Microsoft Windows Server 2025 STIG SCAP Benchmark
Open a previous version of this SCAP benchmark.
- RMF Control
- Severity
- M
- CCI
- CCI-004910
- Version
- WN25-00-000090
- Vuln IDs
- V-277993
- Rule IDs
- SV-277993r1212171_rule
Fix: F-82428r1212170_fix
Ensure systems have a TPM that is configured for use. (Version 2.0 supports Credential Guard.) The TPM must be enabled in the firmware. Run "tpm.msc" for configuration options in Windows.
- RMF Control
- AC-3
- Severity
- H
- CCI
- CCI-000213
- Version
- WN25-00-000130
- Vuln IDs
- V-277997
- Rule IDs
- SV-277997r1268226_rule
Fix: F-82432r1180696_fix
Format volumes to use NTFS, ReFS, or CSVFS.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN25-00-000320
- Vuln IDs
- V-278015
- Rule IDs
- SV-278015r1180751_rule
Fix: F-82450r1180750_fix
Uninstall the "Fax Server" role. Start Server Manager. Select the server with the role. Scroll down to "ROLES AND FEATURES" in the right pane. Select "Remove Roles and Features" from the drop-down "TASKS" list. Select the appropriate server on the "Server Selection" page and click "Next". Deselect "Fax Server" on the "Roles" page. Click "Next" and "Remove" as prompted.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000382
- Version
- WN25-00-000330
- Vuln IDs
- V-278016
- Rule IDs
- SV-278016r1181795_rule
Fix: F-82451r1180753_fix
Uninstall the "FTP Server" role. Start Server Manager. Select the server with the role. Scroll down to "ROLES AND FEATURES" in the right pane. Select "Remove Roles and Features" from the drop-down "TASKS" list. Select the appropriate server on the "Server Selection" page and click "Next". Deselect "FTP Server" under "Web Server (IIS)" on the "Roles" page. Click "Next" and "Remove" as prompted.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000382
- Version
- WN25-00-000333
- Vuln IDs
- V-278018
- Rule IDs
- SV-278018r1180760_rule
Fix: F-82453r1180759_fix
Validate the site documentation to ensure the approval of use for Wi-Fi server connections. If the connection has not been approved, type "Services" in the Windows search bar. In the Services "Name " column, look for the "Bluetooth Support Service" and set this to "Disabled". Any Bluetooth devices listed or in use must be documented and approved by the information system security officer (ISSO) or authorizing official (AO).
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN25-00-000340
- Vuln IDs
- V-278019
- Rule IDs
- SV-278019r1180763_rule
Fix: F-82454r1180762_fix
Uninstall the "Peer Name Resolution Protocol" feature. Start Server Manager. Select the server with the feature. Scroll down to "ROLES AND FEATURES" in the right pane. Select "Remove Roles and Features" from the drop-down "TASKS" list. Select the appropriate server on the "Server Selection" page and click "Next". Deselect "Peer Name Resolution Protocol" on the "Features" page. Click "Next" and "Remove" as prompted.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN25-00-000350
- Vuln IDs
- V-278020
- Rule IDs
- SV-278020r1180766_rule
Fix: F-82455r1180765_fix
Uninstall the "Simple TCP/IP Services" feature. Start Server Manager. Select the server with the feature. Scroll down to "ROLES AND FEATURES" in the right pane. Select "Remove Roles and Features" from the drop-down "TASKS" list. Select the appropriate server on the "Server Selection" page and click "Next". Deselect "Simple TCP/IP Services" on the "Features" page. Click "Next" and "Remove" as prompted.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000382
- Version
- WN25-00-000360
- Vuln IDs
- V-278021
- Rule IDs
- SV-278021r1180769_rule
Fix: F-82456r1180768_fix
Uninstall the "Telnet Client" feature. Start Server Manager. Select the server with the feature. Scroll down to "ROLES AND FEATURES" in the right pane. Select "Remove Roles and Features" from the drop-down "TASKS" list. Select the appropriate server on the "Server Selection" page and click "Next". Deselect "Telnet Client" on the "Features" page. Click "Next" and "Remove" as prompted.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN25-00-000370
- Vuln IDs
- V-278022
- Rule IDs
- SV-278022r1180772_rule
Fix: F-82457r1180771_fix
Uninstall the "TFTP Client" feature. Start Server Manager. Select the server with the feature. Scroll down to "ROLES AND FEATURES" in the right pane. Select "Remove Roles and Features" from the drop-down "TASKS" list. Select the appropriate server on the "Server Selection" page and click "Next". Deselect "TFTP Client" on the "Features" page. Click "Next" and "Remove" as prompted.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN25-00-000380
- Vuln IDs
- V-278023
- Rule IDs
- SV-278023r1182034_rule
Fix: F-82458r1180774_fix
Uninstall the SMBv1 protocol. Open Windows PowerShell with elevated privileges (run as administrator). Enter "Uninstall-WindowsFeature -Name FS-SMB1 -Restart". (Omit the Restart parameter if an immediate restart of the system cannot be done.) Alternately: Start Server Manager. Select the server with the feature. Scroll down to "ROLES AND FEATURES" in the right pane. Select "Remove Roles and Features" from the drop-down "TASKS" list. Select the appropriate server on the "Server Selection" page and click "Next". Deselect "SMB 1.0/CIFS File Sharing Support" on the "Features" page. Click "Next" and "Remove" as prompted.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN25-00-000390
- Vuln IDs
- V-278024
- Rule IDs
- SV-278024r1182036_rule
Fix: F-82459r1182035_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> MS Security Guide >> Configure SMBv1 Server to "Disabled". Restart the system for the change to take effect. This policy setting requires the installation of the SecGuide custom templates included with the STIG package. "SecGuide.admx" and "SecGuide.adml" must be copied to the \Windows\PolicyDefinitions and \Windows\PolicyDefinitions\en-US directories respectively.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN25-00-000400
- Vuln IDs
- V-278025
- Rule IDs
- SV-278025r1182038_rule
Fix: F-82460r1182037_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> MS Security Guide >> Configure SMBv1 client driver to "Enabled" with "Disable driver (recommended)" selected for "Configure MrxSmb10 driver". Restart the system for the changes to take effect. This policy setting requires the installation of the SecGuide custom templates included with the STIG package. "SecGuide.admx" and "SecGuide.adml" must be copied to the \Windows\PolicyDefinitions and \Windows\PolicyDefinitions\en-US directories respectively.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN25-00-000410
- Vuln IDs
- V-278026
- Rule IDs
- SV-278026r1180784_rule
Fix: F-82461r1180783_fix
Uninstall the Windows PowerShell 2.0 Engine. Start Server Manager. Select the server with the feature. Scroll down to "ROLES AND FEATURES" in the right pane. Select "Remove Roles and Features" from the drop-down "TASKS" list. Select the appropriate server on the "Server Selection" page and click "Next". Deselect "Windows PowerShell 2.0 Engine" under "Windows PowerShell" on the "Features" page. Click "Next" and "Remove" as prompted.
- RMF Control
- AC-7
- Severity
- M
- CCI
- CCI-002238
- Version
- WN25-AC-000010
- Vuln IDs
- V-278033
- Rule IDs
- SV-278033r1180805_rule
Fix: F-82468r1180804_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Account Policies >> Account Lockout Policy. Set "Account lockout duration" to "15" minutes or greater. A value of "0" is also acceptable, requiring an administrator to unlock the account.
- RMF Control
- AC-7
- Severity
- M
- CCI
- CCI-000044
- Version
- WN25-AC-000020
- Vuln IDs
- V-278034
- Rule IDs
- SV-278034r1180808_rule
Fix: F-82469r1180807_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Account Policies >> Account Lockout Policy. Set "Account lockout threshold" to "3" or fewer invalid logon attempts (excluding "0", which is unacceptable).
- RMF Control
- AC-7
- Severity
- M
- CCI
- CCI-000044
- Version
- WN25-AC-000030
- Vuln IDs
- V-278035
- Rule IDs
- SV-278035r1180811_rule
Fix: F-82470r1180810_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Account Policies >> Account Lockout Policy. Set "Reset account lockout counter after" to at least "15" minutes.
- RMF Control
- Severity
- M
- CCI
- CCI-004061
- Version
- WN25-AC-000040
- Vuln IDs
- V-278036
- Rule IDs
- SV-278036r1256715_rule
Fix: F-82471r1180813_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Account Policies >> Password Policy. Set "Enforce password history" to "24" passwords remembered.
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- WN25-AC-000050
- Vuln IDs
- V-278037
- Rule IDs
- SV-278037r1268211_rule
Fix: F-82472r1266508_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Account Policies >> Password Policy. Set "Maximum password age" to "180" days or less (excluding "0", which is unacceptable).
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- WN25-AC-000060
- Vuln IDs
- V-278038
- Rule IDs
- SV-278038r1180820_rule
Fix: F-82473r1180819_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Account Policies >> Password Policy. Set "Minimum password age" to at least "1" day.
