Report

Generated by the ATAPAuditor Module Version 4.14 by FB Pro GmbH. Get it in the Audit Test Automation Package. Are you seeing a lot of red sections? Check out our hardening solutions.

Based on:

This report was generated on 01/17/2022 05:19:04 on DESKTOP-EHK98K4 with TAPHtmlReport version 1.8.

HostnameDESKTOP-EHK98K4
Build Number22000
Free disk space(GB) 105.2
Free physical memory (GB)0.804
Operating SystemMicrosoft Windows 11 Pro
Installation LanguageEnglish (United States)

Summary

A total of 347 tests have been executed.

  1. True 40 test(s) ≙ 11.53%
  2. False 307 test(s) ≙ 88.47%
  3. Warning 0 test(s) ≙ 0.00%
  4. None 0 test(s) ≙ 0.00%
  5. Error 0 test(s) ≙ 0.00%

Microsoft Benchmarks

A total of 347 tests have been executed in section Microsoft Benchmarks.

  1. True 40 test(s) ≙ 11.53%
  2. False 307 test(s) ≙ 88.47%
  3. Warning 0 test(s) ≙ 0.00%
  4. None 0 test(s) ≙ 0.00%
  5. Error 0 test(s) ≙ 0.00%

Table of Contents

Click the link(s) below for quick access to a report section.

