CIS Microsoft Windows 10 Enterprise v4.0.0 L2 BL

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: CIS Microsoft Windows 10 Enterprise v4.0.0 L2 BL

Updated: 9/15/2026

Authority: CIS

Plugin: Windows

Revision: 1.1

Estimated Item Count: 159

File Details

Filename: CIS_Microsoft_Windows_10_Enterprise_v4.0.0_L2_BL.audit

Size: 332 kB

MD5: 6420c39ceb79af39d75519811a15a738
SHA256: 63aedc654df74be0b649508730bc0163f66daf353838e26885167e55e583ddd6

Audit Changelog

Ā 
Revision 1.1

Sep 15, 2026

Informational Update
  • '18.9.20.1.10 (L2) Ensure \'Turn off the \'Order Prints\' picture task\' is set to \'Enabled\''
  • '18.9.20.1.11 (L2) Ensure \'Turn off the \'Publish to Web\' task for files and folders\' is set to \'Enabled\''
  • 18.1.3 (L2) Ensure 'Allow Online Tips' is set to 'Disabled'
  • 18.10.11.1 (L2) Ensure 'Allow Use of Camera' is set to 'Disabled'
  • 18.10.13.2 (L2) Ensure 'Turn off cloud optimized content' is set to 'Enabled'
  • 18.10.16.2 (L2) Ensure 'Configure Authenticated Proxy usage for the Connected User Experience and Telemetry service' is set to 'Enabled: Disable Authenticated Proxy usage'
  • 18.10.18.1 (L2) Ensure 'Enable App Installer' is set to 'Disabled'
  • 18.10.18.7 (L2) Ensure 'Enable Windows Package Manager command line interfaces' is set to 'Disabled'
  • 18.10.37.1 (L2) Ensure 'Turn off location' is set to 'Enabled'
  • 18.10.4.1 (L2) Ensure 'Allow a Windows app to share application data between users' is set to 'Disabled'
  • 18.10.41.1 (L2) Ensure 'Allow Message Service Cloud Sync' is set to 'Disabled'
  • 18.10.43.11.1.1.1 (L2) Ensure 'Configure Brute-Force Protection aggressiveness' is set to 'Enabled: Medium' or higher
  • 18.10.43.12.1 (L2) Ensure 'Configure Watson events' is set to 'Disabled'
  • 18.10.43.5.2 (L2) Ensure 'Join Microsoft MAPS' is set to 'Disabled'
  • 18.10.43.8.1 (L2) Ensure 'Convert warn verdict to block' is set to 'Enabled'
  • 18.10.50.1 (L2) Ensure 'Enable news and interests on the taskbar' is set to 'Disabled'
  • 18.10.56.1 (L2) Ensure 'Turn off Push To Install service' is set to 'Enabled'
  • 18.10.57.3.10.1 (L2) Ensure 'Set time limit for active but idle Remote Desktop Services sessions' is set to 'Enabled: 15 minutes or less, but not Never (0)'
  • 18.10.57.3.10.2 (L2) Ensure 'Set time limit for disconnected sessions' is set to 'Enabled: 1 minute'
  • 18.10.57.3.2.1 (L2) Ensure 'Allow users to connect remotely by using Remote Desktop Services' is set to 'Disabled'
  • 18.10.57.3.3.1 (L2) Ensure 'Allow UI Automation redirection' is set to 'Disabled'
  • 18.10.57.3.3.2 (L2) Ensure 'Do not allow COM port redirection' is set to 'Enabled'
  • 18.10.57.3.3.4 (L2) Ensure 'Do not allow location redirection' is set to 'Enabled'
  • 18.10.57.3.3.5 (L2) Ensure 'Do not allow LPT port redirection' is set to 'Enabled'
  • 18.10.57.3.3.6 (L2) Ensure 'Do not allow supported Plug and Play device redirection' is set to 'Enabled'
  • 18.10.57.3.3.7 (L2) Ensure 'Do not allow WebAuthn redirection' is set to 'Enabled'
  • 18.10.59.2 (L2) Ensure 'Allow Cloud Search' is set to 'Enabled: Disable Cloud Search'
  • 18.10.59.7 (L2) Ensure 'Allow search highlights' is set to 'Disabled'
  • 18.10.6.2 (L2) Ensure 'Block launching Universal Windows apps with Windows Runtime API access from hosted content.' is set to 'Enabled'
  • 18.10.63.1 (L2) Ensure 'Turn off KMS Client Online AVS Validation' is set to 'Enabled'
  • 18.10.66.1 (L2) Ensure 'Disable all apps from Microsoft Store' is set to 'Disabled'
  • 18.10.66.4 (L2) Ensure 'Turn off the Store application' is set to 'Enabled'
  • 18.10.80.1 (L2) Ensure 'Allow suggested apps in Windows Ink Workspace' is set to 'Disabled'
  • 18.10.81.3 (L2) Ensure 'Prevent Internet Explorer security prompt for Windows Installer scripts' is set to 'Disabled'
