CIS Microsoft Windows 11 Enterprise v5.0.1 L1 BL

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: CIS Microsoft Windows 11 Enterprise v5.0.1 L1 BL

Updated: 8/13/2026

Authority: CIS

Plugin: Windows

Revision: 1.2

Estimated Item Count: 439

File Details

Filename: CIS_Microsoft_Windows_11_Enterprise_v5.0.1_L1_BL.audit

Size: 940 kB

MD5: bb5164cae2c7b1f5fe4b6e3f24e992d9
SHA256: 6a736f378120d434ded585732e6e122b10d92a84c6fa1e9ea8923a740c82b5fa

Audit Changelog

 
Revision 1.2

Aug 13, 2026

Informational Update
  • '18.6.14.1 Ensure \'Hardened UNC Paths\' is set to \'Enabled, with \'Require Mutual Authentication\', \'Require Integrity\', and \'Require Privacy\' set for all NETLOGON and SYSVOL shares\''
  • 1.1.1 Ensure 'Enforce password history' is set to '24 or more password(s)'
  • 1.1.5 Ensure 'Password must meet complexity requirements' is set to 'Enabled'
  • 1.2.3 Ensure 'Allow Administrator account lockout' is set to 'Enabled'
  • 18.1.2.2 Ensure 'Allow users to enable online speech recognition services' is set to 'Disabled'
  • 18.10.10.1.8 Ensure 'Choose how BitLocker-protected fixed drives can be recovered: Configure storage of BitLocker recovery information to AD DS' is set to 'Enabled: Backup recovery passwords and key packages'
  • 18.10.16.1 Ensure 'Allow Diagnostic Data' is set to 'Enabled: Diagnostic data off (not recommended)' or 'Enabled: Send required diagnostic data'
  • 18.10.43.6 Ensure 'Turn on Microsoft Defender Application Guard in Managed Mode' is set to 'Enabled: 1'
  • 18.10.9.1.1 Ensure 'Configure enhanced anti-spoofing' is set to 'Enabled'
  • 18.10.94.2.1 Ensure 'Configure Automatic Updates' is set to 'Enabled'
  • 18.10.94.2.2 Ensure 'Configure Automatic Updates: Scheduled install day' is set to '0 - Every day'
  • 18.4.6 Ensure 'NetBT NodeType configuration' is set to 'Enabled: P-node (recommended)'
  • 18.6.23.2.1 Ensure 'Allow Windows to automatically connect to suggested open hotspots, to networks shared by contacts, and to hotspots offering paid services' is set to 'Disabled'
  • 18.7.1 Ensure 'Allow Print Spooler to accept client connections' is set to 'Disabled'
  • 18.7.10 Ensure 'Limits print driver installation to Administrators' is set to 'Enabled'
  • 18.7.11 Ensure 'Manage processing of Queue-specific files' is set to 'Enabled: Limit Queue-specific files to Color profiles'
  • 18.7.12 Ensure 'Point and Print Restrictions: When installing drivers for a new connection' is set to 'Enabled: Show warning and elevation prompt'
  • 18.7.13 Ensure 'Point and Print Restrictions: When updating drivers for an existing connection' is set to 'Enabled: Show warning and elevation prompt'
  • 18.7.8 Ensure 'Configure RPC packet level privacy setting for incoming connections' is set to 'Enabled'
  • 18.9.27.2 Ensure 'Configures LSASS to run as a protected process' is set to 'Enabled: Enabled with UEFI Lock'
  • 18.9.3.1 Ensure 'Include command line in process creation events' is set to 'Enabled'
  • 18.9.38.1 Ensure 'Enable RPC Endpoint Mapper Client Authentication' is set to 'Enabled'
  • 18.9.4.1 Ensure 'Encryption Oracle Remediation' is set to 'Enabled: Force Updated Clients'
  • 18.9.4.2 Ensure 'Remote host allows delegation of non-exportable credentials' is set to 'Enabled'
  • 18.9.7.2 Ensure 'Prevent automatic download of applications associated with device metadata' is set to 'Enabled'
  • 2.3.1.3 Configure 'Accounts: Rename administrator account'
  • 2.3.17.3 Ensure 'User Account Control: Behavior of the elevation prompt for standard users' is set to 'Automatically deny elevation requests'
  • 2.3.2.2 Ensure 'Audit: Shut down system immediately if unable to log security audits' is set to 'Disabled'
  • 5.10 Ensure 'Microsoft FTP Service (FTPSVC)' is set to 'Disabled' or 'Not Installed'
  • 5.12 Ensure 'OpenSSH SSH Server (sshd)' is set to 'Disabled' or 'Not Installed'
  • 5.27 Ensure 'Simple TCP/IP Services (simptcp)' is set to 'Disabled' or 'Not Installed'
  • 5.29 Ensure 'Special Administration Console Helper (sacsvr)' is set to 'Disabled' or 'Not Installed'
  • 5.3 Ensure 'Computer Browser (Browser)' is set to 'Disabled' or 'Not Installed'
  • 5.32 Ensure 'Web Management Service (WMSvc)' is set to 'Disabled' or 'Not Installed'
  • 5.40 Ensure 'World Wide Web Publishing Service (W3SVC)' is set to 'Disabled' or 'Not Installed'
  • 5.7 Ensure 'IIS Admin Service (IISADMIN)' is set to 'Disabled' or 'Not Installed'
Miscellaneous
  • Audit deprecated.
  • Metadata updated.
  • Platform check updated.
  • References updated.
Added
  • CIS_Microsoft_Windows_11_Enterprise_v5.0.1_L1_BL.audit from CIS Microsoft Windows 11 Enterprise v5.0.1
Removed
  • CIS_Microsoft_Windows_11_Enterprise_v5.0.1_L1_BL.audit from CIS Microsoft Windows 11 Enterprise 5.0.1
Revision 1.1

Apr 27, 2026

Functional Update
  • 2.2.22 Ensure 'Generate security audits' is set to 'LOCAL SERVICE, NETWORK SERVICE, RESTRICTED SERVICES\PrintSpoolerService'
  • 2.2.23 Ensure 'Impersonate a client after authentication' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE, RESTRICTED SERVICES\PrintSpoolerService'