Microsoft Benchmarks-

This section contains all benchmarks from Microsoft

Registry Settings/Group Policies-

IdTaskMessageStatus
Registry-009Set registry value 'UseEnhancedPin' to 1.Registry key not found.False
Registry-010Set registry value 'RDVDenyCrossOrg' to 0.Registry key not found.False
Registry-011Set registry value 'DisableExternalDMAUnderLock' to 1.Registry key not found.False
Registry-012Set registry value 'DCSettingIndex' to 0.Registry key not found.False
Registry-013Set registry value 'ACSettingIndex' to 0.Registry key not found.False
Registry-014Set registry value 'DenyDeviceClasses' to 1.Registry key not found.False
Registry-015Set registry value 'DenyDeviceClassesRetroactive' to 1.Registry key not found.False
Registry-016Set registry value '1' to 'Prevent installation of drivers matching these device setup classes'.Registry key not found.False
Registry-017Ensure 'Deny write access to removable drives not protected by BitLocker' is set to 'Enabled'.Registry key not found.False
Registry-018Set registry value 'PUAProtection' to 1.Registry value not found.False
Registry-019Set registry value 'MpCloudBlockLevel' to 2.Registry key not found.False
Registry-020Ensure 'Scan all downloaded files and attachments' is set to 'Enabled'.Registry key not found.False
Registry-021Ensure 'Turn off real-time protection' is set to 'Disabled'.Registry key not found.False
Registry-022Set registry value 'DisableScriptScanning' to 0.Registry key not found.False
Registry-023Ensure 'Scan removable drives' is set to 'Enabled'.Registry key not found.False
Registry-024Ensure 'Send file samples when further analysis is required' is set to 'Send safe samples'.Registry key not found.False
Registry-025Ensure 'Join Microsoft MAPS' is set to 'Advanced MAPS'.Registry key not found.False
Registry-026Ensure 'Configure the 'Block at First Sight' feature' is set to 'Enabled'.Registry key not found.False
Registry-027Set registry value 'ExploitGuard_ASR_Rules' to 1.Registry key not found.False
Registry-028(L1) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is configuredRegistry key not found.False
Registry-029(L1) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is configuredRegistry key not found.False
Registry-030(L1) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is configuredRegistry key not found.False
Registry-031(L1) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is configuredRegistry key not found.False
Registry-032(L1) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is configuredRegistry key not found.False
Registry-033(L1) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is configuredRegistry key not found.False
Registry-034(L1) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is configuredRegistry key not found.False
Registry-035(L1) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is configuredRegistry key not found.False
Registry-036(L1) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is configuredRegistry key not found.False
Registry-037(L1) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is configuredRegistry key not found.False
Registry-038(L1) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is configuredRegistry key not found.False
Registry-039Use advanced protection against ransomwareRegistry key not found.False
Registry-040(L1) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is configuredRegistry key not found.False
Registry-041Set registry value 'EnableNetworkProtection' to 1.Registry key not found.False
Registry-042Ensure 'Turn On Virtualization Based Security' is set to 'Enabled'.Registry key not found.False
Registry-043Ensure 'Turn On Virtualization Based Security' is set to 'Secure Boot'.Registry key not found.False
Registry-044Ensure 'Turn On Virtualization Based Security' is set to 'Enabled with UEFI lock'.Registry key not found.False
Registry-045Set registry value 'HVCIMATRequired' to 1.Registry key not found.False
Registry-046Ensure 'Turn On Virtualization Based Security' is set to 'Enabled with UEFI lock'.Registry key not found.False
Registry-047Set registry value 'ConfigureSystemGuardLaunch' to 1.Registry key not found.False
Registry-048Ensure 'Do not suggest third-party content in Windows spotlight' is set to 'Enabled'.Registry value not found.False
Registry-049Set registry value 'NoToastApplicationNotificationOnLockScreen' to 1.Registry key not found.False
Registry-050Set registry value 'AutoConnectAllowedOEM' to 0.Registry value not found.False
Registry-051Ensure 'Enumerate administrator accounts on elevation' is set to 'Disabled'.Registry key not found.False
Registry-052Ensure 'Turn off Autoplay' is set to 'All drives'.Registry value not found.False
Registry-053Set registry value 'NoWebServices' to 1.Registry value not found.False
Registry-054Ensure 'Set the default behavior for AutoRun' is set to 'Do not execute any autorun commands'.Registry value not found.False
Registry-055Ensure 'Allow Microsoft accounts to be optional' is set to 'Enabled'.Registry value not found.False
Registry-056Ensure 'Sign-in last interactive user automatically after a system-initiated restart' is set to 'Disabled'.Registry value not found.False
Registry-057Set registry value 'LocalAccountTokenFilterPolicy' to 0.Registry value not found.False
Registry-058Set registry value 'AllowEncryptionOracle' to 0.Registry key not found.False
Registry-059Set registry value 'EnhancedAntiSpoofing' to 1.Registry key not found.False
Registry-060Ensure 'Prevent downloading of enclosures' is set to 'Enabled'.Registry key not found.False
Registry-061Ensure 'Require a password when a computer wakes (on battery)' is set to 'Enabled'.Registry key not found.False
Registry-062Ensure 'Require a password when a computer wakes (plugged in)' is set to 'Enabled'.Registry key not found.False
Registry-063Set registry value 'LetAppsActivateWithVoiceAboveLock' to 2.Registry key not found.False
Registry-064Ensure 'Turn off Microsoft consumer experiences' is set to 'Enabled'.Registry key not found.False