  • 18.10.87.1 (L2) Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'
  • 18.10.87.2 (L2) Ensure 'Turn on PowerShell Transcription' is set to 'Enabled'
  • 18.10.89.2.2 (L2) Ensure 'Allow remote server management through WinRM' is set to 'Disabled'
  • 18.10.90.1 (L2) Ensure 'Allow Remote Shell Access' is set to 'Disabled'
  • 18.5.11 (L2) Ensure 'MSS: (TcpMaxDataRetransmissions IPv6) How many times unacknowledged data is retransmitted' is set to 'Enabled: 3'
  • 18.5.12 (L2) Ensure 'MSS: (TcpMaxDataRetransmissions) How many times unacknowledged data is retransmitted' is set to 'Enabled: 3'
  • 18.5.4 (L2) Ensure 'MSS: (DisableSavePassword) Prevent the dial-up password from being saved' is set to 'Enabled'
  • 18.5.6 (L2) Ensure 'MSS: (KeepAliveTime) How often keep-alive packets are sent in milliseconds' is set to 'Enabled: 300,000 or 5 minutes'
  • 18.5.8 (L2) Ensure 'MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses' is set to 'Disabled'
  • 18.6.10.2 (L2) Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' is set to 'Enabled'
  • 18.6.19.2.1 (L2) Disable IPv6 (Ensure TCPIP6 Parameter 'DisabledComponents' is set to '0xff (255)')
  • 18.6.20.1 (L2) Ensure 'Configuration of wireless settings using Windows Connect Now' is set to 'Disabled'
  • 18.6.20.2 (L2) Ensure 'Prohibit access of the Windows Connect Now wizards' is set to 'Enabled'
  • 18.6.4.3 (L2) Ensure 'Turn off default IPv6 DNS Servers' is set to 'Enabled'
  • 18.6.5.1 (L2) Ensure 'Enable Font Providers' is set to 'Disabled'
  • 18.6.9.1 (L2) Ensure 'Turn on Mapper I/O (LLTDIO) driver' is set to 'Disabled'
  • 18.6.9.2 (L2) Ensure 'Turn on Responder (RSPNDR) driver' is set to 'Disabled'
  • 18.8.1.1 (L2) Ensure 'Turn off notifications network usage' is set to 'Enabled'
  • 18.9.20.1.1 (L2) Ensure 'Turn off access to the Store' is set to 'Enabled'
  • 18.9.20.1.12 (L2) Ensure 'Turn off the Windows Messenger Customer Experience Improvement Program' is set to 'Enabled'
  • 18.9.20.1.13 (L2) Ensure 'Turn off Windows Customer Experience Improvement Program' is set to 'Enabled'
  • 18.9.20.1.14 (L2) Ensure 'Turn off Windows Error Reporting' is set to 'Enabled'
  • 18.9.20.1.3 (L2) Ensure 'Turn off handwriting personalization data sharing' is set to 'Enabled'
  • 18.9.20.1.4 (L2) Ensure 'Turn off handwriting recognition error reporting' is set to 'Enabled'
  • 18.9.20.1.5 (L2) Ensure 'Turn off Internet Connection Wizard if URL connection is referring to Microsoft.com' is set to 'Enabled'
  • 18.9.20.1.7 (L2) Ensure 'Turn off printing over HTTP' is set to 'Enabled'
  • 18.9.20.1.8 (L2) Ensure 'Turn off Registration if URL connection is referring to Microsoft.com' is set to 'Enabled'
  • 18.9.20.1.9 (L2) Ensure 'Turn off Search Companion content file updates' is set to 'Enabled'
  • 18.9.23.1 (L2) Ensure 'Support device authentication using certificate' is set to 'Enabled: Automatic'
  • 18.9.27.1 (L2) Ensure 'Disallow copying of user input methods to the system account for sign-in' is set to 'Enabled'
  • 18.9.31.1 (L2) Ensure 'Allow Clipboard synchronization across devices' is set to 'Disabled'
  • 18.9.31.2 (L2) Ensure 'Allow upload of User Activities' is set to 'Disabled'
  • 18.9.47.11.1 (L2) Ensure 'Enable/Disable PerfTrack' is set to 'Disabled'
  • 18.9.47.5.1 (L2) Ensure 'Microsoft Support Diagnostic Tool: Turn on MSDT interactive communication with support provider' is set to 'Disabled'
  • 18.9.49.1 (L2) Ensure 'Turn off the advertising ID' is set to 'Enabled'
  • 19.6.6.1.1 (L2) Ensure 'Turn off Help Experience Improvement Program' is set to 'Enabled'
  • 19.7.46.2.1 (L2) Ensure 'Prevent Codec Download' is set to 'Enabled'
  • 19.7.8.3 (L2) Ensure 'Do not use diagnostic data for tailored experiences' is set to 'Enabled'