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- WN25-AC-000080
- Vuln IDs
- V-278039
- Rule IDs
- SV-278039r1180823_rule
Fix: F-82474r1180822_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Account Policies >> Password Policy. Set the value for "Password must meet complexity requirements" to "Enabled".
- RMF Control
- Severity
- H
- CCI
- CCI-004062
- Version
- WN25-AC-000090
- Vuln IDs
- V-278040
- Rule IDs
- SV-278040r1180826_rule
Fix: F-82475r1180825_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Account Policies >> Password Policy. Set "Store passwords using reversible encryption" to "Disabled".
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-000162
- Version
- WN25-AU-000030
- Vuln IDs
- V-278043
- Rule IDs
- SV-278043r1180835_rule
Fix: F-82478r1180834_fix
Configure the permissions on the Application event log file (Application.evtx) to prevent access by nonprivileged accounts. The default permissions listed below satisfy this requirement: Eventlog - Full Control SYSTEM - Full Control Administrators - Full Control The default location is the "%SystemRoot%\System32\winevt\Logs" folder. If the location of the logs has been changed, when adding Eventlog to the permissions, it must be entered as "NT Service\Eventlog".
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-000162
- Version
- WN25-AU-000040
- Vuln IDs
- V-278044
- Rule IDs
- SV-278044r1182051_rule
Fix: F-82479r1180837_fix
Configure the permissions on the Security event log file (Security.evtx) to prevent access by nonprivileged accounts. The default permissions listed below satisfy this requirement: Eventlog - Full Control SYSTEM - Full Control Administrators - Full Control The default location is the "%SystemRoot%\System32\winevt\Logs" folder. If the location of the logs has been changed, when adding Eventlog to the permissions, it must be entered as "NT Service\Eventlog".
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-000162
- Version
- WN25-AU-000050
- Vuln IDs
- V-278045
- Rule IDs
- SV-278045r1180841_rule
Fix: F-82480r1180840_fix
Configure the permissions on the System event log file (System.evtx) to prevent access by nonprivileged accounts. The default permissions listed below satisfy this requirement: Eventlog - Full Control SYSTEM - Full Control Administrators - Full Control The default location is the "%SystemRoot%\System32\winevt\Logs" folder. If the location of the logs has been changed, when adding Eventlog to the permissions, it must be entered as "NT Service\Eventlog".
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-001494
- Version
- WN25-AU-000060
- Vuln IDs
- V-278046
- Rule IDs
- SV-278046r1211151_rule
Fix: F-82481r1180843_fix
Configure the permissions on the "Eventvwr.exe" file to prevent modification by any groups or accounts other than TrustedInstaller. The default permissions listed below satisfy this requirement: TrustedInstaller - Full Control Administrators, SYSTEM, Users, ALL APPLICATION PACKAGES, ALL RESTRICTED APPLICATION PACKAGES - Read & Execute The default location is the "%SystemRoot%\System32" folder.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-AU-000070
- Vuln IDs
- V-278047
- Rule IDs
- SV-278047r1180847_rule
Fix: F-82482r1180846_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Account Logon >> Audit Credential Validation with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-AU-000080
- Vuln IDs
- V-278048
- Rule IDs
- SV-278048r1180850_rule
Fix: F-82483r1180849_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Account Logon >> Audit Credential Validation with "Failure" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-AU-000090
- Vuln IDs
- V-278049
- Rule IDs
- SV-278049r1180853_rule
Fix: F-82484r1180852_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Account Management >> Audit Other Account Management Events with "Success" selected.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-000018
- Version
- WN25-AU-000100
- Vuln IDs
- V-278050
- Rule IDs
- SV-278050r1180856_rule
Fix: F-82485r1180855_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Account Management >> Audit Security Group Management with "Success" selected.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-000018
- Version
- WN25-AU-000110
- Vuln IDs
- V-278051
- Rule IDs
- SV-278051r1180859_rule
Fix: F-82486r1180858_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Account Management >> Audit User Account Management with "Success" selected.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-000018
- Version
- WN25-AU-000120
- Vuln IDs
- V-278052
- Rule IDs
- SV-278052r1180862_rule
Fix: F-82487r1180861_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Account Management >> Audit User Account Management with "Failure" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-AU-000130
- Vuln IDs
- V-278053
- Rule IDs
- SV-278053r1180865_rule
Fix: F-82488r1180864_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Detailed Tracking >> Audit PNP Activity with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-AU-000140
- Vuln IDs
- V-278054
- Rule IDs
- SV-278054r1180868_rule
Fix: F-82489r1180867_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Detailed Tracking >> Audit Process Creation with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-AU-000150
- Vuln IDs
- V-278055
- Rule IDs
- SV-278055r1180871_rule
Fix: F-82490r1180870_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Logon/Logoff >> Audit Account Lockout with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-AU-000160
- Vuln IDs
- V-278056
- Rule IDs
- SV-278056r1180874_rule
Fix: F-82491r1180873_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Logon/Logoff >> Audit Account Lockout with "Failure" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-AU-000170
- Vuln IDs
- V-278057
- Rule IDs
- SV-278057r1180877_rule
Fix: F-82492r1180876_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Logon/Logoff >> Audit Group Membership with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-AU-000180
- Vuln IDs
- V-278058
- Rule IDs
- SV-278058r1180880_rule
Fix: F-82493r1180879_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Logon/Logoff >> Audit Logoff with "Success" selected.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000067
- Version
- WN25-AU-000190
- Vuln IDs
- V-278059
- Rule IDs
- SV-278059r1268219_rule
Fix: F-82494r1180882_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Logon/Logoff >> Audit Logon with "Success" selected.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000067
- Version
- WN25-AU-000200
- Vuln IDs
- V-278060
- Rule IDs
- SV-278060r1268219_rule
Fix: F-82495r1180885_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Logon/Logoff >> Audit Logon with "Failure" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-AU-000210
- Vuln IDs
- V-278061
- Rule IDs
- SV-278061r1180889_rule
Fix: F-82496r1180888_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Logon/Logoff >> Audit Special Logon with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-AU-000220
- Vuln IDs
- V-278062
- Rule IDs
- SV-278062r1180892_rule
Fix: F-82497r1180891_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Object Access >> Audit Other Object Access Events with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-AU-000230
- Vuln IDs
- V-278063
- Rule IDs
- SV-278063r1180895_rule
Fix: F-82498r1180894_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Object Access >> Audit Other Object Access Events with "Failure" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-AU-000240
- Vuln IDs
- V-278064
- Rule IDs
- SV-278064r1180898_rule
Fix: F-82499r1180897_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Object Access >> Audit Removable Storage with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-AU-000250
- Vuln IDs
- V-278065
- Rule IDs
- SV-278065r1180901_rule
Fix: F-82500r1180900_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Object Access >> Audit Removable Storage with "Failure" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-AU-000260
- Vuln IDs
- V-278066
- Rule IDs
- SV-278066r1180904_rule
Fix: F-82501r1180903_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Policy Change >> Audit Audit Policy Change with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-AU-000270
- Vuln IDs
- V-278067
- Rule IDs
- SV-278067r1180907_rule
Fix: F-82502r1180906_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Policy Change >> Audit Audit Policy Change with "Failure" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-AU-000280
- Vuln IDs
- V-278068
- Rule IDs
- SV-278068r1180910_rule
Fix: F-82503r1180909_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Policy Change >> Audit Authentication Policy Change with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-AU-000281
- Vuln IDs
- V-278069
- Rule IDs
- SV-278069r1180913_rule
Fix: F-82504r1180912_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Policy Change >> Audit Authorization Policy Change with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-AU-000300
- Vuln IDs
- V-278070
- Rule IDs
- SV-278070r1180916_rule
Fix: F-82505r1180915_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Privilege Use >> Audit Sensitive Privilege Use with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-AU-000310
- Vuln IDs
- V-278071
- Rule IDs
- SV-278071r1180919_rule
Fix: F-82506r1180918_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Privilege Use >> Audit Sensitive Privilege Use with "Failure" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-AU-000320
- Vuln IDs
- V-278072
- Rule IDs
- SV-278072r1180922_rule
Fix: F-82507r1180921_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> System >> Audit IPsec Driver with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-AU-000330
- Vuln IDs
- V-278073
- Rule IDs
- SV-278073r1180925_rule
Fix: F-82508r1180924_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> System >> Audit IPsec Driver with "Failure" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-AU-000340
- Vuln IDs
- V-278074
- Rule IDs
- SV-278074r1180928_rule
Fix: F-82509r1180927_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> System >> Audit Other System Events with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-AU-000350
- Vuln IDs
- V-278075
- Rule IDs
- SV-278075r1180931_rule
Fix: F-82510r1180930_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> System >> Audit Other System Events with "Failure" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-AU-000360
- Vuln IDs
- V-278076
- Rule IDs
- SV-278076r1180934_rule
Fix: F-82511r1180933_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> System >> Audit Security State Change with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-AU-000370
- Vuln IDs
- V-278077
- Rule IDs
- SV-278077r1180937_rule
Fix: F-82512r1180936_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> System >> Audit Security System Extension with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-AU-000380
- Vuln IDs
- V-278078
- Rule IDs
- SV-278078r1180940_rule
Fix: F-82513r1180939_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> System >> Audit System Integrity with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-AU-000390
- Vuln IDs
- V-278079
- Rule IDs
- SV-278079r1180943_rule
Fix: F-82514r1180942_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> System >> Audit System Integrity with "Failure" selected.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN25-CC-000010
- Vuln IDs
- V-278080
- Rule IDs
- SV-278080r1180946_rule
Fix: F-82515r1180945_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Control Panel >> Personalization >> Prevent enabling lock screen slide show to "Enabled".
