CIS Microsoft Windows 10 Enterprise v4.0.0 L2 NG

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: CIS Microsoft Windows 10 Enterprise v4.0.0 L2 NG

Updated: 9/15/2026

Authority: CIS

Plugin: Windows

Revision: 1.1

Estimated Item Count: 119

File Details

Filename: CIS_Microsoft_Windows_10_Enterprise_v4.0.0_L2_NG.audit

Size: 237 kB

MD5: 2f08eecddf6240e29c203e4a20bf61ab
SHA256: 0c1b2ac9a0408a8f76ef3b18f312726f1d9edd48719a451adfe3e35c72d99cba

Audit Changelog

Ā 
Revision 1.1

Sep 15, 2026

Informational Update
  • '18.9.20.1.10 (L2) Ensure \'Turn off the \'Order Prints\' picture task\' is set to \'Enabled\''
  • '18.9.20.1.11 (L2) Ensure \'Turn off the \'Publish to Web\' task for files and folders\' is set to \'Enabled\''
  • 18.1.3 (L2) Ensure 'Allow Online Tips' is set to 'Disabled'
  • 18.10.11.1 (L2) Ensure 'Allow Use of Camera' is set to 'Disabled'
  • 18.10.13.2 (L2) Ensure 'Turn off cloud optimized content' is set to 'Enabled'
  • 18.10.16.2 (L2) Ensure 'Configure Authenticated Proxy usage for the Connected User Experience and Telemetry service' is set to 'Enabled: Disable Authenticated Proxy usage'
  • 18.10.18.1 (L2) Ensure 'Enable App Installer' is set to 'Disabled'
  • 18.10.18.7 (L2) Ensure 'Enable Windows Package Manager command line interfaces' is set to 'Disabled'
  • 18.10.37.1 (L2) Ensure 'Turn off location' is set to 'Enabled'
  • 18.10.4.1 (L2) Ensure 'Allow a Windows app to share application data between users' is set to 'Disabled'
  • 18.10.41.1 (L2) Ensure 'Allow Message Service Cloud Sync' is set to 'Disabled'
  • 18.10.43.11.1.1.1 (L2) Ensure 'Configure Brute-Force Protection aggressiveness' is set to 'Enabled: Medium' or higher
  • 18.10.43.12.1 (L2) Ensure 'Configure Watson events' is set to 'Disabled'
  • 18.10.43.5.2 (L2) Ensure 'Join Microsoft MAPS' is set to 'Disabled'
  • 18.10.43.8.1 (L2) Ensure 'Convert warn verdict to block' is set to 'Enabled'
  • 18.10.50.1 (L2) Ensure 'Enable news and interests on the taskbar' is set to 'Disabled'
  • 18.10.56.1 (L2) Ensure 'Turn off Push To Install service' is set to 'Enabled'
  • 18.10.57.3.10.1 (L2) Ensure 'Set time limit for active but idle Remote Desktop Services sessions' is set to 'Enabled: 15 minutes or less, but not Never (0)'
  • 18.10.57.3.10.2 (L2) Ensure 'Set time limit for disconnected sessions' is set to 'Enabled: 1 minute'
  • 18.10.57.3.2.1 (L2) Ensure 'Allow users to connect remotely by using Remote Desktop Services' is set to 'Disabled'
  • 18.10.57.3.3.1 (L2) Ensure 'Allow UI Automation redirection' is set to 'Disabled'
  • 18.10.57.3.3.2 (L2) Ensure 'Do not allow COM port redirection' is set to 'Enabled'
  • 18.10.57.3.3.4 (L2) Ensure 'Do not allow location redirection' is set to 'Enabled'
  • 18.10.57.3.3.5 (L2) Ensure 'Do not allow LPT port redirection' is set to 'Enabled'
  • 18.10.57.3.3.6 (L2) Ensure 'Do not allow supported Plug and Play device redirection' is set to 'Enabled'
  • 18.10.57.3.3.7 (L2) Ensure 'Do not allow WebAuthn redirection' is set to 'Enabled'
  • 18.10.59.2 (L2) Ensure 'Allow Cloud Search' is set to 'Enabled: Disable Cloud Search'