Registry-065Set registry value 'AllowProtectedCreds' to 1.Registry key not found.False
Registry-066Ensure 'Specify the maximum log file size (KB)' is set to '32768'.Registry key not found.False
Registry-067Ensure 'Specify the maximum log file size (KB)' is set to '196608'.Registry key not found.False
Registry-068Ensure 'Specify the maximum log file size (KB)' is set to '32768'.Registry key not found.False
Registry-069Ensure 'Disallow Autoplay for non-volume devices' is set to 'Enabled'.Registry key not found.False
Registry-070Set registry value 'AllowGameDVR' to 0.Registry key not found.False
Registry-071Ensure 'Configure registry policy processing' is set to '0'.Registry key not found.False
Registry-072Ensure 'Configure registry policy processing' is set to '0'.Registry key not found.False
Registry-073Set registry value 'AlwaysInstallElevated' to 0.Registry key not found.False
Registry-074Ensure 'Allow user control over installs' is set to 'Disabled'.Registry key not found.False
Registry-075Set registry value 'DeviceEnumerationPolicy' to 0.Registry key not found.False
Registry-076Ensure 'Enable insecure guest logons' is set to 'Disabled'.Registry key not found.False
Registry-077Ensure 'Prohibit use of Internet Connection Sharing on your DNS domain network' is set to 'Enabled'.Registry value not found.False
Registry-078Set registry value '\\*\SYSVOL' to RequireMutualAuthentication=1,RequireIntegrity=1.Registry value is ''. Expected: RequireMutualAuthentication=1,RequireIntegrity=1False
Registry-079Set registry value '\\*\NETLOGON' to RequireMutualAuthentication=1,RequireIntegrity=1.Registry value is ''. Expected: RequireMutualAuthentication=1,RequireIntegrity=1False
Registry-080Set registry value 'NoLockScreenCamera' to 1.Registry key not found.False
Registry-081Set registry value 'NoLockScreenSlideshow' to 1.Registry key not found.False
Registry-082Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'.Registry key not found.False
Registry-083Ensure 'Turn on PowerShell Script Block Logging' is not set.Compliant. Registry key not found.True
Registry-084Ensure 'Turn on convenience PIN sign-in' is set to 'Disabled'.Registry value not found.False
Registry-085Ensure 'Enumerate local users on domain-joined computers' is set to 'Disabled'.Registry value not found.False
Registry-086Ensure 'Configure Windows SmartScreen' is set to 'Enabled'.Registry value not found.False
Registry-087Set registry value 'ShellSmartScreenLevel' to Block.Registry value not found.False
Registry-088Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled'.Registry value not found.False
Registry-089Set registry value 'AllowIndexingEncryptedStoresOrItems' to 0.Registry key not found.False
Registry-090Ensure 'Disallow Digest authentication' is set to 'Enabled'.Registry key not found.False
Registry-091Ensure 'Allow unencrypted traffic' is set to 'Disabled'.Registry key not found.False
Registry-092Ensure 'Allow Basic authentication' is set to 'Disabled'.Registry key not found.False
Registry-093Ensure 'Allow unencrypted traffic' is set to 'Disabled'.Registry key not found.False
Registry-094Ensure 'Disallow WinRM from storing RunAs credentials' is set to 'Enabled'.Registry key not found.False
Registry-095Ensure 'Allow Basic authentication' is set to 'Disabled'.Registry key not found.False
Registry-096Ensure 'Turn off multicast name resolution' is set to 'Enabled'.Registry key not found.False
Registry-097Set registry value 'DisableWebPnPDownload' to 1.Registry key not found.False
Registry-098Set registry value 'RestrictDriverInstallationToAdministrators' to 1.Registry key not found.False
Registry-099Ensure 'Restrict Unauthenticated RPC clients' is set to 'Authenticated'.Registry key not found.False
Registry-100Set registry value 'fUseMailto' to .Compliant. Registry value not found.True
Registry-101Set registry value 'fAllowToGetHelp' to 0.Registry value not found.False
Registry-102Set registry value 'fAllowFullControl' to .Compliant. Registry value not found.True
Registry-103Set registry value 'MaxTicketExpiry' to .Compliant. Registry value not found.True
Registry-104Set registry value 'MaxTicketExpiryUnits' to .Compliant. Registry value not found.True
Registry-105Set registry value 'MinEncryptionLevel' to 3.Registry value not found.False
Registry-106Set registry value 'fPromptForPassword' to 1.Registry value not found.False
Registry-107Set registry value 'fDisableCdm' to 1.Registry value not found.False
Registry-108Set registry value 'DisablePasswordSaving' to 1.Registry value not found.False
Registry-109Set registry value 'fEncryptRPCTraffic' to 1.Registry value not found.False
Registry-110Set registry value 'PolicyVersion' to 538.Registry key not found.False
Registry-111Set registry value 'DefaultOutboundAction' to 0.Registry key not found.False
Registry-112Set registry value 'DisableNotifications' to 1.Registry key not found.False
Registry-113Set registry value 'EnableFirewall' to 1.Registry key not found.False
Registry-114Set registry value 'DefaultInboundAction' to 1.Registry key not found.False
Registry-115Set registry value 'LogDroppedPackets' to 1.Registry key not found.False
Registry-116Set registry value 'LogFileSize' to 16384.Registry key not found.False
Registry-117Set registry value 'LogSuccessfulConnections' to 1.Registry key not found.False
Registry-118Set registry value 'EnableFirewall' to 1.Registry key not found.False
Registry-119Set registry value 'DisableNotifications' to 1.Registry key not found.False
Registry-120Set registry value 'DefaultInboundAction' to 1.Registry key not found.False
Registry-121Set registry value 'DefaultOutboundAction' to 0.Registry key not found.False
Registry-122Set registry value 'LogSuccessfulConnections' to 1.Registry key not found.False
Registry-123Set registry value 'LogDroppedPackets' to 1.Registry key not found.False
Registry-124Set registry value 'LogFileSize' to 16384.Registry key not found.False
Registry-125Set registry value 'DefaultOutboundAction' to 0.Registry key not found.False
Registry-126Set registry value 'EnableFirewall' to 1.Registry key not found.False