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- WN25-CC-000030
- Vuln IDs
- V-278082
- Rule IDs
- SV-278082r1268251_rule
Fix: F-82517r1180951_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> MSS (Legacy) >> MSS: (DisableIPSourceRouting IPv6) IP source routing protection level (protects against packet spoofing) to "Enabled" with "Highest protection, source routing is completely disabled" selected. This policy setting requires the installation of the MSS-Legacy custom templates included with the STIG package. "MSS-Legacy.admx" and "MSS-Legacy.adml" must be copied to the \Windows\PolicyDefinitions and \Windows\PolicyDefinitions\en-US directories respectively.
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- WN25-CC-000040
- Vuln IDs
- V-278083
- Rule IDs
- SV-278083r1268251_rule
Fix: F-82518r1180954_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> MSS (Legacy) >> MSS: (DisableIPSourceRouting) IP source routing protection level (protects against packet spoofing) to "Enabled" with "Highest protection, source routing is completely disabled" selected. This policy setting requires the installation of the MSS-Legacy custom templates included with the STIG package. "MSS-Legacy.admx" and "MSS-Legacy.adml" must be copied to the \Windows\PolicyDefinitions and \Windows\PolicyDefinitions\en-US directories respectively.
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- WN25-CC-000050
- Vuln IDs
- V-278084
- Rule IDs
- SV-278084r1268251_rule
Fix: F-82519r1180957_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> MSS (Legacy) >> MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes to "Disabled". This policy setting requires the installation of the MSS-Legacy custom templates included with the STIG package. "MSS-Legacy.admx" and "MSS-Legacy.adml" must be copied to the \Windows\PolicyDefinitions and \Windows\PolicyDefinitions\en-US directories respectively.
- RMF Control
- SC-5
- Severity
- L
- CCI
- CCI-002385
- Version
- WN25-CC-000060
- Vuln IDs
- V-278085
- Rule IDs
- SV-278085r1180961_rule
Fix: F-82520r1180960_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> MSS (Legacy) >> MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers to "Enabled". This policy setting requires the installation of the MSS-Legacy custom templates included with the STIG package. "MSS-Legacy.admx" and "MSS-Legacy.adml" must be copied to the \Windows\PolicyDefinitions and \Windows\PolicyDefinitions\en-US directories respectively.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN25-CC-000070
- Vuln IDs
- V-278086
- Rule IDs
- SV-278086r1268251_rule
Fix: F-82521r1180963_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Network >> Lanman Workstation >> Enable insecure guest logons to "Disabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN25-CC-000080
- Vuln IDs
- V-278087
- Rule IDs
- SV-278087r1268251_rule
Fix: F-82522r1181927_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Network >> Network Provider >> Hardened UNC Paths" to "Enabled" with at least the following configured in "Hardened UNC Paths" (click "Show" to display): Value Name: \\*\SYSVOL Value: RequireMutualAuthentication=1, RequireIntegrity=1 Value Name: \\*\NETLOGON Value: RequireMutualAuthentication=1, RequireIntegrity=1
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000135
- Version
- WN25-CC-000090
- Vuln IDs
- V-278088
- Rule IDs
- SV-278088r1180970_rule
Fix: F-82523r1180969_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> System >> Audit Process Creation >> Include command line in process creation events to "Enabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN25-CC-000100
- Vuln IDs
- V-278089
- Rule IDs
- SV-278089r1268251_rule
Fix: F-82524r1180972_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> System >> Credentials Delegation >> Remote host allows delegation of nonexportable credentials to "Enabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN25-CC-000130
- Vuln IDs
- V-278091
- Rule IDs
- SV-278091r1268251_rule
Fix: F-82526r1182243_fix
The default behavior is for Early Launch Antimalware - Boot-Start Driver Initialization policy to enforce "Good, unknown and bad but critical" (preventing "bad"). To correct this, or if a more secure setting is desired, configure the policy value for Computer Configuration >> Administrative Templates >> System >> Early Launch Antimalware >> Boot-Start Driver Initialization Policy to "Not Configured" or "Enabled" with any option other than "All" selected.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN25-CC-000140
- Vuln IDs
- V-278092
- Rule IDs
- SV-278092r1268251_rule
Fix: F-82527r1180981_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> System >> Group Policy >> Configure registry policy processing to "Enabled" with the option "Process even if the Group Policy objects have not changed" selected.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN25-CC-000150
- Vuln IDs
- V-278093
- Rule IDs
- SV-278093r1180985_rule
Fix: F-82528r1180984_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> System >> Internet Communication Management >> Internet Communication settings >> Turn off downloading of print drivers over HTTP to "Enabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN25-CC-000160
- Vuln IDs
- V-278094
- Rule IDs
- SV-278094r1180988_rule
Fix: F-82529r1180987_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> System >> Internet Communication Management >> Internet Communication settings >> Turn off printing over HTTP to "Enabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN25-CC-000170
- Vuln IDs
- V-278095
- Rule IDs
- SV-278095r1180991_rule
Fix: F-82530r1180990_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> System >> Logon >> Do not display network selection UI to "Enabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN25-CC-000180
- Vuln IDs
- V-278096
- Rule IDs
- SV-278096r1268251_rule
Fix: F-82531r1180993_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> System >> Power Management >> Sleep Settings >> Require a password when a computer wakes (on battery) to "Enabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN25-CC-000190
- Vuln IDs
- V-278097
- Rule IDs
- SV-278097r1268251_rule
Fix: F-82532r1180996_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> System >> Power Management >> Sleep Settings >> Require a password when a computer wakes (plugged in) to "Enabled".
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- WN25-CC-000200
- Vuln IDs
- V-278098
- Rule IDs
- SV-278098r1181000_rule
Fix: F-82533r1180999_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Application Compatibility >> Turn off Inventory Collector to "Enabled".
- RMF Control
- CM-7
- Severity
- H
- CCI
- CCI-001764
- Version
- WN25-CC-000210
- Vuln IDs
- V-278099
- Rule IDs
- SV-278099r1181003_rule
Fix: F-82534r1181002_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> AutoPlay Policies >> Disallow Autoplay for nonvolume devices to "Enabled".
- RMF Control
- CM-7
- Severity
- H
- CCI
- CCI-001764
- Version
- WN25-CC-000220
- Vuln IDs
- V-278100
- Rule IDs
- SV-278100r1181006_rule
Fix: F-82535r1181005_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> AutoPlay Policies >> Set the default behavior for AutoRun to "Enabled" with "Do not execute any autorun commands" selected.
- RMF Control
- CM-7
- Severity
- H
- CCI
- CCI-001764
- Version
- WN25-CC-000230
- Vuln IDs
- V-278101
- Rule IDs
- SV-278101r1181009_rule
Fix: F-82536r1181008_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> AutoPlay Policies >> Turn off AutoPlay to "Enabled" with "All Drives" selected.
- RMF Control
- SC-3
- Severity
- M
- CCI
- CCI-001084
- Version
- WN25-CC-000240
- Vuln IDs
- V-278102
- Rule IDs
- SV-278102r1181012_rule
Fix: F-82537r1181011_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Credential User Interface >> Enumerate administrator accounts on elevation to "Disabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN25-CC-000250
- Vuln IDs
- V-278103
- Rule IDs
- SV-278103r1268251_rule
Fix: F-82538r1181981_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Data Collection and Preview Build >> Allow Diagnostic Data to "Enabled" with "Send required diagnostic data" selected or "Diagnostic data off (not recommended)".
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- WN25-CC-000260
- Vuln IDs
- V-278104
- Rule IDs
- SV-278104r1268251_rule
Fix: F-82539r1181017_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Delivery Optimization >> Download Mode to "Enabled" with any option except "Internet" selected. Acceptable selections include: Bypass (100) Group (2) HTTP only (0) LAN (1) Simple (99)
- RMF Control
- AU-4
- Severity
- M
- CCI
- CCI-001849
- Version
- WN25-CC-000270
- Vuln IDs
- V-278105
- Rule IDs
- SV-278105r1181812_rule
Fix: F-82540r1181020_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Event Log Service >> Application >> Specify the maximum log file size (KB) to "Enabled" with a "Maximum Log Size (KB)" of "32768" or greater.