  • 18.10.59.7 (L2) Ensure 'Allow search highlights' is set to 'Disabled'
  • 18.10.6.2 (L2) Ensure 'Block launching Universal Windows apps with Windows Runtime API access from hosted content.' is set to 'Enabled'
  • 18.10.63.1 (L2) Ensure 'Turn off KMS Client Online AVS Validation' is set to 'Enabled'
  • 18.10.66.1 (L2) Ensure 'Disable all apps from Microsoft Store' is set to 'Disabled'
  • 18.10.66.4 (L2) Ensure 'Turn off the Store application' is set to 'Enabled'
  • 18.10.80.1 (L2) Ensure 'Allow suggested apps in Windows Ink Workspace' is set to 'Disabled'
  • 18.10.81.3 (L2) Ensure 'Prevent Internet Explorer security prompt for Windows Installer scripts' is set to 'Disabled'
  • 18.10.87.1 (L2) Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'
  • 18.10.87.2 (L2) Ensure 'Turn on PowerShell Transcription' is set to 'Enabled'
  • 18.10.89.2.2 (L2) Ensure 'Allow remote server management through WinRM' is set to 'Disabled'
  • 18.10.90.1 (L2) Ensure 'Allow Remote Shell Access' is set to 'Disabled'
  • 18.5.11 (L2) Ensure 'MSS: (TcpMaxDataRetransmissions IPv6) How many times unacknowledged data is retransmitted' is set to 'Enabled: 3'
  • 18.5.12 (L2) Ensure 'MSS: (TcpMaxDataRetransmissions) How many times unacknowledged data is retransmitted' is set to 'Enabled: 3'
  • 18.5.4 (L2) Ensure 'MSS: (DisableSavePassword) Prevent the dial-up password from being saved' is set to 'Enabled'
  • 18.5.6 (L2) Ensure 'MSS: (KeepAliveTime) How often keep-alive packets are sent in milliseconds' is set to 'Enabled: 300,000 or 5 minutes'
  • 18.5.8 (L2) Ensure 'MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses' is set to 'Disabled'
  • 18.6.10.2 (L2) Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' is set to 'Enabled'
  • 18.6.19.2.1 (L2) Disable IPv6 (Ensure TCPIP6 Parameter 'DisabledComponents' is set to '0xff (255)')
  • 18.6.20.1 (L2) Ensure 'Configuration of wireless settings using Windows Connect Now' is set to 'Disabled'
  • 18.6.20.2 (L2) Ensure 'Prohibit access of the Windows Connect Now wizards' is set to 'Enabled'
  • 18.6.4.3 (L2) Ensure 'Turn off default IPv6 DNS Servers' is set to 'Enabled'
  • 18.6.5.1 (L2) Ensure 'Enable Font Providers' is set to 'Disabled'
  • 18.6.9.1 (L2) Ensure 'Turn on Mapper I/O (LLTDIO) driver' is set to 'Disabled'
  • 18.6.9.2 (L2) Ensure 'Turn on Responder (RSPNDR) driver' is set to 'Disabled'
  • 18.8.1.1 (L2) Ensure 'Turn off notifications network usage' is set to 'Enabled'
  • 18.9.20.1.1 (L2) Ensure 'Turn off access to the Store' is set to 'Enabled'
  • 18.9.20.1.12 (L2) Ensure 'Turn off the Windows Messenger Customer Experience Improvement Program' is set to 'Enabled'
  • 18.9.20.1.13 (L2) Ensure 'Turn off Windows Customer Experience Improvement Program' is set to 'Enabled'
  • 18.9.20.1.14 (L2) Ensure 'Turn off Windows Error Reporting' is set to 'Enabled'
  • 18.9.20.1.3 (L2) Ensure 'Turn off handwriting personalization data sharing' is set to 'Enabled'
  • 18.9.20.1.4 (L2) Ensure 'Turn off handwriting recognition error reporting' is set to 'Enabled'
  • 18.9.20.1.5 (L2) Ensure 'Turn off Internet Connection Wizard if URL connection is referring to Microsoft.com' is set to 'Enabled'
