CIS Microsoft Intune for Windows 10 v5.0.0 L1

Audit Details

Name: CIS Microsoft Intune for Windows 10 v5.0.0 L1

Updated: 8/18/2026

Authority: CIS

Plugin: Windows

Revision: 1.0

Estimated Item Count: 246

File Details

Filename: CIS_Microsoft_Intune_for_Windows_10_v5.0.0_L1.audit

Size: 652 kB

MD5: 86f1b4d573eae9ceda3d11901b5700e3
SHA256: d35beba6b2a4e550d504812b5cb900bdd91dfde43974df2c1a320837fb0f9702

Audit Items

DescriptionCategories
1.1 Ensure 'Allow Cortana Above Lock' is set to 'Block'

CONFIGURATION MANAGEMENT

1.2 Ensure 'Allow Toasts' is set to 'Block'

CONFIGURATION MANAGEMENT

4.1.3.1 Ensure 'Prevent enabling lock screen camera' is set to 'Enabled'

ACCESS CONTROL

4.1.3.2 Ensure 'Prevent enabling lock screen slide show' is set to 'Enabled'

ACCESS CONTROL

4.4.1 Ensure 'Apply UAC restrictions to local accounts on network logons' is set to 'Enabled'

ACCESS CONTROL

4.4.2 Ensure 'Configure SMB v1 client driver' is set to 'Enabled: Disable driver (recommended)'

CONFIGURATION MANAGEMENT

4.4.3 Ensure 'Configure SMB v1 server' is set to 'Disabled'

CONFIGURATION MANAGEMENT

4.4.4 Ensure 'Enable Structured Exception Handling Overwrite Protection (SEHOP)' is set to 'Enabled'

SYSTEM AND INFORMATION INTEGRITY

4.4.5 Ensure 'WDigest Authentication' is set to 'Disabled'

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.5.1 Ensure 'MSS: (AutoAdminLogon) Enable Automatic Logon (not recommended)' is set to 'Disabled'

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.5.2 Ensure 'MSS: (DisableIPSourceRouting IPv6) IP source routing protection level (protects against packet spoofing)' is set to 'Enabled: Highest protection, source routing is completely disabled'

SYSTEM AND COMMUNICATIONS PROTECTION

4.5.3 Ensure 'MSS: (DisableIPSourceRouting) IP source routing protection level (protects against packet spoofing)' is set to 'Enabled: Highest protection, source routing is completely disabled'

SYSTEM AND COMMUNICATIONS PROTECTION

4.5.5 Ensure 'MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes' is set to 'Disabled'

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

4.5.7 Ensure 'MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers' is set to 'Enabled'

ACCESS CONTROL, CONFIGURATION MANAGEMENT

4.5.9 Ensure 'MSS: (SafeDllSearchMode) Enable Safe DLL search mode (recommended)' is set to 'Enabled'

SYSTEM AND INFORMATION INTEGRITY

4.5.12 Ensure 'MSS: (WarningLevel) Percentage threshold for the security event log at which the system will generate a warning' is set to 'Enabled: 90% or less'

AUDIT AND ACCOUNTABILITY

4.6.4.1 Ensure 'Turn off multicast name resolution' is set to 'Enabled'

CONFIGURATION MANAGEMENT

4.6.9.1 Ensure 'Prohibit installation and configuration of Network Bridge on your DNS domain network' is set to 'Enabled'

ACCESS CONTROL, CONFIGURATION MANAGEMENT

4.6.9.2 Ensure 'Prohibit use of Internet Connection Sharing on your DNS domain network' is set to 'Enabled'

CONFIGURATION MANAGEMENT

4.6.9.3 Ensure 'Require domain users to elevate when setting a network's location' is set to 'Enabled'

ACCESS CONTROL

4.6.11.1 Ensure 'Hardened UNC Paths' is set to 'Enabled, with 'Require Mutual Authentication', 'Require Integrity', and 'Require Privacy' set for all NETLOGON and SYSVOL shares'

IDENTIFICATION AND AUTHENTICATION

4.6.18.1 Ensure 'Minimize the number of simultaneous connections to the Internet or a Windows Domain' is set to 'Enabled: 3 = Prevent Wi-Fi when on Ethernet'

