CIS Microsoft Windows Server 2025 v2.0.0 L1 MS

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: CIS Microsoft Windows Server 2025 v2.0.0 L1 MS

Updated: 8/21/2026

Authority: CIS

Plugin: Windows

Revision: 1.1

Estimated Item Count: 332

File Details

Filename: CIS_Microsoft_Windows_Server_2025_v2.0.0_L1_MS.audit

Size: 725 kB

MD5: 70cb4d762558a4395ff2b8d74cb850ba
SHA256: f01341defa53e19fbdc22a9d127b497e3fd0e394a47566b65ea9b6f51cc8986f

Audit Changelog

 
Revision 1.1

Aug 21, 2026

Informational Update
  • '18.6.14.1 Ensure \'Hardened UNC Paths\' is set to \'Enabled, with \'Require Mutual Authentication\', \'Require Integrity\', and \'Require Privacy\' set for all NETLOGON and SYSVOL shares\''
  • 1.1.1 Ensure 'Enforce password history' is set to '24 or more password(s)'
  • 1.2.3 Ensure 'Allow Administrator account lockout' is set to 'Enabled' (MS only)
  • 18.1.2.2 Ensure 'Allow users to enable online speech recognition services' is set to 'Disabled'
  • 18.10.16.1 Ensure 'Allow Diagnostic Data' is set to 'Enabled: Diagnostic data off (not recommended)' or 'Enabled: Send required diagnostic data'
  • 18.10.9.1.1 Ensure 'Configure enhanced anti-spoofing' is set to 'Enabled'
  • 18.10.94.2.1 Ensure 'Configure Automatic Updates' is set to 'Enabled'
  • 18.4.6 Ensure 'NetBT NodeType configuration' is set to 'Enabled: P-node (recommended)'
  • 18.7.1 Ensure 'Allow Print Spooler to accept client connections' is set to 'Disabled'
  • 18.7.10 Ensure 'Limits print driver installation to Administrators' is set to 'Enabled'
  • 18.7.11 Ensure 'Manage processing of Queue-specific files' is set to 'Enabled: Limit Queue-specific files to Color profiles'
  • 18.7.12 Ensure 'Point and Print Restrictions: When installing drivers for a new connection' is set to 'Enabled: Show warning and elevation prompt'
  • 18.7.13 Ensure 'Point and Print Restrictions: When updating drivers for an existing connection' is set to 'Enabled: Show warning and elevation prompt'
  • 18.7.8 Ensure 'Configure RPC packet level privacy setting for incoming connections' is set to 'Enabled'
  • 18.9.3.1 Ensure 'Include command line in process creation events' is set to 'Enabled'
  • 18.9.38.1 Ensure 'Enable RPC Endpoint Mapper Client Authentication' is set to 'Enabled' (MS only)
  • 18.9.4.1 Ensure 'Encryption Oracle Remediation' is set to 'Enabled: Force Updated Clients'
  • 18.9.4.2 Ensure 'Remote host allows delegation of non-exportable credentials' is set to 'Enabled'
  • 18.9.7.2 Ensure 'Prevent automatic download of applications associated with device metadata' is set to 'Enabled'
  • 2.3.1.3 Configure 'Accounts: Rename administrator account'
  • 2.3.17.3 Ensure 'User Account Control: Behavior of the elevation prompt for standard users' is set to 'Automatically deny elevation requests'
  • 2.3.2.2 Ensure 'Audit: Shut down system immediately if unable to log security audits' is set to 'Disabled'
Miscellaneous
  • Audit deprecated.
  • Metadata updated.
  • Platform check updated.
  • References updated.
Added
  • CIS_Microsoft_Windows_Server_2025_v2.0.0_L1_MS.audit from CIS Microsoft Windows Server 2025 v2.0.0
Removed
  • CIS_Microsoft_Windows_Server_2025_v2.0.0_L1_MS.audit from CIS Microsoft Windows Server 2025 2.0.0