  • 18.9.20.1.7 (L2) Ensure 'Turn off printing over HTTP' is set to 'Enabled'
  • 18.9.20.1.8 (L2) Ensure 'Turn off Registration if URL connection is referring to Microsoft.com' is set to 'Enabled'
  • 18.9.20.1.9 (L2) Ensure 'Turn off Search Companion content file updates' is set to 'Enabled'
  • 18.9.23.1 (L2) Ensure 'Support device authentication using certificate' is set to 'Enabled: Automatic'
  • 18.9.27.1 (L2) Ensure 'Disallow copying of user input methods to the system account for sign-in' is set to 'Enabled'
  • 18.9.31.1 (L2) Ensure 'Allow Clipboard synchronization across devices' is set to 'Disabled'
  • 18.9.31.2 (L2) Ensure 'Allow upload of User Activities' is set to 'Disabled'
  • 18.9.47.11.1 (L2) Ensure 'Enable/Disable PerfTrack' is set to 'Disabled'
  • 18.9.47.5.1 (L2) Ensure 'Microsoft Support Diagnostic Tool: Turn on MSDT interactive communication with support provider' is set to 'Disabled'
  • 18.9.49.1 (L2) Ensure 'Turn off the advertising ID' is set to 'Enabled'
  • 19.6.6.1.1 (L2) Ensure 'Turn off Help Experience Improvement Program' is set to 'Enabled'
  • 19.7.46.2.1 (L2) Ensure 'Prevent Codec Download' is set to 'Enabled'
  • 19.7.8.3 (L2) Ensure 'Do not use diagnostic data for tailored experiences' is set to 'Enabled'
  • 19.7.8.4 (L2) Ensure 'Turn off all Windows spotlight features' is set to 'Enabled'
  • 2.2.28 (L2) Ensure 'Log on as a batch job' is set to 'Administrators'
  • 2.2.29 (L2) Ensure 'Log on as a service' is configured
  • 2.3.14.1 (L2) Ensure 'System cryptography: Force strong key protection for user keys stored on the computer' is set to 'User is prompted when the key is first used' or higher
  • 2.3.4.1 (L2) Ensure 'Devices: Prevent users from installing printer drivers' is set to 'Enabled'
  • 2.3.7.7 (L2) Ensure 'Interactive logon: Number of previous logons to cache (in case domain controller is not available)' is set to '4 or fewer logon(s)'
  • 5.1 (L2) Ensure 'Bluetooth Audio Gateway Service (BTAGService)' is set to 'Disabled'
  • 5.10 (L2) Ensure 'Link-Layer Topology Discovery Mapper (lltdsvc)' is set to 'Disabled'
  • 5.13 (L2) Ensure 'Microsoft iSCSI Initiator Service (MSiSCSI)' is set to 'Disabled'
  • 5.15 (L2) Ensure 'Peer Name Resolution Protocol (PNRPsvc)' is set to 'Disabled'
  • 5.16 (L2) Ensure 'Peer Networking Grouping (p2psvc)' is set to 'Disabled'
  • 5.17 (L2) Ensure 'Peer Networking Identity Manager (p2pimsvc)' is set to 'Disabled'
  • 5.18 (L2) Ensure 'PNRP Machine Name Publication Service (PNRPAutoReg)' is set to 'Disabled'
  • 5.19 (L2) Ensure 'Print Spooler (Spooler)' is set to 'Disabled'
  • 5.2 (L2) Ensure 'Bluetooth Support Service (bthserv)' is set to 'Disabled'
  • 5.20 (L2) Ensure 'Problem Reports and Solutions Control Panel Support (wercplsupport)' is set to 'Disabled'
  • 5.21 (L2) Ensure 'Remote Access Auto Connection Manager (RasAuto)' is set to 'Disabled'
  • 5.22 (L2) Ensure 'Remote Desktop Configuration (SessionEnv)' is set to 'Disabled'
  • 5.23 (L2) Ensure 'Remote Desktop Services (TermService)' is set to 'Disabled'