Registry-127Set registry value 'DisableNotifications' to 1.Registry key not found.False
Registry-128Set registry value 'AllowLocalIPsecPolicyMerge' to 0.Registry key not found.False
Registry-129Set registry value 'AllowLocalPolicyMerge' to 0.Registry key not found.False
Registry-130Set registry value 'DefaultInboundAction' to 1.Registry key not found.False
Registry-131Set registry value 'LogFileSize' to 16384.Registry key not found.False
Registry-132Set registry value 'LogDroppedPackets' to 1.Registry key not found.False
Registry-133Set registry value 'LogSuccessfulConnections' to 1.Registry key not found.False
Registry-134Ensure 'Allow Windows Ink Workspace' is set to 'On, but disallow access above lock'.Registry key not found.False
Registry-135Set registry value 'AdmPwdEnabled' to 1.Registry key not found.False
Registry-136Ensure 'WDigest Authentication (disabling may require KB2871997)' is set to 'Disabled'.Registry value not found.False
Registry-137Ensure 'Enable Structured Exception Handling Overwrite Protection (SEHOP)' is set to 'Enabled'.Registry value not found.False
Registry-138Set registry value 'DriverLoadPolicy' to 3.Registry key not found.False
Registry-139Ensure 'Configure SMB v1 server' is set to 'Disabled'.Registry value not found.False
Registry-140Ensure 'Configure SMB v1 client driver' is set to 'Disable driver (recommended)'.Registry key not found.False
Registry-141Set registry value 'NoNameReleaseOnDemand' to 1.Registry value not found.False
Registry-142Set registry value 'NodeType' to 2.Registry value not found.False
Registry-143Set registry value 'EnableICMPRedirect' to 0.Registry value not found.False
Registry-144Set registry value 'DisableIPSourceRouting' to 2.Registry value not found.False
Registry-145Set registry value 'DisableIPSourceRouting' to 2.Registry value not found.False
Registry-146Set registry value 'ScRemoveOption' to 1.Registry value is '0'. Expected: 1False
Registry-147Set registry value 'InactivityTimeoutSecs' to 900.Registry value not found.False
Registry-148Set registry value 'NoLMHash' to 1.CompliantTrue
Registry-149Set registry value 'EnablePlainTextPassword' to 0.CompliantTrue
Registry-150Set registry value 'LimitBlankPasswordUse' to 1.CompliantTrue
Registry-151Set registry value 'RestrictAnonymousSAM' to 1.CompliantTrue
Registry-152Set registry value 'RestrictAnonymous' to 1.Registry value is '0'. Expected: 1False
Registry-153Set registry value 'RestrictNullSessAccess' to 1.CompliantTrue
Registry-154Set registry value 'SCENoApplyLegacyAuditPolicy' to 1.Registry value not found.False
Registry-155Set registry value 'NTLMMinClientSec' to 537395200.Registry value is '536870912'. Expected: 537395200False
Registry-156Set registry value 'LmCompatibilityLevel' to 5.Registry value not found.False
Registry-157Set registry value 'allownullsessionfallback' to 0.Registry value not found.False
Registry-158Set registry value 'NTLMMinServerSec' to 537395200.Registry value is '536870912'. Expected: 537395200False
Registry-159Set registry value 'requirestrongkey' to 1.CompliantTrue
Registry-160Set registry value 'RequireSecuritySignature' to 1.Registry value is '0'. Expected: 1False
Registry-161Set registry value 'sealsecurechannel' to 1.CompliantTrue
Registry-162Set registry value 'requiresignorseal' to 1.CompliantTrue
Registry-163Set registry value 'signsecurechannel' to 1.CompliantTrue
Registry-164Set registry value 'requiresecuritysignature' to 1.Registry value is '0'. Expected: 1False
Registry-165Set registry value 'ProtectionMode' to 1.CompliantTrue
Registry-166Set registry value 'ConsentPromptBehaviorAdmin' to 2.Registry value is '5'. Expected: 2False
Registry-167Set registry value 'EnableSecureUIAPaths' to 1.CompliantTrue
Registry-168Set registry value 'EnableLUA' to 1.CompliantTrue
Registry-169Set registry value 'ConsentPromptBehaviorUser' to 0.Registry value is '3'. Expected: 0False
Registry-170Set registry value 'EnableInstallerDetection' to 1.CompliantTrue
Registry-171Set registry value 'FilterAdministratorToken' to 1.Registry value not found.False
Registry-172Set registry value 'EnableVirtualization' to 1.CompliantTrue
Registry-173Set registry value 'LDAPClientIntegrity' to 1.CompliantTrue
Registry-174Remote calls to the Security Account Manager (SAM) must be restricted to Administrators.Registry value not found.False
Registry-222Set registry value 'FormSuggest Passwords' to 1.Registry key not found.False
Registry-223Ensure 'Turn on the auto-complete feature for user names and passwords on forms' is set to 'no'.Registry key not found.False
Registry-224Set registry value 'FormSuggest Passwords' to no.Registry key not found.False
Registry-225Ensure 'Remove "Run this time" button for outdated ActiveX controls in Internet Explorer ' is set to 'Enabled'.Registry value not found.False
Registry-226Ensure 'Turn off blocking of outdated ActiveX controls for Internet Explorer' is set to 'Disabled'.Registry value not found.False
Registry-227Ensure 'Allow software to run or install even if the signature is invalid' is set to 'Disabled'.Registry key not found.False
Registry-228Set registry value 'CheckExeSignatures' to yes.Registry key not found.False
Registry-229Ensure 'Turn on 64-bit tab processes when running in Enhanced Protected Mode on 64-bit versions of Windows' is set to 'Enabled'.Registry key not found.False
Registry-230Ensure 'Do not allow ActiveX controls to run in Protected Mode when Enhanced Protected Mode is enabled' is set to 'Enabled'.Registry key not found.False
Registry-231Set registry value 'Isolation' to PMEM.Registry key not found.False
Registry-232Set registry value '(Reserved)' to 1.Registry key not found.False
Registry-234Set registry value 'explorer.exe' to 1.Registry key not found.False
Registry-235Set registry value 'explorer.exe' to 1.Registry key not found.False
Registry-237Set registry value '(Reserved)' to 1.Registry key not found.False
Registry-238Set registry value 'explorer.exe' to 1.Registry key not found.False
Registry-240Set registry value '(Reserved)' to 1.Registry key not found.False
