'18.6.14.1 Ensure \'Hardened UNC Paths\' is set to \'Enabled, with \'Require Mutual Authentication\', \'Require Integrity\', and \'Require Privacy\' set for all NETLOGON and SYSVOL shares\''
1.1.1 Ensure 'Enforce password history' is set to '24 or more password(s)'
1.2.3 Ensure 'Allow Administrator account lockout' is set to 'Enabled' (MS only)
18.1.2.2 Ensure 'Allow users to enable online speech recognition services' is set to 'Disabled'
18.10.16.1 Ensure 'Allow Diagnostic Data' is set to 'Enabled: Diagnostic data off (not recommended)' or 'Enabled: Send required diagnostic data'
18.10.9.1.1 Ensure 'Configure enhanced anti-spoofing' is set to 'Enabled'
18.10.94.2.1 Ensure 'Configure Automatic Updates' is set to 'Enabled'
18.4.6 Ensure 'NetBT NodeType configuration' is set to 'Enabled: P-node (recommended)'
18.7.1 Ensure 'Allow Print Spooler to accept client connections' is set to 'Disabled'
18.7.10 Ensure 'Limits print driver installation to Administrators' is set to 'Enabled'
18.7.11 Ensure 'Manage processing of Queue-specific files' is set to 'Enabled: Limit Queue-specific files to Color profiles'
18.7.12 Ensure 'Point and Print Restrictions: When installing drivers for a new connection' is set to 'Enabled: Show warning and elevation prompt'
18.7.13 Ensure 'Point and Print Restrictions: When updating drivers for an existing connection' is set to 'Enabled: Show warning and elevation prompt'
18.7.8 Ensure 'Configure RPC packet level privacy setting for incoming connections' is set to 'Enabled'
18.9.3.1 Ensure 'Include command line in process creation events' is set to 'Enabled'
18.9.38.1 Ensure 'Enable RPC Endpoint Mapper Client Authentication' is set to 'Enabled' (MS only)
18.9.4.1 Ensure 'Encryption Oracle Remediation' is set to 'Enabled: Force Updated Clients'
18.9.4.2 Ensure 'Remote host allows delegation of non-exportable credentials' is set to 'Enabled'
18.9.7.2 Ensure 'Prevent automatic download of applications associated with device metadata' is set to 'Enabled'