Revision 1.3Nov 18, 2025

Miscellaneous
  • Metadata updated.
  • Platform check updated.
Added
  • 18.8.5.1 (NG) Ensure 'Turn On Virtualization Based Security' is set to 'Enabled'
  • 18.8.5.2 (NG) Ensure 'Turn On Virtualization Based Security: Select Platform Security Level' is set to 'Secure Boot and DMA Protection'
  • 18.8.5.3 (NG) Ensure 'Turn On Virtualization Based Security: Virtualization Based Protection of Code Integrity' is set to 'Enabled with UEFI lock'
  • 18.8.5.4 (NG) Ensure 'Turn On Virtualization Based Security: Require UEFI Memory Attributes Table' is set to 'True (checked)'
  • 18.8.5.5 (NG) Ensure 'Turn On Virtualization Based Security: Credential Guard Configuration' is set to 'Enabled with UEFI lock' (MS Only)
  • 18.8.5.7 (NG) Ensure 'Turn On Virtualization Based Security: Secure Launch Configuration' is set to 'Enabled'
  • CIS_Azure_Compute_Microsoft_Windows_Server_2022_v1.0.0_NG_MS.audit from CIS Azure Compute Microsoft Windows Server 2022 Benchmark v1.0.0
Removed
  • 18.8.5.1 Ensure 'Turn On Virtualization Based Security' is set to 'Enabled'
  • 18.8.5.2 Ensure 'Turn On Virtualization Based Security: Select Platform Security Level' is set to 'Secure Boot and DMA Protection'
  • 18.8.5.3 Ensure 'Turn On Virtualization Based Security: Virtualization Based Protection of Code Integrity' is set to 'Enabled with UEFI lock'
  • 18.8.5.4 Ensure 'Turn On Virtualization Based Security: Require UEFI Memory Attributes Table' is set to 'True (checked)'
  • 18.8.5.5 Ensure 'Turn On Virtualization Based Security: Credential Guard Configuration' is set to 'Enabled with UEFI lock' (MS Only) - Enabled with UEFI lock
  • 18.8.5.7 Ensure 'Turn On Virtualization Based Security: Secure Launch Configuration' is set to 'Enabled'
  • CIS_Azure_Compute_Microsoft_Windows_Server_2022_Benchmark_v1.0.0_MS_NG.audit from CIS Azure Compute Microsoft Windows Server 2022 Benchmark