- RMF Control
- AU-4
- Severity
- M
- CCI
- CCI-001849
- Version
- WN25-CC-000280
- Vuln IDs
- V-278106
- Rule IDs
- SV-278106r1211154_rule
Fix: F-82541r1211153_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Event Log Service >> Security >> Specify the maximum log file size (KB) to "Enabled" with a "Maximum Log Size (KB)" of a value that will contain one week of audit records or greater. Note: The registry entry value in the Check is an example; the value must equal at least one week's worth of records in the environment.
- RMF Control
- AU-4
- Severity
- M
- CCI
- CCI-001849
- Version
- WN25-CC-000290
- Vuln IDs
- V-278107
- Rule IDs
- SV-278107r1181816_rule
Fix: F-82542r1181026_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Event Log Service >> System >> Specify the maximum log file size (KB) to "Enabled" with a "Maximum Log Size (KB)" of "32768" or greater.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN25-CC-000300
- Vuln IDs
- V-278108
- Rule IDs
- SV-278108r1181818_rule
Fix: F-82543r1181029_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> File Explorer >> Configure Windows Defender SmartScreen to "Enabled" with either option "Warn" or "Warn and prevent bypass" selected. Windows Server 2025 includes duplicate policies for this setting. It can also be configured under Computer Configuration >> Administrative Templates >> Windows Components >> Windows Defender SmartScreen >> Explorer.
- RMF Control
- SI-16
- Severity
- M
- CCI
- CCI-002824
- Version
- WN25-CC-000310
- Vuln IDs
- V-278109
- Rule IDs
- SV-278109r1182061_rule
Fix: F-82544r1182060_fix
The default behavior is for data execution prevention to be turned on for File Explorer. To correct this, configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> File Explorer >> Turn off Data Execution Prevention for Explorer to "Not Configured" or "Disabled".
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- WN25-CC-000320
- Vuln IDs
- V-278110
- Rule IDs
- SV-278110r1268251_rule
Fix: F-82545r1182062_fix
The default behavior is for File Explorer heap termination on corruption to be disabled. To correct this, configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> File Explorer >> Turn off heap termination on corruption to "Not Configured" or "Disabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN25-CC-000330
- Vuln IDs
- V-278111
- Rule IDs
- SV-278111r1268251_rule
Fix: F-82546r1182064_fix
The default behavior is for shell protected mode to be turned on for File Explorer. To correct this, configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> File Explorer >> Turn off shell protocol protected mode to "Not Configured" or "Disabled".
- RMF Control
- Severity
- M
- CCI
- CCI-004895
- Version
- WN25-CC-000340
- Vuln IDs
- V-278112
- Rule IDs
- SV-278112r1181042_rule
Fix: F-82547r1181041_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Remote Desktop Services >> Remote Desktop Connection Client >> Do not allow passwords to be saved to "Enabled".
- RMF Control
- SC-4
- Severity
- M
- CCI
- CCI-001090
- Version
- WN25-CC-000350
- Vuln IDs
- V-278113
- Rule IDs
- SV-278113r1268233_rule
Fix: F-82548r1181044_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Remote Desktop Services >> Remote Desktop Session Host >> Device and Resource Redirection >> Do not allow drive redirection to "Enabled".
- RMF Control
- Severity
- M
- CCI
- CCI-004895
- Version
- WN25-CC-000360
- Vuln IDs
- V-278114
- Rule IDs
- SV-278114r1181048_rule
Fix: F-82549r1181047_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Remote Desktop Services >> Remote Desktop Session Host >> Security >> Always prompt for password upon connection to "Enabled".
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000068
- Version
- WN25-CC-000370
- Vuln IDs
- V-278115
- Rule IDs
- SV-278115r1268222_rule
Fix: F-82550r1181050_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Remote Desktop Services >> Remote Desktop Session Host >> Security >> Require secure RPC communication to "Enabled".
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000068
- Version
- WN25-CC-000380
- Vuln IDs
- V-278116
- Rule IDs
- SV-278116r1268222_rule
Fix: F-82551r1181053_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Remote Desktop Services >> Remote Desktop Session Host >> Security >> Set client connection encryption level to "Enabled" with "High Level" selected.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN25-CC-000390
- Vuln IDs
- V-278117
- Rule IDs
- SV-278117r1268251_rule
Fix: F-82552r1181056_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> RSS Feeds >> Prevent downloading of enclosures to "Enabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN25-CC-000400
- Vuln IDs
- V-278118
- Rule IDs
- SV-278118r1182067_rule
Fix: F-82553r1182066_fix
The default behavior is for the Windows RSS platform to not use Basic authentication over HTTP connections. To correct this, configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> RSS Feeds >> Turn on Basic feed authentication over HTTP to "Not Configured" or "Disabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN25-CC-000410
- Vuln IDs
- V-278119
- Rule IDs
- SV-278119r1181063_rule
Fix: F-82554r1181062_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Search >> Allow indexing of encrypted files to "Disabled".
- RMF Control
- Severity
- M
- CCI
- CCI-003980
- Version
- WN25-CC-000420
- Vuln IDs
- V-278120
- Rule IDs
- SV-278120r1181066_rule
Fix: F-82555r1181065_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Windows Installer >> Allow user control over installs to "Disabled".
- RMF Control
- Severity
- H
- CCI
- CCI-003980
- Version
- WN25-CC-000430
- Vuln IDs
- V-278121
- Rule IDs
- SV-278121r1181069_rule
Fix: F-82556r1181068_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Windows Installer >> Always install with elevated privileges to "Disabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN25-CC-000440
- Vuln IDs
- V-278122
- Rule IDs
- SV-278122r1268251_rule
Fix: F-82557r1182068_fix
The default behavior is for Internet Explorer to warn users and select whether to allow or refuse installation when a web-based program attempts to install software on the system. To correct this, configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Windows Installer >> Prevent Internet Explorer security prompt for Windows Installer scripts to "Not Configured" or "Disabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN25-CC-000450
- Vuln IDs
- V-278123
- Rule IDs
- SV-278123r1181075_rule
Fix: F-82558r1181074_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Windows Logon Options >> Sign-in and lock last interactive user automatically after a restart to "Disabled".
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000135
- Version
- WN25-CC-000460
- Vuln IDs
- V-278124
- Rule IDs
- SV-278124r1181078_rule
Fix: F-82559r1181077_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Windows PowerShell >> Turn on PowerShell Script Block Logging to "Enabled".
- RMF Control
- MA-4
- Severity
- H
- CCI
- CCI-000877
- Version
- WN25-CC-000470
- Vuln IDs
- V-278125
- Rule IDs
- SV-278125r1181081_rule
Fix: F-82560r1181080_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Windows Remote Management (WinRM) >> WinRM Client >> Allow Basic authentication to "Disabled".
- RMF Control
- MA-4
- Severity
- M
- CCI
- CCI-002890
- Version
- WN25-CC-000480
- Vuln IDs
- V-278126
- Rule IDs
- SV-278126r1181084_rule
Fix: F-82561r1181083_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Windows Remote Management (WinRM) >> WinRM Client >> Allow unencrypted traffic to "Disabled".
- RMF Control
- MA-4
- Severity
- M
- CCI
- CCI-000877
- Version
- WN25-CC-000490
- Vuln IDs
- V-278127
- Rule IDs
- SV-278127r1181087_rule
Fix: F-82562r1181086_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Windows Remote Management (WinRM) >> WinRM Client >> Disallow Digest authentication to "Enabled".
- RMF Control
- MA-4
- Severity
- H
- CCI
- CCI-000877
- Version
- WN25-CC-000500
- Vuln IDs
- V-278128
- Rule IDs
- SV-278128r1181090_rule
Fix: F-82563r1181089_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Windows Remote Management (WinRM) >> WinRM Service >> Allow Basic authentication to "Disabled".
- RMF Control
- MA-4
- Severity
- M
- CCI
- CCI-002890
- Version
- WN25-CC-000510
- Vuln IDs
- V-278129
- Rule IDs
- SV-278129r1181093_rule
Fix: F-82564r1181092_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Windows Remote Management (WinRM) >> WinRM Service >> Allow unencrypted traffic to "Disabled".
- RMF Control
- Severity
- M
- CCI
- CCI-004895
- Version
- WN25-CC-000520
- Vuln IDs
- V-278130
- Rule IDs
- SV-278130r1181925_rule
Fix: F-82565r1181095_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Windows Remote Management (WinRM) >> WinRM Service >> Disallow WinRM from storing RunAs credentials to "Enabled".
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-001941
- Version
- WN25-DC-000020
- Vuln IDs
- V-278133
- Rule IDs
- SV-278133r1182071_rule
Fix: F-82568r1181104_fix
Configure the policy value in the Default Domain Policy for Computer Configuration >> Policies >> Windows Settings >> Security Settings >> Account Policies >> Kerberos Policy >> Enforce user logon restrictions to "Enabled".
