CIS Windows Server 2012 R2 DC L1 v2.6.0

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: CIS Windows Server 2012 R2 DC L1 v2.6.0

Updated: 3/1/2024

Authority: CIS

Plugin: Windows

Revision: 1.9

Estimated Item Count: 338

File Details

Filename: CIS_DC_SERVER_2012_R2_Level_1_v2.6.0.audit

Size: 744 kB

MD5: 4a15a8459ca3eb3a7d5a5b8e8ceb64b1
SHA256: 174cf920d98ee7b87f50a90c6a571d6805124d3e71e1391bc3469159e49e59e4

Audit Changelog

 
Revision 1.9

Mar 1, 2024

Miscellaneous
  • Audit deprecated.
  • Metadata updated.
  • References updated.
Revision 1.8

Dec 4, 2023

Functional Update
  • 2.3.17.2 Ensure 'User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode' is set to 'Prompt for consent on the secure desktop'
Miscellaneous
  • References updated.
Revision 1.7

Oct 6, 2023

Functional Update
  • 18.9.25.1 Ensure 'EMET 5.52' or higher is installed - EMET 5.52 or higher is installed
Miscellaneous
  • Metadata updated.
  • References updated.
Revision 1.6

Aug 24, 2023

Added
  • 18.9.108.2.2 Ensure 'Configure Automatic Updates: Scheduled install day' is set to '0 - Every day'
Removed
  • 18.9.108.2.2 Ensure 'Configure Automatic Updates: Scheduled install day' is set to '0 - Every day' - Every day'
Revision 1.5

Apr 12, 2023

Functional Update
  • 1.1.1 Ensure 'Enforce password history' is set to '24 or more password(s)'
  • 1.1.2 Ensure 'Maximum password age' is set to '365 or fewer days, but not 0'
  • 1.1.3 Ensure 'Minimum password age' is set to '1 or more day(s)'
  • 1.1.4 Ensure 'Minimum password length' is set to '14 or more character(s)'
Miscellaneous
  • Metadata updated.
  • Platform check updated.
  • Variables updated.
Revision 1.4

Mar 21, 2023

Functional Update
  • 2.3.5.2 Ensure 'Domain controller: Allow vulnerable Netlogon secure channel connections' is set to 'Not Configured' (DC Only)
Miscellaneous
  • References updated.
Revision 1.3

Mar 8, 2023

Functional Update
  • 18.9.31.4 Ensure 'Turn off shell protocol protected mode' is set to 'Disabled' - Disabled
  • 18.9.65.3.9.2 Ensure 'Require secure RPC communication' is set to 'Enabled' - Enabled
  • 2.3.1.4 Ensure 'Accounts: Limit local account use of blank passwords to console logon only' is set to 'Enabled'
  • 2.3.11.7 Ensure 'Network security: LAN Manager authentication level' is set to 'Send NTLMv2 response only. Refuse LM & NTLM'
Revision 1.2

Mar 7, 2023

Miscellaneous
  • Metadata updated.
  • References updated.
Revision 1.1

Jan 4, 2023

Miscellaneous
  • Metadata updated.
Revision 1.0

Dec 21, 2022

Miscellaneous
  • Metadata updated.