  • 19.7.8.4 (L2) Ensure 'Turn off all Windows spotlight features' is set to 'Enabled'
  • 2.2.28 (L2) Ensure 'Log on as a batch job' is set to 'Administrators'
  • 2.2.29 (L2) Ensure 'Log on as a service' is configured
  • 2.3.14.1 (L2) Ensure 'System cryptography: Force strong key protection for user keys stored on the computer' is set to 'User is prompted when the key is first used' or higher
  • 2.3.4.1 (L2) Ensure 'Devices: Prevent users from installing printer drivers' is set to 'Enabled'
  • 2.3.7.7 (L2) Ensure 'Interactive logon: Number of previous logons to cache (in case domain controller is not available)' is set to '4 or fewer logon(s)'
  • 5.1 (L2) Ensure 'Bluetooth Audio Gateway Service (BTAGService)' is set to 'Disabled'
  • 5.10 (L2) Ensure 'Link-Layer Topology Discovery Mapper (lltdsvc)' is set to 'Disabled'
  • 5.13 (L2) Ensure 'Microsoft iSCSI Initiator Service (MSiSCSI)' is set to 'Disabled'
  • 5.15 (L2) Ensure 'Peer Name Resolution Protocol (PNRPsvc)' is set to 'Disabled'
  • 5.16 (L2) Ensure 'Peer Networking Grouping (p2psvc)' is set to 'Disabled'
  • 5.17 (L2) Ensure 'Peer Networking Identity Manager (p2pimsvc)' is set to 'Disabled'
  • 5.18 (L2) Ensure 'PNRP Machine Name Publication Service (PNRPAutoReg)' is set to 'Disabled'
  • 5.19 (L2) Ensure 'Print Spooler (Spooler)' is set to 'Disabled'
  • 5.2 (L2) Ensure 'Bluetooth Support Service (bthserv)' is set to 'Disabled'
  • 5.20 (L2) Ensure 'Problem Reports and Solutions Control Panel Support (wercplsupport)' is set to 'Disabled'
  • 5.21 (L2) Ensure 'Remote Access Auto Connection Manager (RasAuto)' is set to 'Disabled'
  • 5.22 (L2) Ensure 'Remote Desktop Configuration (SessionEnv)' is set to 'Disabled'
  • 5.23 (L2) Ensure 'Remote Desktop Services (TermService)' is set to 'Disabled'
  • 5.24 (L2) Ensure 'Remote Desktop Services UserMode Port Redirector (UmRdpService)' is set to 'Disabled'
  • 5.26 (L2) Ensure 'Remote Registry (RemoteRegistry)' is set to 'Disabled'
  • 5.28 (L2) Ensure 'Server (LanmanServer)' is set to 'Disabled'
  • 5.30 (L2) Ensure 'SNMP Service (SNMP)' is set to 'Disabled' or 'Not Installed'
  • 5.35 (L2) Ensure 'Windows Error Reporting Service (WerSvc)' is set to 'Disabled'
  • 5.36 (L2) Ensure 'Windows Event Collector (Wecsvc)' is set to 'Disabled'
  • 5.39 (L2) Ensure 'Windows Push Notifications System Service (WpnService)' is set to 'Disabled'
  • 5.4 (L2) Ensure 'Downloaded Maps Manager (MapsBroker)' is set to 'Disabled'
  • 5.40 (L2) Ensure 'Windows PushToInstall Service (PushToInstall)' is set to 'Disabled'
  • 5.41 (L2) Ensure 'Windows Remote Management (WS-Management) (WinRM)' is set to 'Disabled'
  • 5.42 (L2) Ensure 'WinHTTP Web Proxy Auto-Discovery Service (WinHttpAutoProxySvc)' is set to 'Disabled'
  • 5.5 (L2) Ensure 'GameInput Service (GameInputSvc)' is set to 'Disabled'
  • 5.6 (L2) Ensure 'Geolocation Service (lfsvc)' is set to 'Disabled'
Miscellaneous
  • Audit deprecated.
  • Metadata updated.
  • Platform check updated.
  • References updated.
Added
  • 18.10.10.1.1 (BL) Ensure 'Allow access to BitLocker-protected fixed data drives from earlier versions of Windows' is set to 'Disabled'
  • 18.10.10.1.10 (BL) Ensure 'Configure use of hardware-based encryption for fixed data drives' is set to 'Disabled'
  • 18.10.10.1.11 (BL) Ensure 'Configure use of passwords for fixed data drives' is set to 'Disabled'
  • 18.10.10.1.12 (BL) Ensure 'Configure use of smart cards on fixed data drives' is set to 'Enabled'
  • 18.10.10.1.13 (BL) Ensure 'Configure use of smart cards on fixed data drives: Require use of smart cards on fixed data drives' is set to 'Enabled: True'
  • 18.10.10.1.2 (BL) Ensure 'Choose how BitLocker-protected fixed drives can be recovered' is set to 'Enabled'
