'18.6.14.1 Ensure \'Hardened UNC Paths\' is set to \'Enabled, with \'Require Mutual Authentication\', \'Require Integrity\', and \'Require Privacy\' set for all NETLOGON and SYSVOL shares\''
1.1.1 Ensure 'Enforce password history' is set to '24 or more password(s)'
1.1.5 Ensure 'Password must meet complexity requirements' is set to 'Enabled'
1.2.3 Ensure 'Allow Administrator account lockout' is set to 'Enabled'
18.1.2.2 Ensure 'Allow users to enable online speech recognition services' is set to 'Disabled'
18.10.10.1.8 Ensure 'Choose how BitLocker-protected fixed drives can be recovered: Configure storage of BitLocker recovery information to AD DS' is set to 'Enabled: Backup recovery passwords and key packages'
18.10.16.1 Ensure 'Allow Diagnostic Data' is set to 'Enabled: Diagnostic data off (not recommended)' or 'Enabled: Send required diagnostic data'
18.10.43.6 Ensure 'Turn on Microsoft Defender Application Guard in Managed Mode' is set to 'Enabled: 1'
18.10.9.1.1 Ensure 'Configure enhanced anti-spoofing' is set to 'Enabled'
18.10.94.2.1 Ensure 'Configure Automatic Updates' is set to 'Enabled'
18.10.94.2.2 Ensure 'Configure Automatic Updates: Scheduled install day' is set to '0 - Every day'
18.4.6 Ensure 'NetBT NodeType configuration' is set to 'Enabled: P-node (recommended)'
18.6.23.2.1 Ensure 'Allow Windows to automatically connect to suggested open hotspots, to networks shared by contacts, and to hotspots offering paid services' is set to 'Disabled'
18.7.1 Ensure 'Allow Print Spooler to accept client connections' is set to 'Disabled'
18.7.10 Ensure 'Limits print driver installation to Administrators' is set to 'Enabled'
18.7.11 Ensure 'Manage processing of Queue-specific files' is set to 'Enabled: Limit Queue-specific files to Color profiles'
18.7.12 Ensure 'Point and Print Restrictions: When installing drivers for a new connection' is set to 'Enabled: Show warning and elevation prompt'
18.7.13 Ensure 'Point and Print Restrictions: When updating drivers for an existing connection' is set to 'Enabled: Show warning and elevation prompt'
18.7.8 Ensure 'Configure RPC packet level privacy setting for incoming connections' is set to 'Enabled'
18.9.27.2 Ensure 'Configures LSASS to run as a protected process' is set to 'Enabled: Enabled with UEFI Lock'
18.9.3.1 Ensure 'Include command line in process creation events' is set to 'Enabled'
18.9.38.1 Ensure 'Enable RPC Endpoint Mapper Client Authentication' is set to 'Enabled'
18.9.4.1 Ensure 'Encryption Oracle Remediation' is set to 'Enabled: Force Updated Clients'
18.9.4.2 Ensure 'Remote host allows delegation of non-exportable credentials' is set to 'Enabled'
18.9.7.2 Ensure 'Prevent automatic download of applications associated with device metadata' is set to 'Enabled'