  • 5.24 (L2) Ensure 'Remote Desktop Services UserMode Port Redirector (UmRdpService)' is set to 'Disabled'
  • 5.26 (L2) Ensure 'Remote Registry (RemoteRegistry)' is set to 'Disabled'
  • 5.28 (L2) Ensure 'Server (LanmanServer)' is set to 'Disabled'
  • 5.30 (L2) Ensure 'SNMP Service (SNMP)' is set to 'Disabled' or 'Not Installed'
  • 5.35 (L2) Ensure 'Windows Error Reporting Service (WerSvc)' is set to 'Disabled'
  • 5.36 (L2) Ensure 'Windows Event Collector (Wecsvc)' is set to 'Disabled'
  • 5.39 (L2) Ensure 'Windows Push Notifications System Service (WpnService)' is set to 'Disabled'
  • 5.4 (L2) Ensure 'Downloaded Maps Manager (MapsBroker)' is set to 'Disabled'
  • 5.40 (L2) Ensure 'Windows PushToInstall Service (PushToInstall)' is set to 'Disabled'
  • 5.41 (L2) Ensure 'Windows Remote Management (WS-Management) (WinRM)' is set to 'Disabled'
  • 5.42 (L2) Ensure 'WinHTTP Web Proxy Auto-Discovery Service (WinHttpAutoProxySvc)' is set to 'Disabled'
  • 5.5 (L2) Ensure 'GameInput Service (GameInputSvc)' is set to 'Disabled'
  • 5.6 (L2) Ensure 'Geolocation Service (lfsvc)' is set to 'Disabled'
Miscellaneous
  • Audit deprecated.
  • Metadata updated.
  • Platform check updated.
  • References updated.
Added
  • 18.10.44.1 (NG) Ensure 'Allow auditing events in Microsoft Defender Application Guard' is set to 'Enabled'
  • 18.10.44.2 (NG) Ensure 'Allow camera and microphone access in Microsoft Defender Application Guard' is set to 'Disabled'
  • 18.10.44.3 (NG) Ensure 'Allow data persistence for Microsoft Defender Application Guard' is set to 'Disabled'
  • 18.10.44.4 (NG) Ensure 'Allow files to download and save to the host operating system from Microsoft Defender Application Guard' is set to 'Disabled'
  • 18.10.44.5 (NG) Ensure 'Configure Microsoft Defender Application Guard clipboard settings: Clipboard behavior setting' is set to 'Enabled: Enable clipboard operation from an isolated session to the host'
  • 18.10.44.6 (NG) Ensure 'Turn on Microsoft Defender Application Guard in Managed Mode' is set to 'Enabled: 1'
  • 18.9.26.2 (NG) Ensure 'Configures LSASS to run as a protected process' is set to 'Enabled: Enabled with UEFI Lock'
  • 18.9.5.1 (NG) Ensure 'Turn On Virtualization Based Security' is set to 'Enabled'
  • 18.9.5.2 (NG) Ensure 'Turn On Virtualization Based Security: Select Platform Security Level' is set to 'Secure Boot' or higher
  • 18.9.5.3 (NG) Ensure 'Turn On Virtualization Based Security: Virtualization Based Protection of Code Integrity' is set to 'Enabled with UEFI lock'
  • 18.9.5.4 (NG) Ensure 'Turn On Virtualization Based Security: Require UEFI Memory Attributes Table' is set to 'True (checked)'
  • 18.9.5.5 (NG) Ensure 'Turn On Virtualization Based Security: Credential Guard Configuration' is set to 'Enabled with UEFI lock'
  • 18.9.5.6 (NG) Ensure 'Turn On Virtualization Based Security: Secure Launch Configuration' is set to 'Enabled'
  • CIS_Microsoft_Windows_10_Enterprise_v4.0.0_L2_NG.audit from CIS Microsoft Windows 10 Enterprise v4.0.0
Removed
  • CIS_Microsoft_Windows_10_Enterprise_v4.0.0_L2_NG.audit from CIS Microsoft Windows 10 Enterprise Benchmark v4.0.0