Registry-241Set registry value '(Reserved)' to 1.Registry key not found.False
Registry-242Set registry value 'explorer.exe' to 1.Registry key not found.False
Registry-244Set registry value '(Reserved)' to 1.Registry key not found.False
Registry-246Set registry value 'explorer.exe' to 1.Registry key not found.False
Registry-247Set registry value '(Reserved)' to 1.Registry key not found.False
Registry-249Set registry value 'explorer.exe' to 1.Registry key not found.False
Registry-251Set registry value '(Reserved)' to 1.Registry key not found.False
Registry-252Set registry value 'explorer.exe' to 1.Registry key not found.False
Registry-253Set registry value '(Reserved)' to 1.Registry key not found.False
Registry-254Set registry value 'explorer.exe' to 1.Registry key not found.False
Registry-255Set registry value 'iexplore.exe' to 1.Registry key not found.False
Registry-256Set registry value 'PreventOverrideAppRepUnknown' to 1.Registry key not found.False
Registry-257Set registry value 'PreventOverride' to 1.Registry key not found.False
Registry-258Ensure 'Prevent managing SmartScreen Filter' is set to 'On'.Registry key not found.False
Registry-259Set registry value 'NoCrashDetection' to 1.Registry key not found.False
Registry-260Ensure 'Turn off the Security Settings Check feature' is set to 'Disabled'.Registry key not found.False
Registry-261Ensure 'Prevent per-user installation of ActiveX controls' is set to 'Enabled'.Registry key not found.False
Registry-262Ensure 'Specify use of ActiveX Installer Service for installation of ActiveX controls' is set to 'Enabled'.Registry key not found.False
Registry-263Set registry value 'Security_zones_map_edit' to 1.Registry value not found.False
Registry-264Set registry value 'Security_options_edit' to 1.Registry value not found.False
Registry-265Set registry value 'Security_HKLM_only' to 1.Registry value not found.False
Registry-266Ensure 'Check for server certificate revocation' is set to 'Enabled'.Registry value not found.False
Registry-267Ensure 'Prevent ignoring certificate errors' is set to 'Enabled'.Registry value not found.False
Registry-268Set registry value 'WarnOnBadCertRecving' to 1.Registry value not found.False
Registry-269Ensure 'Allow fallback to SSL 3.0 (Internet Explorer)' is set to 'No Sites'.Registry value not found.False
Registry-270Ensure 'Turn off encryption support' is set to 'Use TLS 1.1 and TLS 1.2'.Registry value not found.False
Registry-271Ensure 'Java permissions' is set to 'Disable Java'.Registry key not found.False
Registry-272Ensure 'Java permissions' is set to 'Disable Java'.Registry key not found.False
Registry-273Ensure 'Java permissions' is set to 'Disable Java'.Registry key not found.False
Registry-274Ensure 'Turn on SmartScreen Filter scan' is set to 'Enable'.Registry key not found.False
Registry-275Ensure 'Turn on SmartScreen Filter scan' is set to 'Enable'.Registry key not found.False
Registry-276Ensure 'Java permissions' is set to 'Disable Java'.Registry key not found.False
Registry-277Ensure 'Intranet Sites: Include all network paths (UNCs)' is set to 'Disabled'.Registry key not found.False
Registry-278Ensure 'Java permissions' is set to 'Disable Java'.Registry key not found.False
Registry-279Ensure 'Don't run antimalware programs against ActiveX controls' is set to 'Disable'.Registry key not found.False
Registry-280Ensure 'Don't run antimalware programs against ActiveX controls' is set to 'Disable'.Registry key not found.False
Registry-281Ensure 'Initialize and script ActiveX controls not marked as safe' is set to 'Disable'.Registry key not found.False
Registry-282Ensure 'Java permissions' is set to 'High safety'.Registry key not found.False
Registry-283Ensure 'Java permissions' is set to 'High safety'.Registry key not found.False
Registry-284Ensure 'Don't run antimalware programs against ActiveX controls' is set to 'Disable'.Registry key not found.False
Registry-285Ensure 'Initialize and script ActiveX controls not marked as safe' is set to 'Disable'.Registry key not found.False
Registry-286Ensure 'Run .NET Framework-reliant components signed with Authenticode' is set to 'Disable'.Registry key not found.False
Registry-287Ensure 'Allow script-initiated windows without size or position constraints' is set to 'Disable'.Registry key not found.False
Registry-288Ensure 'Allow drag and drop or copy and paste files' is set to 'Disable'.Registry key not found.False
Registry-289Ensure 'Include local path when user is uploading files to a server' is set to 'Disable'.Registry key not found.False
Registry-290Ensure 'Initialize and script ActiveX controls not marked as safe' is set to 'Disable'.Registry key not found.False
Registry-291Ensure 'Access data sources across domains' is set to 'Disable'.Registry key not found.False
Registry-292Ensure 'Launching applications and files in an IFRAME' is set to 'Disable'.Registry key not found.False
Registry-293Ensure 'Automatic prompting for file downloads' is set to 'Disable'.Registry key not found.False
Registry-294Ensure 'Allow scriptlets' is set to 'Disable'.Registry key not found.False
Registry-295Ensure 'Allow scripting of Internet Explorer WebBrowser controls' is set to 'Disable'.Registry key not found.False
Registry-296Ensure 'Use Pop-up Blocker' is set to 'Enable'.Registry key not found.False
Registry-297Ensure 'Turn on Protected Mode' is set to 'Enable'.Registry key not found.False
Registry-298Ensure 'Allow updates to status bar via script' is set to 'Disable'.Registry key not found.False
Registry-299Ensure 'Userdata persistence' is set to 'Disable'.Registry key not found.False
Registry-300Ensure 'Allow loading of XAML files' is set to 'Disable'.Registry key not found.False
Registry-301Ensure 'Run .NET Framework-reliant components not signed with Authenticode' is set to 'Disable'.Registry key not found.False
Registry-302Ensure 'Java permissions' is set to 'Disable Java'.Registry key not found.False
Registry-303Ensure 'Download signed ActiveX controls' is set to 'Disable'.Registry key not found.False