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

4.6.18.2 Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled'

SYSTEM AND COMMUNICATIONS PROTECTION

4.7.1 Ensure 'Allow Print Spooler to accept client connections' is set to 'Disabled'

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

4.7.2 Ensure 'Point and Print Restrictions: When installing drivers for a new connection' is set to 'Enabled: Show warning and elevation prompt'

ACCESS CONTROL

4.7.3 Ensure 'Point and Print Restrictions: When updating drivers for an existing connection' is set to 'Enabled: Show warning and elevation prompt'

CONFIGURATION MANAGEMENT

4.10.4.1 Ensure 'Include command line in process creation events' is set to 'Enabled'

AUDIT AND ACCOUNTABILITY

4.10.5.1 Ensure 'Encryption Oracle Remediation' is set to 'Enabled: Force Updated Clients'

SYSTEM AND INFORMATION INTEGRITY

4.10.5.2 Ensure 'Remote host allows delegation of non-exportable credentials' is set to 'Enabled'

IDENTIFICATION AND AUTHENTICATION

4.10.9.2 Ensure 'Prevent automatic download of applications associated with device metadata' is set to 'Enabled'

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

4.10.13.1 Ensure 'Boot-Start Driver Initialization Policy' is set to 'Enabled: Good, unknown and bad but critical'

SYSTEM AND INFORMATION INTEGRITY

4.10.19.1 Ensure 'Continue experiences on this device' is set to 'Disabled'

CONFIGURATION MANAGEMENT

4.10.20.1.2 Ensure 'Turn off downloading of print drivers over HTTP' is set to 'Enabled'

CONFIGURATION MANAGEMENT

4.10.20.1.5 Ensure 'Turn off Internet download for Web publishing and online ordering wizards' is set to 'Enabled'

CONFIGURATION MANAGEMENT

4.10.26.1 Ensure 'Block user from showing account details on sign-in' is set to 'Enabled'

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

4.10.26.2 Ensure 'Do not display network selection UI' is set to 'Enabled'

ACCESS CONTROL

4.10.26.3 Ensure 'Do not enumerate connected users on domain-joined computers' is set to 'Enabled'

ACCESS CONTROL

4.10.26.4 Ensure 'Enumerate local users on domain-joined computers' is set to 'Disabled'

ACCESS CONTROL

4.10.26.5 Ensure 'Turn off app notifications on the lock screen' is set to 'Enabled'

CONFIGURATION MANAGEMENT

4.10.26.6 Ensure 'Turn off picture password sign-in' is set to 'Enabled'

CONFIGURATION MANAGEMENT

4.10.26.7 Ensure 'Turn on convenience PIN sign-in' is set to 'Disabled'

CONFIGURATION MANAGEMENT

4.10.29.5.1 Ensure 'Require a password when a computer wakes (on battery)' is set to 'Enabled'

ACCESS CONTROL

4.10.29.5.2 Ensure 'Require a password when a computer wakes (plugged in)' is set to 'Enabled'

ACCESS CONTROL

4.10.30.1 Ensure 'Configure Offer Remote Assistance' is set to 'Disabled'

CONFIGURATION MANAGEMENT

4.10.30.2 Ensure 'Configure Solicited Remote Assistance' is set to 'Disabled'

CONFIGURATION MANAGEMENT

4.10.31.1 Ensure 'Enable RPC Endpoint Mapper Client Authentication' is set to 'Enabled'

CONFIGURATION MANAGEMENT

4.10.31.2 Ensure 'Restrict Unauthenticated RPC clients' is set to 'Enabled: Authenticated'

CONFIGURATION MANAGEMENT

4.10.44.1.1 Ensure 'Enable Windows NTP Client' is set to 'Enabled'

AUDIT AND ACCOUNTABILITY

4.10.44.1.2 Ensure 'Enable Windows NTP Server' is set to 'Disabled'

AUDIT AND ACCOUNTABILITY

4.11.3.1 Ensure 'Allow Microsoft accounts to be optional' is set to 'Enabled'

ACCESS CONTROL