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-001941
- Version
- WN25-DC-000030
- Vuln IDs
- V-278134
- Rule IDs
- SV-278134r1182073_rule
Fix: F-82569r1181107_fix
Configure the policy value in the Default Domain Policy for Computer Configuration >> Policies >> Windows Settings >> Security Settings >> Account Policies >> Kerberos Policy >> Maximum lifetime for service ticket to a maximum of "600" minutes, but not "0", which equates to "Ticket doesn't expire".
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-001941
- Version
- WN25-DC-000040
- Vuln IDs
- V-278135
- Rule IDs
- SV-278135r1182075_rule
Fix: F-82570r1181110_fix
Configure the policy value in the Default Domain Policy for Computer Configuration >> Policies >> Windows Settings >> Security Settings >> Account Policies >> Kerberos Policy >> Maximum lifetime for user ticket to a maximum of "10" hours but not "0", which equates to "Ticket doesn't expire".
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-001941
- Version
- WN25-DC-000050
- Vuln IDs
- V-278136
- Rule IDs
- SV-278136r1182077_rule
Fix: F-82571r1181113_fix
Configure the policy value in the Default Domain Policy for Computer Configuration >> Policies >> Windows Settings >> Security Settings >> Account Policies >> Kerberos Policy >> Maximum lifetime for user ticket renewal to a maximum of "7" days or less.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-001941
- Version
- WN25-DC-000060
- Vuln IDs
- V-278137
- Rule IDs
- SV-278137r1182079_rule
Fix: F-82572r1181116_fix
Configure the policy value in the Default Domain Policy for Computer Configuration >> Windows Settings >> Security Settings >> Account Policies >> Kerberos Policy >> Maximum tolerance for computer clock synchronization to a maximum of "5" minutes or less.
- RMF Control
- AC-6
- Severity
- H
- CCI
- CCI-002235
- Version
- WN25-DC-000070
- Vuln IDs
- V-278138
- Rule IDs
- SV-278138r1182081_rule
Fix: F-82573r1181119_fix
Maintain the permissions on NTDS database and log files as follows: NT AUTHORITY\SYSTEM:(I)(F) BUILTIN\Administrators:(I)(F) (I) - permission inherited from parent container (F) - full access
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-000018
- Version
- WN25-DC-000230
- Vuln IDs
- V-278154
- Rule IDs
- SV-278154r1182114_rule
Fix: F-82589r1181167_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Account Management >> Audit Computer Account Management with Success selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-DC-000240
- Vuln IDs
- V-278155
- Rule IDs
- SV-278155r1182116_rule
Fix: F-82590r1181170_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> DS Access >> Directory Service Access with Success selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-DC-000250
- Vuln IDs
- V-278156
- Rule IDs
- SV-278156r1182118_rule
Fix: F-82591r1181173_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> DS Access >> Directory Service Access with "Failure" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-DC-000260
- Vuln IDs
- V-278157
- Rule IDs
- SV-278157r1182120_rule
Fix: F-82592r1181176_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> DS Access >> Directory Service Changes with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-DC-000270
- Vuln IDs
- V-278158
- Rule IDs
- SV-278158r1182122_rule
Fix: F-82593r1181179_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> DS Access >> Directory Service Changes with "Failure" selected.
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- WN25-DC-000320
- Vuln IDs
- V-278163
- Rule IDs
- SV-278163r1266515_rule
Fix: F-82598r1266514_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Domain controller: LDAP server signing requirements Enforcement to "Not Configured" or "Enabled". Note: For the Windows Server 2025 security policy "Domain controller: LDAP server signing requirements Enforcement", configuring the setting to "Not Configured" (Default) or "Enabled" results in the same behavior.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN25-DC-000330
- Vuln IDs
- V-278164
- Rule IDs
- SV-278164r1268251_rule
Fix: F-82599r1181197_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Domain controller: Refuse machine account password changes to "Disabled".
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- WN25-DC-000340
- Vuln IDs
- V-278165
- Rule IDs
- SV-278165r1268226_rule
Fix: F-82600r1181824_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Access this computer from the network to include only the following accounts or groups: - Administrators. - Authenticated Users. - Enterprise Domain Controllers.
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN25-DC-000350
- Vuln IDs
- V-278166
- Rule IDs
- SV-278166r1182138_rule
Fix: F-82601r1181827_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Add workstations to domain to include only the following accounts or groups: - Administrators.
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- WN25-DC-000360
- Vuln IDs
- V-278167
- Rule IDs
- SV-278167r1268226_rule
Fix: F-82602r1181830_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Allow log on through Remote Desktop Services to include only the following accounts or groups: - Administrators.
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- WN25-DC-000370
- Vuln IDs
- V-278168
- Rule IDs
- SV-278168r1268226_rule
Fix: F-82603r1181833_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Deny access to this computer from the network to include the following: - Guests Group.
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- WN25-DC-000380
- Vuln IDs
- V-278169
- Rule IDs
- SV-278169r1268226_rule
Fix: F-82604r1181836_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Deny log on as a batch job to include the following: - Guests Group.
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- WN25-DC-000390
- Vuln IDs
- V-278170
- Rule IDs
- SV-278170r1268226_rule
Fix: F-82605r1181215_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Deny log on as a service to include no entries (blank).
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- WN25-DC-000400
- Vuln IDs
- V-278171
- Rule IDs
- SV-278171r1268226_rule
Fix: F-82606r1181840_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Deny log on locally to include the following: - Guests Group.
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- WN25-DC-000406
- Vuln IDs
- V-278173
- Rule IDs
- SV-278173r1268226_rule
Fix: F-82608r1181931_fix
Configure the policy value for Computer Configuration >> Administrative Template >> System >> KDC >> Allow name-based strong mappings for certificates to "Enabled". The policy must contain exactly one certificate thumbprint per rule, with each rule represented as a tuple. Thumbprints must be unique and cannot be repeated in multiple rules. The sections of each tuple that are separated by semi-colons must be in the stated order, while the fields separated by commas can be in any order. The rules themselves are separated by new lines.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-002314
- Version
- WN25-DC-000410
- Vuln IDs
- V-278174
- Rule IDs
- SV-278174r1268238_rule
Fix: F-82609r1181845_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Deny log on through Remote Desktop Services to include the following: - Guests Group.
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN25-DC-000420
- Vuln IDs
- V-278175
- Rule IDs
- SV-278175r1182148_rule
Fix: F-82610r1181848_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Enable computer and user accounts to be trusted for delegation to include only the following accounts or groups: - Administrators.
- RMF Control
- SC-3
- Severity
- M
- CCI
- CCI-001084
- Version
- WN25-MS-000020
- Vuln IDs
- V-278178
- Rule IDs
- SV-278178r1182282_rule
Fix: F-82613r1181239_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> MS Security Guide >> Apply UAC restrictions to local accounts on network logons to "Enabled". This policy setting requires the installation of the SecGuide custom templates included with the STIG package. "SecGuide.admx" and " SecGuide.adml" must be copied to the \Windows\PolicyDefinitions and \Windows\PolicyDefinitions\en-US directories respectively.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- WN25-MS-000030
- Vuln IDs
- V-278179
- Rule IDs
- SV-278179r1182284_rule
Fix: F-82614r1181242_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> System >> Logon >> Enumerate local users on domain-joined computers to "Disabled".
- RMF Control
- IA-3
- Severity
- M
- CCI
- CCI-001967
- Version
- WN25-MS-000040
- Vuln IDs
- V-278180
- Rule IDs
- SV-278180r1182286_rule
Fix: F-82615r1181245_fix
Configure the policy value for Computer Configuration >> Administrative Templates >> System >> Remote Procedure Call >> Restrict Unauthenticated RPC clients to "Enabled" with "Authenticated" selected.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN25-MS-000050
- Vuln IDs
- V-278181
- Rule IDs
- SV-278181r1268251_rule
Fix: F-82616r1181248_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Interactive Logon: Number of previous logons to cache (in case Domain Controller is not available) to "4" logons or less.
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN25-MS-000060
- Vuln IDs
- V-278182
- Rule IDs
- SV-278182r1182290_rule
Fix: F-82617r1181251_fix
Navigate to the policy Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Network access: Restrict clients allowed to make remote calls to SAM. Select "Edit Security" to configure the "Security descriptor:". Add "Administrators" in "Group or user names:" if it is not already listed (this is the default). Select "Administrators" in "Group or user names:". Select "Allow" for "Remote Access" in "Permissions for "Administrators". Click "OK". The "Security descriptor:" must be populated with "O:BAG:BAD:(A;;RC;;;BA) for the policy to be enforced.
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- WN25-MS-000070
- Vuln IDs
- V-278183
- Rule IDs
- SV-278183r1268226_rule
Fix: F-82618r1181859_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Access this computer from the network to include only the following accounts or groups: - Administrators. - Authenticated Users.