Registry-304Ensure 'Logon options' is set to 'Prompt for user name and password'.Registry key not found.False
Registry-305Ensure 'Enable dragging of content from different domains within a window' is set to 'Disable'.Registry key not found.False
Registry-306Ensure 'Download unsigned ActiveX controls' is set to 'Disable'.Registry key not found.False
Registry-307Ensure 'Allow only approved domains to use ActiveX controls without prompt' is set to 'Enable'.Registry key not found.False
Registry-308Ensure 'Allow cut, copy or paste operations from the clipboard via script' is set to 'Disable'.Registry key not found.False
Registry-309Ensure 'Turn on Cross-Site Scripting Filter' is set to 'Enable'.Registry key not found.False
Registry-310Ensure 'Don't run antimalware programs against ActiveX controls' is set to 'Disable'.Registry key not found.False
Registry-311Ensure 'Navigate windows and frames across different domains' is set to 'Disable'.Registry key not found.False
Registry-312Ensure 'Enable dragging of content from different domains across windows' is set to 'Disable'.Registry key not found.False
Registry-313Ensure 'Web sites in less privileged Web content zones can navigate into this zone' is set to 'Disable'.Registry key not found.False
Registry-314Ensure 'Turn on SmartScreen Filter scan' is set to 'Enable'.Registry key not found.False
Registry-315Ensure 'Show security warning for potentially unsafe files' is set to 'Prompt'.Registry key not found.False
Registry-316Ensure 'Allow only approved domains to use the TDC ActiveX control' is set to 'Enable'.Registry key not found.False
Registry-317Set registry value '140C' to 3.Registry key not found.False
Registry-318Ensure 'Allow META REFRESH' is set to 'Disable'.Registry key not found.False
Registry-319Ensure 'Initialize and script ActiveX controls not marked as safe' is set to 'Disable'.Registry key not found.False
Registry-320Ensure 'Download signed ActiveX controls' is set to 'Disable'.Registry key not found.False
Registry-321Ensure 'Navigate windows and frames across different domains' is set to 'Disable'.Registry key not found.False
Registry-322Ensure 'Allow only approved domains to use ActiveX controls without prompt' is set to 'Enable'.Registry key not found.False
Registry-323Ensure 'Use Pop-up Blocker' is set to 'Enable'.Registry key not found.False
Registry-324Ensure 'Download unsigned ActiveX controls' is set to 'Disable'.Registry key not found.False
Registry-325Ensure 'Userdata persistence' is set to 'Disable'.Registry key not found.False
Registry-326Ensure 'Allow cut, copy or paste operations from the clipboard via script' is set to 'Disable'.Registry key not found.False
Registry-327Ensure 'Include local path when user is uploading files to a server' is set to 'Disable'.Registry key not found.False
Registry-328Ensure 'Access data sources across domains' is set to 'Disable'.Registry key not found.False
Registry-329Ensure 'Allow script-initiated windows without size or position constraints' is set to 'Disable'.Registry key not found.False
Registry-330Ensure 'Run .NET Framework-reliant components not signed with Authenticode' is set to 'Disable'.Registry key not found.False
Registry-331Ensure 'Automatic prompting for file downloads' is set to 'Disable'.Registry key not found.False
Registry-332Ensure 'Allow binary and script behaviors' is set to 'Disable'.Registry key not found.False
Registry-333Ensure 'Scripting of Java applets' is set to 'Disable'.Registry key not found.False
Registry-334Ensure 'Allow file downloads' is set to 'Disable'.Registry key not found.False
Registry-335Ensure 'Allow loading of XAML files' is set to 'Disable'.Registry key not found.False
Registry-336Ensure 'Allow active scripting' is set to 'Disable'.Registry key not found.False
Registry-337Ensure 'Logon options' is set to 'Anonymous logon'.Registry key not found.False
Registry-338Ensure 'Run .NET Framework-reliant components signed with Authenticode' is set to 'Disable'.Registry key not found.False
Registry-339Ensure 'Turn on Protected Mode' is set to 'Enable'.Registry key not found.False
Registry-340Ensure 'Turn on Cross-Site Scripting Filter' is set to 'Enable'.Registry key not found.False
Registry-341Ensure 'Java permissions' is set to 'Disable Java'.Registry key not found.False
Registry-342Ensure 'Allow scriptlets' is set to 'Disable'.Registry key not found.False
Registry-343Ensure 'Don't run antimalware programs against ActiveX controls' is set to 'Disable'.Registry key not found.False
Registry-344Ensure 'Allow scripting of Internet Explorer WebBrowser controls' is set to 'Disable'.Registry key not found.False
Registry-345Ensure 'Enable dragging of content from different domains within a window' is set to 'Disable'.Registry key not found.False
Registry-346Ensure 'Allow drag and drop or copy and paste files' is set to 'Disable'.Registry key not found.False
Registry-347Ensure 'Allow updates to status bar via script' is set to 'Disable'.Registry key not found.False
Registry-348Ensure 'Enable dragging of content from different domains across windows' is set to 'Disable'.Registry key not found.False
Registry-349Ensure 'Script ActiveX controls marked safe for scripting' is set to 'Disable'.Registry key not found.False
Registry-350Ensure 'Web sites in less privileged Web content zones can navigate into this zone' is set to 'Disable'.Registry key not found.False
Registry-351Ensure 'Turn on SmartScreen Filter scan' is set to 'Enable'.Registry key not found.False
Registry-352Ensure 'Run ActiveX controls and plugins' is set to 'Disable'.Registry key not found.False
Registry-353Ensure 'Launching applications and files in an IFRAME' is set to 'Disable'.Registry key not found.False
Registry-354Ensure 'Show security warning for potentially unsafe files' is set to 'Disable'.Registry key not found.False
Registry-355Ensure 'Allow only approved domains to use the TDC ActiveX control' is set to 'Enable'.Registry key not found.False
Registry-356Set registry value '140C' to 3.Registry key not found.False