  • 18.10.10.1.3 (BL) Ensure 'Choose how BitLocker-protected fixed drives can be recovered: Allow data recovery agent' is set to 'Enabled: True'
  • 18.10.10.1.4 (BL) Ensure 'Choose how BitLocker-protected fixed drives can be recovered: Recovery Password' is set to 'Enabled: Allow 48-digit recovery password' or higher
  • 18.10.10.1.5 (BL) Ensure 'Choose how BitLocker-protected fixed drives can be recovered: Recovery Key' is set to 'Enabled: Allow 256-bit recovery key' or higher
  • 18.10.10.1.6 (BL) Ensure 'Choose how BitLocker-protected fixed drives can be recovered: Omit recovery options from the BitLocker setup wizard' is set to 'Enabled: True'
  • 18.10.10.1.7 (BL) Ensure 'Choose how BitLocker-protected fixed drives can be recovered: Save BitLocker recovery information to AD DS for fixed data drives' is set to 'Enabled: False'
  • 18.10.10.1.8 (BL) Ensure 'Choose how BitLocker-protected fixed drives can be recovered: Configure storage of BitLocker recovery information to AD DS' is set to 'Enabled: Backup recovery passwords and key packages'
  • 18.10.10.1.9 (BL) Ensure 'Choose how BitLocker-protected fixed drives can be recovered: Do not enable BitLocker until recovery information is stored to AD DS for fixed data drives' is set to 'Enabled: False'
  • 18.10.10.2.1 (BL) Ensure 'Allow enhanced PINs for startup' is set to 'Enabled'
  • 18.10.10.2.10 (BL) Ensure 'Choose how BitLocker-protected operating system drives can be recovered: Do not enable BitLocker until recovery information is stored to AD DS for operating system drives' is set to 'Enabled: True'
  • 18.10.10.2.11 (BL) Ensure 'Configure use of hardware-based encryption for operating system drives' is set to 'Disabled'
  • 18.10.10.2.12 (BL) Ensure 'Configure use of passwords for operating system drives' is set to 'Disabled'
  • 18.10.10.2.13 (BL) Ensure 'Require additional authentication at startup' is set to 'Enabled'
  • 18.10.10.2.14 (BL) Ensure 'Require additional authentication at startup: Allow BitLocker without a compatible TPM' is set to 'Enabled: False'
  • 18.10.10.2.2 (BL) Ensure 'Allow Secure Boot for integrity validation' is set to 'Enabled'
  • 18.10.10.2.3 (BL) Ensure 'Choose how BitLocker-protected operating system drives can be recovered' is set to 'Enabled'
  • 18.10.10.2.4 (BL) Ensure 'Choose how BitLocker-protected operating system drives can be recovered: Allow data recovery agent' is set to 'Enabled: False'
  • 18.10.10.2.5 (BL) Ensure 'Choose how BitLocker-protected operating system drives can be recovered: Recovery Password' is set to 'Enabled: Require 48-digit recovery password'
  • 18.10.10.2.6 (BL) Ensure 'Choose how BitLocker-protected operating system drives can be recovered: Recovery Key' is set to 'Enabled: Do not allow 256-bit recovery key'
  • 18.10.10.2.7 (BL) Ensure 'Choose how BitLocker-protected operating system drives can be recovered: Omit recovery options from the BitLocker setup wizard' is set to 'Enabled: True'
  • 18.10.10.2.8 (BL) Ensure 'Choose how BitLocker-protected operating system drives can be recovered: Save BitLocker recovery information to AD DS for operating system drives' is set to 'Enabled: True'
  • 18.10.10.2.9 (BL) Ensure 'Choose how BitLocker-protected operating system drives can be recovered: Configure storage of BitLocker recovery information to AD DS:' is set to 'Enabled: Store recovery passwords and key packages'
  • 18.10.10.3.1 (BL) Ensure 'Allow access to BitLocker-protected removable data drives from earlier versions of Windows' is set to 'Disabled'
  • 18.10.10.3.10 (BL) Ensure 'Configure use of hardware-based encryption for removable data drives' is set to 'Disabled'
  • 18.10.10.3.11 (BL) Ensure 'Configure use of passwords for removable data drives' is set to 'Disabled'