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- WN25-MS-000080
- Vuln IDs
- V-278184
- Rule IDs
- SV-278184r1268226_rule
Fix: F-82619r1181257_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Deny access to this computer from the network to include the following: Domain Systems Only: - Enterprise Admins group. - Domain Admins group. - "Local account and member of Administrators group" or "Local account" (see Note below). All Systems: - Guests group. Note: These are built-in security groups. "Local account" is more restrictive but may cause issues on servers such as systems that provide failover clustering.
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- WN25-MS-000090
- Vuln IDs
- V-278185
- Rule IDs
- SV-278185r1268226_rule
Fix: F-82620r1181260_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Deny log on as a batch job to include the following: Domain Systems Only: - Enterprise Admins Group. - Domain Admins Group. All Systems: - Guests Group.
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- WN25-MS-000100
- Vuln IDs
- V-278186
- Rule IDs
- SV-278186r1268226_rule
Fix: F-82621r1182298_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Deny log on as a service to include the following: Domain systems: - Enterprise Admins Group. - Domain Admins Group.
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- WN25-MS-000110
- Vuln IDs
- V-278187
- Rule IDs
- SV-278187r1268226_rule
Fix: F-82622r1181266_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Deny log on locally to include the following: Domain Systems Only: - Enterprise Admins Group. - Domain Admins Group. All Systems: - Guests Group.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-002314
- Version
- WN25-MS-000120
- Vuln IDs
- V-278188
- Rule IDs
- SV-278188r1268238_rule
Fix: F-82623r1181269_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Deny log on through Remote Desktop Services to include the following: Domain Systems Only: - Enterprise Admins group. - Domain Admins group. - Local account (see Note below). All Systems: - Guests group. Note: "Local account" refers to the Windows built-in security group.
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN25-MS-000130
- Vuln IDs
- V-278189
- Rule IDs
- SV-278189r1182305_rule
Fix: F-82624r1181272_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Enable computer and user accounts to be trusted for delegation to be defined but containing no entries (blank).
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000185
- Version
- WN25-PK-000010
- Vuln IDs
- V-278192
- Rule IDs
- SV-278192r1256723_rule
Fix: F-82627r1256722_fix
Install valid and unexpired DoW Root CA certificates. DOD Root CA 3 DOD Root CA 5 DOD Root CA 6 The InstallRoot tool is available on Cyber Exchange at https://cyber.mil/pki-pke/tools-configuration-files. Certificate bundles published by the PKI can be found at https://crl.gds.disa.mil/.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000185
- Version
- WN25-PK-000020
- Vuln IDs
- V-278193
- Rule IDs
- SV-278193r1256726_rule
Fix: F-82628r1256725_fix
Install valid and unexpired DoW Interoperability Root CA cross-certificates on unclassified systems. The list below is not to be treated as exhaustive. The STIG should not be used as a definitive resource for the organizationally approved certificates for the systems. DoD Interoperability Root CA 2 Administrators must run the Federal Bridge Certification Authority (FBCA) Cross-Certificate Removal Tool once as an administrator and once as the current user. The FBCA Cross-Certificate Remover Tool and User Guide are available on Cyber Exchange at https://cyber.mil/pki-pke/tools-configuration-files. Certificate bundles published by the PKI can be found at https://crl.gds.disa.mil/.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000185
- Version
- WN25-PK-000030
- Vuln IDs
- V-278194
- Rule IDs
- SV-278194r1256729_rule
Fix: F-82629r1256728_fix
Install valid and unexpired US DoW CCEB Interoperability Root CA cross-certificate on unclassified systems. The list below is not to be treated as exhaustive. The STIG should not be used as a definitive resource for the organizationally approved certificates for the systems. US DOD CCEB Interoperability Root CA 2 Administrators must run the Federal Bridge Certification Authority (FBCA) Cross-Certificate Removal Tool once as an administrator and once as the current user. The FBCA Cross-Certificate Remover Tool and User Guide are available on Cyber Exchange at https://cyber.mil/pki-pke/tools-configuration-files. Certificate bundles published by the PKI can be found at https://crl.gds.disa.mil/.
- RMF Control
- IA-8
- Severity
- M
- CCI
- CCI-000804
- Version
- WN25-SO-000010
- Vuln IDs
- V-278195
- Rule IDs
- SV-278195r1181291_rule
Fix: F-82630r1181290_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Accounts: Guest account status to "Disabled".
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000366
- Version
- WN25-SO-000020
- Vuln IDs
- V-278196
- Rule IDs
- SV-278196r1268251_rule
Fix: F-82631r1181293_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Accounts: Limit local account use of blank passwords to console logon only to "Enabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN25-SO-000030
- Vuln IDs
- V-278197
- Rule IDs
- SV-278197r1268251_rule
Fix: F-82632r1181296_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Accounts: Rename administrator account to a name other than "Administrator".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN25-SO-000040
- Vuln IDs
- V-278198
- Rule IDs
- SV-278198r1268251_rule
Fix: F-82633r1181299_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Accounts: Rename guest account to a name other than "Guest".
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000169
- Version
- WN25-SO-000050
- Vuln IDs
- V-278199
- Rule IDs
- SV-278199r1268225_rule
Fix: F-82634r1181302_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Audit: Force audit policy subcategory settings (Windows 7 or later) to override audit policy category settings to "Enabled".
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- WN25-SO-000060
- Vuln IDs
- V-278200
- Rule IDs
- SV-278200r1181306_rule
Fix: F-82635r1181305_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Domain member: Digitally encrypt or sign secure channel data (always) to "Enabled".
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- WN25-SO-000070
- Vuln IDs
- V-278201
- Rule IDs
- SV-278201r1181309_rule
Fix: F-82636r1181308_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Domain member: Digitally encrypt secure channel data (when possible) to "Enabled".
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- WN25-SO-000080
- Vuln IDs
- V-278202
- Rule IDs
- SV-278202r1181312_rule
Fix: F-82637r1181311_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Domain member: Digitally sign secure channel data (when possible) to "Enabled".
- RMF Control
- IA-3
- Severity
- M
- CCI
- CCI-001967
- Version
- WN25-SO-000090
- Vuln IDs
- V-278203
- Rule IDs
- SV-278203r1181315_rule
Fix: F-82638r1181314_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Domain member: Disable machine account password changes to "Disabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN25-SO-000100
- Vuln IDs
- V-278204
- Rule IDs
- SV-278204r1268251_rule
Fix: F-82639r1181317_fix
This is the default configuration for this setting (30 days). Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Domain member: Maximum machine account password age to "30" or less (excluding "0", which is unacceptable).
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- WN25-SO-000110
- Vuln IDs
- V-278205
- Rule IDs
- SV-278205r1181321_rule
Fix: F-82640r1181320_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Domain member: Require strong (Windows 2000 or Later) session key to "Enabled".
- RMF Control
- AC-11
- Severity
- M
- CCI
- CCI-000056
- Version
- WN25-SO-000120
- Vuln IDs
- V-278206
- Rule IDs
- SV-278206r1181324_rule
Fix: F-82641r1181323_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Interactive logon: Machine inactivity limit to "900" seconds or less, excluding "0", which is effectively disabled.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN25-SO-000150
- Vuln IDs
- V-278209
- Rule IDs
- SV-278209r1268251_rule
Fix: F-82644r1181332_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Interactive logon: Smart card removal behavior to "Lock Workstation" or "Force Logoff".
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- WN25-SO-000160
- Vuln IDs
- V-278210
- Rule IDs
- SV-278210r1181336_rule
Fix: F-82645r1181335_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Microsoft network client: Digitally sign communications (always) to "Enabled".
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- WN25-SO-000170
- Vuln IDs
- V-278211
- Rule IDs
- SV-278211r1181339_rule
Fix: F-82646r1181338_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Microsoft network client: Digitally sign communications (if server agrees) to "Enabled".
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000197
- Version
- WN25-SO-000180
- Vuln IDs
- V-278212
- Rule IDs
- SV-278212r1181342_rule
Fix: F-82647r1181341_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Microsoft Network Client: Send unencrypted password to third-party SMB servers to "Disabled".
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- WN25-SO-000190
- Vuln IDs
- V-278213
- Rule IDs
- SV-278213r1181345_rule
Fix: F-82648r1181344_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Microsoft network server: Digitally sign communications (always) to "Enabled".
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- WN25-SO-000200
- Vuln IDs
- V-278214
- Rule IDs
- SV-278214r1181348_rule
Fix: F-82649r1181347_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Microsoft network server: Digitally sign communications (if client agrees) to "Enabled".
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000366
- Version
- WN25-SO-000210
- Vuln IDs
- V-278215
- Rule IDs
- SV-278215r1268251_rule
Fix: F-82650r1181350_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Network access: Allow anonymous SID/Name translation to "Disabled".
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000366
- Version
- WN25-SO-000220
- Vuln IDs
- V-278216
- Rule IDs
- SV-278216r1268251_rule
Fix: F-82651r1181353_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Network access: Do not allow anonymous enumeration of SAM accounts to "Enabled".