User Rights Assignment-

IdTaskMessageStatus
UserRight-176Ensure 'SeSecurityPrivilege' is set to 'administrator'CompliantTrue
UserRight-177Ensure 'SeRestorePrivilege' is set to 'administrator'The user right 'SeRestorePrivilege' contains following unexpected users: BUILTIN\Backup OperatorsFalse
UserRight-178Ensure 'SeTakeOwnershipPrivilege' is set to 'administrator'CompliantTrue
UserRight-179Ensure 'SeBackupPrivilege' is set to 'administrator'The user right 'SeBackupPrivilege' contains following unexpected users: BUILTIN\Backup OperatorsFalse
UserRight-180Ensure 'SeDenyRemoteInteractiveLogonRight' is set to 'Local account'The user 'SeDenyRemoteInteractiveLogonRight' setting does not contain the following users: NT AUTHORITY\Local accountFalse
UserRight-181Ensure 'SeCreatePermanentPrivilege' is set to 'none'The user 'SeCreatePermanentPrivilege' setting does not contain the following users: NULL SIDFalse
UserRight-182Ensure 'SeManageVolumePrivilege' is set to 'administrator'CompliantTrue
UserRight-183Ensure 'SeLoadDriverPrivilege' is set to 'administrator'CompliantTrue
UserRight-184Ensure 'SeLockMemoryPrivilege' is set to 'none'CompliantTrue
UserRight-185Ensure 'SeDenyNetworkLogonRight' is set to 'Local account'The user right 'SeDenyNetworkLogonRight' contains following unexpected users: DESKTOP-EHK98K4\Guest The user 'SeDenyNetworkLogonRight' setting does not contain the following users: NT AUTHORITY\Local accountFalse
UserRight-186Ensure 'SeNetworkLogonRight' is set to 'administrator, Remote Desktop Users'The user right 'SeNetworkLogonRight' contains following unexpected users: Everyone, BUILTIN\Users, BUILTIN\Backup Operators The user 'SeNetworkLogonRight' setting does not contain the following users: BUILTIN\Remote Desktop UsersFalse
UserRight-187Ensure 'SeImpersonatePrivilege' is set to 'administrator, Service, Local Service, Network Service'The user right 'SeImpersonatePrivilege' contains following unexpected users: BUILTIN\IIS_IUSRSFalse
UserRight-188Ensure 'SeCreateTokenPrivilege' is set to 'none'The user 'SeCreateTokenPrivilege' setting does not contain the following users: NULL SIDFalse
UserRight-189Ensure 'SeCreateGlobalPrivilege' is set to 'administrator, Service, Local Service, Network Service'CompliantTrue
UserRight-190Ensure 'SeSystemEnvironmentPrivilege' is set to 'administrator'CompliantTrue
UserRight-191Ensure 'SeCreatePagefilePrivilege' is set to 'administrator'CompliantTrue
UserRight-192Ensure 'SeInteractiveLogonRight' is set to 'administrator, Users'The user right 'SeInteractiveLogonRight' contains following unexpected users: DESKTOP-EHK98K4\Guest, BUILTIN\Backup OperatorsFalse
UserRight-193Ensure 'SeRemoteShutdownPrivilege' is set to 'administrator'CompliantTrue
UserRight-194Ensure 'SeDebugPrivilege' is set to 'administrator'CompliantTrue
UserRight-195Ensure 'SeTrustedCredManAccessPrivilege' is set to 'none'The user 'SeTrustedCredManAccessPrivilege' setting does not contain the following users: NULL SIDFalse
UserRight-196Ensure 'SeProfileSingleProcessPrivilege' is set to 'administrator'CompliantTrue
UserRight-197Ensure 'SeTcbPrivilege' is set to 'none'The user 'SeTcbPrivilege' setting does not contain the following users: NULL SIDFalse
UserRight-198Ensure 'SeEnableDelegationPrivilege' is set to 'none'The user 'SeEnableDelegationPrivilege' setting does not contain the following users: NULL SIDFalse