  • 18.10.10.3.12 (BL) Ensure 'Configure use of smart cards on removable data drives' is set to 'Enabled'
  • 18.10.10.3.13 (BL) Ensure 'Configure use of smart cards on removable data drives: Require use of smart cards on removable data drives' is set to 'Enabled: True'
  • 18.10.10.3.14 (BL) Ensure 'Deny write access to removable drives not protected by BitLocker' is set to 'Enabled'
  • 18.10.10.3.15 (BL) Ensure 'Deny write access to removable drives not protected by BitLocker: Do not allow write access to devices configured in another organization' is set to 'Enabled: False'
  • 18.10.10.3.2 (BL) Ensure 'Choose how BitLocker-protected removable drives can be recovered' is set to 'Enabled'
  • 18.10.10.3.3 (BL) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Allow data recovery agent' is set to 'Enabled: True'
  • 18.10.10.3.4 (BL) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Recovery Password' is set to 'Enabled: Do not allow 48-digit recovery password'
  • 18.10.10.3.5 (BL) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Recovery Key' is set to 'Enabled: Do not allow 256-bit recovery key'
  • 18.10.10.3.6 (BL) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Omit recovery options from the BitLocker setup wizard' is set to 'Enabled: True'
  • 18.10.10.3.7 (BL) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Save BitLocker recovery information to AD DS for removable data drives' is set to 'Enabled: False'
  • 18.10.10.3.8 (BL) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Configure storage of BitLocker recovery information to AD DS:' is set to 'Enabled: Backup recovery passwords and key packages'
  • 18.10.10.3.9 (BL) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Do not enable BitLocker until recovery information is stored to AD DS for removable data drives' is set to 'Enabled: False'
  • 18.10.10.4 (BL) Ensure 'Disable new DMA devices when this computer is locked' is set to 'Enabled'
  • 18.9.24.1 (BL) Ensure 'Enumeration policy for external devices incompatible with Kernel DMA Protection' is set to 'Enabled: Block All'
  • 18.9.33.6.3 (BL) Ensure 'Allow standby states (S1-S3) when sleeping (on battery)' is set to 'Disabled'
  • 18.9.33.6.4 (BL) Ensure 'Allow standby states (S1-S3) when sleeping (plugged in)' is set to 'Disabled'
  • 18.9.7.1.1 (BL) Ensure 'Prevent installation of devices that match any of these device IDs' is set to 'Enabled'
  • 18.9.7.1.2 (BL) Ensure 'Prevent installation of devices that match any of these device IDs: Prevent installation of devices that match any of these device IDs' is set to 'PCI\CC_0C0A'
  • 18.9.7.1.3 (BL) Ensure 'Prevent installation of devices that match any of these device IDs: Also apply to matching devices that are already installed.' is set to 'True' (checked)
  • 18.9.7.1.4 (BL) Ensure 'Prevent installation of devices using drivers that match these device setup classes' is set to 'Enabled'
  • 18.9.7.1.5 (BL) Ensure 'Prevent installation of devices using drivers that match these device setup classes: Prevent installation of devices using drivers for these device setup' is set to 'IEEE 1394 device setup classes'
  • 18.9.7.1.6 (BL) Ensure 'Prevent installation of devices using drivers that match these device setup classes: Also apply to matching devices that are already installed.' is set to 'True' (checked)
  • 2.3.7.3 (BL) Ensure 'Interactive logon: Machine account lockout threshold' is set to '10 or fewer invalid logon attempts, but not 0'
  • CIS_Microsoft_Windows_10_Enterprise_v4.0.0_L2_BL.audit from CIS Microsoft Windows 10 Enterprise v4.0.0
Removed
  • CIS_Microsoft_Windows_10_Enterprise_v4.0.0_L2_BL.audit from CIS Microsoft Windows 10 Enterprise Benchmark v4.0.0