- RMF Control
- SC-4
- Severity
- H
- CCI
- CCI-001090
- Version
- WN25-SO-000230
- Vuln IDs
- V-278217
- Rule IDs
- SV-278217r1268233_rule
Fix: F-82652r1181356_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Network access: Do not allow anonymous enumeration of SAM accounts and shares to "Enabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN25-SO-000240
- Vuln IDs
- V-278218
- Rule IDs
- SV-278218r1268251_rule
Fix: F-82653r1181359_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Network access: Let Everyone permissions apply to anonymous users to "Disabled".
- RMF Control
- SC-4
- Severity
- H
- CCI
- CCI-001090
- Version
- WN25-SO-000250
- Vuln IDs
- V-278219
- Rule IDs
- SV-278219r1268233_rule
Fix: F-82654r1181362_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Network access: Restrict anonymous access to Named Pipes and Shares to "Enabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN25-SO-000260
- Vuln IDs
- V-278220
- Rule IDs
- SV-278220r1268251_rule
Fix: F-82655r1181365_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Network security: Allow Local System to use computer identity for NTLM to "Enabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN25-SO-000270
- Vuln IDs
- V-278221
- Rule IDs
- SV-278221r1268251_rule
Fix: F-82656r1181368_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Network security: Allow LocalSystem NULL session fallback to "Disabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN25-SO-000280
- Vuln IDs
- V-278222
- Rule IDs
- SV-278222r1268251_rule
Fix: F-82657r1181371_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Network security: Allow PKU2U authentication requests to this computer to use online identities to "Disabled".
- RMF Control
- IA-7
- Severity
- M
- CCI
- CCI-000803
- Version
- WN25-SO-000290
- Vuln IDs
- V-278223
- Rule IDs
- SV-278223r1268232_rule
Fix: F-82658r1181374_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Network security: Configure encryption types allowed for Kerberos to "Enabled" with only the following selected: AES128_HMAC_SHA1 AES256_HMAC_SHA1 Future encryption types Note: Organizations with domain controllers running earlier versions of Windows where RC4 encryption is enabled, which select "The other domain supports Kerberos AES Encryption" on domain trusts, may be required to allow client communication across the trust relationship.
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000366
- Version
- WN25-SO-000310
- Vuln IDs
- V-278225
- Rule IDs
- SV-278225r1268251_rule
Fix: F-82660r1181380_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Network security: LAN Manager authentication level to "Send NTLMv2 response only. Refuse LM & NTLM".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN25-SO-000320
- Vuln IDs
- V-278226
- Rule IDs
- SV-278226r1268251_rule
Fix: F-82661r1181383_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Network security: LDAP client signing requirements to "Negotiate signing" at a minimum.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN25-SO-000330
- Vuln IDs
- V-278227
- Rule IDs
- SV-278227r1268251_rule
Fix: F-82662r1181386_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Network security: Minimum session security for NTLM SSP based (including secure RPC) clients to "Require NTLMv2 session security" and "Require 128-bit encryption" (all options selected).
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN25-SO-000340
- Vuln IDs
- V-278228
- Rule IDs
- SV-278228r1268251_rule
Fix: F-82663r1181389_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> Network security: Minimum session security for NTLM SSP based (including secure RPC) servers to "Require NTLMv2 session security" and "Require 128-bit encryption" (all options selected).
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000186
- Version
- WN25-SO-000350
- Vuln IDs
- V-278229
- Rule IDs
- SV-278229r1181393_rule
Fix: F-82664r1181392_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> System cryptography: Force strong key protection for user keys stored on the computer to "User must enter a password each time they use a key".
- RMF Control
- SC-13
- Severity
- M
- CCI
- CCI-002450
- Version
- WN25-SO-000360
- Vuln IDs
- V-278230
- Rule IDs
- SV-278230r1181396_rule
Fix: F-82665r1181395_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing to "Enabled".
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- WN25-SO-000370
- Vuln IDs
- V-278231
- Rule IDs
- SV-278231r1268251_rule
Fix: F-82666r1181398_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> System objects: Strengthen default permissions of internal system objects (e.g., Symbolic Links) to "Enabled".
- RMF Control
- Severity
- M
- CCI
- CCI-004895
- Version
- WN25-SO-000380
- Vuln IDs
- V-278232
- Rule IDs
- SV-278232r1182191_rule
Fix: F-82667r1181401_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> User Account Control: Admin Approval Mode for the Built-in Administrator account to "Enabled".
- RMF Control
- SC-3
- Severity
- M
- CCI
- CCI-001084
- Version
- WN25-SO-000390
- Vuln IDs
- V-278233
- Rule IDs
- SV-278233r1182193_rule
Fix: F-82668r1181404_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> User Account Control: Allow UIAccess applications to prompt for elevation without using the secure desktop to "Disabled".
- RMF Control
- SC-3
- Severity
- M
- CCI
- CCI-001084
- Version
- WN25-SO-000400
- Vuln IDs
- V-278234
- Rule IDs
- SV-278234r1182195_rule
Fix: F-82669r1181407_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode to "Prompt for consent on the secure desktop". The more secure option for this setting, "Prompt for credentials on the secure desktop", would also be acceptable.
- RMF Control
- Severity
- M
- CCI
- CCI-004895
- Version
- WN25-SO-000410
- Vuln IDs
- V-278235
- Rule IDs
- SV-278235r1182197_rule
Fix: F-82670r1181410_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> User Account Control: Behavior of the elevation prompt for standard users to "Automatically deny elevation requests".
- RMF Control
- SC-3
- Severity
- M
- CCI
- CCI-001084
- Version
- WN25-SO-000420
- Vuln IDs
- V-278236
- Rule IDs
- SV-278236r1182199_rule
Fix: F-82671r1181413_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> User Account Control: Detect application installations and prompt for elevation to "Enabled".
- RMF Control
- SC-3
- Severity
- M
- CCI
- CCI-001084
- Version
- WN25-SO-000430
- Vuln IDs
- V-278237
- Rule IDs
- SV-278237r1182201_rule
Fix: F-82672r1181416_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> User Account Control: Only elevate UIAccess applications that are installed in secure locations to "Enabled".
- RMF Control
- Severity
- M
- CCI
- CCI-004895
- Version
- WN25-SO-000440
- Vuln IDs
- V-278238
- Rule IDs
- SV-278238r1182203_rule
Fix: F-82673r1181419_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> User Account Control: Run all administrators in Admin Approval Mode to "Enabled".
- RMF Control
- SC-3
- Severity
- M
- CCI
- CCI-001084
- Version
- WN25-SO-000450
- Vuln IDs
- V-278239
- Rule IDs
- SV-278239r1182205_rule
Fix: F-82674r1181422_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> User Account Control: Virtualize file and registry write failures to per-user locations to "Enabled".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN25-UC-000010
- Vuln IDs
- V-278240
- Rule IDs
- SV-278240r1268251_rule
Fix: F-82675r1266520_fix
The default behavior is for Windows to mark file attachments with their zone information. To correct this, for each user profile on the system configure the policy value for User Configuration >> Administrative Templates >> Windows Components >> Attachment Manager >> Do not preserve zone information in file attachments to "Not Configured" or "Disabled".
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN25-UR-000010
- Vuln IDs
- V-278241
- Rule IDs
- SV-278241r1182208_rule
Fix: F-82676r1181428_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Access Credential Manager as a trusted caller to be defined but containing no entries (blank).
- RMF Control
- AC-6
- Severity
- H
- CCI
- CCI-002235
- Version
- WN25-UR-000020
- Vuln IDs
- V-278242
- Rule IDs
- SV-278242r1182209_rule
Fix: F-82677r1181431_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Act as part of the operating system to be defined but containing no entries (blank).
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- WN25-UR-000030
- Vuln IDs
- V-278243
- Rule IDs
- SV-278243r1268226_rule
Fix: F-82678r1181867_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Allow log on locally to include only the following accounts or groups: - Administrators.
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN25-UR-000040
- Vuln IDs
- V-278244
- Rule IDs
- SV-278244r1182211_rule
Fix: F-82679r1181870_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Back up files and directories to include only the following accounts or groups: - Administrators.
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN25-UR-000050
- Vuln IDs
- V-278245
- Rule IDs
- SV-278245r1182212_rule
Fix: F-82680r1181873_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Create a pagefile to include only the following accounts or groups: - Administrators.
- RMF Control
- AC-6
- Severity
- H
- CCI
- CCI-002235
- Version
- WN25-UR-000060
- Vuln IDs
- V-278246
- Rule IDs
- SV-278246r1182213_rule
Fix: F-82681r1181443_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Create a token object to be defined but containing no entries (blank).
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN25-UR-000070
- Vuln IDs
- V-278247
- Rule IDs
- SV-278247r1182214_rule
Fix: F-82682r1181876_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Create global objects to include only the following accounts or groups: - Administrators. - Service. - Local Service. - Network Service.