Account Policies-

IdTaskMessageStatus
AccountPolicy-001Ensure 'MinimumPasswordLength' is set to '14'.'MinimumPasswordLength' currently set to: 0. Expected: 14False
AccountPolicy-002Ensure 'PasswordComplexity' is set to '1'.'PasswordComplexity' currently set to: 0. Expected: 1False
AccountPolicy-003Ensure 'PasswordHistorySize' is set to '24'.'PasswordHistorySize' currently set to: 0. Expected: 24False
AccountPolicy-004Ensure 'LockoutBadCount' is set to '10'.'LockoutBadCount' currently set to: 0. Expected: 10False
AccountPolicy-005Ensure 'ResetLockoutCount' is set to '15'.Currently not set.False
AccountPolicy-006Ensure 'LockoutDuration' is set to '15'.Currently not set.False
AccountPolicy-007Ensure 'ClearTextPassword' is set to '0'.CompliantTrue

Advanced Audit Policy Configuration-

IdTaskMessageStatus
AuditPolicy-199Ensure 'Credential Validation' is set to 'Success' and is set to 'Failure'.Set to: No AuditingFalse
AuditPolicy-200Ensure 'Security Group Management' is set to 'Success'.CompliantTrue
AuditPolicy-201Ensure 'User Account Management' is set to 'Success' and is set to 'Failure'.Set to: SuccessFalse
AuditPolicy-202Ensure 'Plug and Play Events' is set to 'Success'.Set to: No AuditingFalse
AuditPolicy-203Ensure 'Process Creation' is set to 'Success'.Set to: No AuditingFalse
AuditPolicy-204Ensure 'Account Lockout' is set to 'Failure'.Set to: SuccessFalse
AuditPolicy-205Ensure 'Group Membership' is set to 'Success'.Set to: No AuditingFalse
AuditPolicy-206Ensure 'Logon' is set to 'Success' and is set to 'Failure'.CompliantTrue
AuditPolicy-207Ensure 'Other Logon/Logoff Events' is set to 'Success' and is set to 'Failure'.Set to: No AuditingFalse
AuditPolicy-208Ensure 'Special Logon' is set to 'Success'.CompliantTrue
AuditPolicy-209Ensure 'Detailed File Share' is set to 'Failure'.Set to: No AuditingFalse
AuditPolicy-210Ensure 'File Share' is set to 'Success' and is set to 'Failure'.Set to: No AuditingFalse
AuditPolicy-211Ensure 'Other Object Access Events' is set to 'Success' and is set to 'Failure'.Set to: No AuditingFalse
AuditPolicy-212Ensure 'Removable Storage' is set to 'Success' and is set to 'Failure'.Set to: No AuditingFalse
AuditPolicy-213Ensure 'Audit Policy Change' is set to 'Success'.CompliantTrue
AuditPolicy-214Ensure 'Authentication Policy Change' is set to 'Success'.CompliantTrue
AuditPolicy-215Ensure 'MPSSVC Rule-Level Policy Change' is set to 'Success' and is set to 'Failure'.Set to: No AuditingFalse
AuditPolicy-216Ensure 'Other Policy Change Events' is set to 'Failure'.Set to: No AuditingFalse
AuditPolicy-217Ensure 'Sensitive Privilege Use' is set to 'Success' and is set to 'Failure'.Set to: No AuditingFalse
AuditPolicy-218Ensure 'Other System Events' is set to 'Success' and is set to 'Failure'.CompliantTrue
AuditPolicy-219Ensure 'Security State Change' is set to 'Success'.CompliantTrue
AuditPolicy-220Ensure 'Security System Extension' is set to 'Success'.Set to: No AuditingFalse
AuditPolicy-221Ensure 'System Integrity' is set to 'Success' and is set to 'Failure'.CompliantTrue