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN25-UR-000080
- Vuln IDs
- V-278248
- Rule IDs
- SV-278248r1182215_rule
Fix: F-82683r1181449_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Create permanent shared objects to be defined but containing no entries (blank).
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN25-UR-000090
- Vuln IDs
- V-278249
- Rule IDs
- SV-278249r1182217_rule
Fix: F-82684r1182216_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Create symbolic links to include only the following accounts or groups: - Administrators. Systems that have the Hyper-V role will also have "Virtual Machines" given this user right. To add this manually, enter it as "NT Virtual Machine\Virtual Machines".
- RMF Control
- AC-6
- Severity
- H
- CCI
- CCI-002235
- Version
- WN25-UR-000100
- Vuln IDs
- V-278250
- Rule IDs
- SV-278250r1182218_rule
Fix: F-82685r1181883_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Debug programs to include only the following accounts or groups: - Administrators.
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN25-UR-000110
- Vuln IDs
- V-278251
- Rule IDs
- SV-278251r1182219_rule
Fix: F-82686r1181886_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Force shutdown from a remote system to include only the following accounts or groups: - Administrators.
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN25-UR-000120
- Vuln IDs
- V-278252
- Rule IDs
- SV-278252r1182220_rule
Fix: F-82687r1181889_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Generate security audits to include only the following accounts or groups: - Local Service. - Network Service.
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN25-UR-000130
- Vuln IDs
- V-278253
- Rule IDs
- SV-278253r1182221_rule
Fix: F-82688r1181892_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Impersonate a client after authentication to include only the following accounts or groups: - Administrators. - Service. - Local Service. - Network Service.
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN25-UR-000140
- Vuln IDs
- V-278254
- Rule IDs
- SV-278254r1182222_rule
Fix: F-82689r1181895_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Increase scheduling priority to include only the following accounts or groups: - Administrators.
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN25-UR-000150
- Vuln IDs
- V-278255
- Rule IDs
- SV-278255r1182223_rule
Fix: F-82690r1181898_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Load and unload device drivers to include only the following accounts or groups: - Administrators.
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN25-UR-000160
- Vuln IDs
- V-278256
- Rule IDs
- SV-278256r1182224_rule
Fix: F-82691r1181473_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Lock pages in memory to be defined but containing no entries (blank).
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-000162
- Version
- WN25-UR-000170
- Vuln IDs
- V-278257
- Rule IDs
- SV-278257r1182225_rule
Fix: F-82692r1181902_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Manage auditing and security log to include only the following accounts or groups: - Administrators.
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN25-UR-000180
- Vuln IDs
- V-278258
- Rule IDs
- SV-278258r1182226_rule
Fix: F-82693r1181905_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Modify firmware environment values to include only the following accounts or groups: - Administrators.
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN25-UR-000190
- Vuln IDs
- V-278259
- Rule IDs
- SV-278259r1182227_rule
Fix: F-82694r1181908_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Perform volume maintenance tasks to include only the following accounts or groups: - Administrators.
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN25-UR-000200
- Vuln IDs
- V-278260
- Rule IDs
- SV-278260r1182228_rule
Fix: F-82695r1181911_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Profile single process to include only the following accounts or groups: - Administrators.
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN25-UR-000210
- Vuln IDs
- V-278261
- Rule IDs
- SV-278261r1182229_rule
Fix: F-82696r1181914_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Restore files and directories to include only the following accounts or groups: - Administrators.
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002235
- Version
- WN25-UR-000220
- Vuln IDs
- V-278262
- Rule IDs
- SV-278262r1182230_rule
Fix: F-82697r1181917_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> User Rights Assignment >> Take ownership of files or other objects to include only the following accounts or groups: - Administrators.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-AU-000583
- Vuln IDs
- V-279918
- Rule IDs
- SV-279918r1268225_rule
Fix: F-84383r1181959_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Object Access >> "Audit Handle Manipulation" with "Failure" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-AU-000585
- Vuln IDs
- V-279920
- Rule IDs
- SV-279920r1268225_rule
Fix: F-84385r1181965_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Object Access >> "Audit Registry" with "Failure" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-AU-000586
- Vuln IDs
- V-279921
- Rule IDs
- SV-279921r1268225_rule
Fix: F-84386r1181968_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Object Access >> "Audit Registry" with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-AU-000587
- Vuln IDs
- V-279922
- Rule IDs
- SV-279922r1268225_rule
Fix: F-84387r1181971_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Privilege Use >> Audit Sensitive Privilege Use with "Success" selected.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- WN25-AU-000588
- Vuln IDs
- V-279923
- Rule IDs
- SV-279923r1268225_rule
Fix: F-84388r1181974_fix
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Advanced Audit Policy Configuration >> System Audit Policies >> Privilege Use >> Audit Sensitive Privilege Use with "Failure" selected.
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- WN25-SH-000010
- Vuln IDs
- V-285313
- Rule IDs
- SV-285313r1211167_rule
Fix: F-89788r1211166_fix
To install and start the OpenSSH service, run the following commands: C:\ > Add-WindowsCapability -Online -Name OpenSSH.Server~~~~0.0.1.0 C:\ > Start-Service sshd C:\ > Set-Service -Name sshd -StartupType 'Automatic'
- RMF Control
- AC-8
- Severity
- M
- CCI
- CCI-000048
- Version
- WN25-SH-000020
- Vuln IDs
- V-285314
- Rule IDs
- SV-285314r1268215_rule
Fix: F-89789r1211169_fix
To configure the system, add or modify the following line in the "$env:ProgramData/ssh/sshd_config" file. An example configuration line is: Banner C:\ProgramData\ssh\Banner.txt Restart the OpenSSH service for the settings to take effect.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000765
- Version
- WN25-SH-000030
- Vuln IDs
- V-285315
- Rule IDs
- SV-285315r1268228_rule
Fix: F-89790r1211172_fix
To configure the system, add or modify the following line in the "$env:ProgramData/ssh/sshd_config" file: PubkeyAuthentication yes Restart the OpenSSH service for the settings to take effect.
- RMF Control
- IA-2
- Severity
- H
- CCI
- CCI-000766
- Version
- WN25-SH-000040
- Vuln IDs
- V-285316
- Rule IDs
- SV-285316r1268229_rule
Fix: F-89791r1211175_fix
To configure the system, add or modify the following line in the "$env:ProgramData/ssh/sshd_config" file: PermitEmptyPasswords no Restart the OpenSSH service for the settings to take effect.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000068
- Version
- WN25-SH-000050
- Vuln IDs
- V-285317
- Rule IDs
- SV-285317r1211179_rule
Fix: F-89792r1211178_fix
To configure the system, add or modify the following line in the "$env:ProgramData/ssh/sshd_config" file. An example configuration line is: RekeyLimit 1G 1h Restart the OpenSSH service for the settings to take effect.
- RMF Control
- SC-10
- Severity
- M
- CCI
- CCI-001133
- Version
- WN25-SH-000060
- Vuln IDs
- V-285318
- Rule IDs
- SV-285318r1211182_rule
Fix: F-89793r1211181_fix
To configure the system, add or modify the following line in the "$env:ProgramData/ssh/sshd_config" file: ClientAliveCountMax 1 Restart the OpenSSH service for the settings to take effect.
- RMF Control
- SC-10
- Severity
- M
- CCI
- CCI-001133
- Version
- WN25-SH-000070
- Vuln IDs
- V-285319
- Rule IDs
- SV-285319r1212174_rule
Fix: F-89794r1211184_fix
To configure the system, add or modify the following line in the "$env:ProgramData/ssh/sshd_config" file. ClientAliveInterval 600 Restart the OpenSSH service for the settings to take effect.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN25-SH-000080
- Vuln IDs
- V-285320
- Rule IDs
- SV-285320r1268251_rule
Fix: F-89795r1256735_fix
Maintain the permissions of the "$env:ProgramData/ssh/sshd_config" file as follows: NT AUTHORITY\SYSTEM:(F) BUILTIN\Administrators:(F) NT AUTHORITY\Authenticated Users:(RX)
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN25-SH-000090
- Vuln IDs
- V-285321
- Rule IDs
- SV-285321r1268251_rule
Fix: F-89796r1211190_fix
Maintain the permissions of the private host key files as follows: BUILTIN\Administrators:(F) NT AUTHORITY\SYSTEM:(F)
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- WN25-SH-000100
- Vuln IDs
- V-285322
- Rule IDs
- SV-285322r1268251_rule
Fix: F-89797r1211193_fix
Maintain the permissions of the public host key files as follows: BUILTIN\Administrators:(F) NT AUTHORITY\SYSTEM:(F)
- RMF Control
- CM-5
- Severity
- M
- CCI
- CCI-001813
- Version
- WN25-SH-000110
- Vuln IDs
- V-285323
- Rule IDs
- SV-285323r1211197_rule
Fix: F-89798r1211196_fix
To configure the system, add or modify the following line in the "$env:ProgramData/ssh/sshd_config" file: GSSAPIAuthentication no Restart the OpenSSH service for the settings to take effect.