DISA Windows Server 2016 STIG v2r4

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: DISA Windows Server 2016 STIG v2r4

Updated: 3/8/2023

Authority: Operating Systems and Applications

Plugin: Windows

Revision: 1.10

Estimated Item Count: 285

Audit Changelog

 
Revision 1.10

Mar 8, 2023

Functional Update
  • WN16-CC-000240 - The Application Compatibility Program Inventory must be prevented from collecting data and sending the information to Microsoft.
  • WN16-CC-000400 - The Remote Desktop Session Host must require secure Remote Procedure Call (RPC) communications.
  • WN16-SO-000020 - Local accounts with blank passwords must be restricted to prevent access from the network.
  • WN16-SO-000380 - The LAN Manager authentication level must be set to send NTLMv2 response only and to refuse LM and NTLM.
Revision 1.9

Feb 7, 2023

Miscellaneous
  • Audit deprecated.
  • Metadata updated.
  • References updated.
Revision 1.8

Dec 7, 2022

Miscellaneous
  • Variables updated.
Revision 1.7

Oct 26, 2022

Functional Update
  • WN16-MS-000010 - Only administrators responsible for the member server or standalone system must have Administrator rights on the system.
Informational Update
  • WN16-MS-000010 - Only administrators responsible for the member server or standalone system must have Administrator rights on the system.
Revision 1.6

Sep 16, 2022

Functional Update
  • WN16-DC-000080 - The Active Directory SYSVOL directory must have the proper access control permissions.
Revision 1.5

Aug 29, 2022

Functional Update
  • WN16-DC-000080 - The Active Directory SYSVOL directory must have the proper access control permissions.
Miscellaneous
  • Variables updated.
Revision 1.4

Aug 11, 2022

Functional Update
  • WN16-00-000050 - Members of the Backup Operators group must have separate accounts for backup duties and normal operational tasks.
  • WN16-00-000080 - Shared user accounts must not be permitted on the system.
  • WN16-00-000090 - Windows Server 2016 must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.
  • WN16-00-000250 - Non-system-created file shares on a system must limit access to groups that require it.
  • WN16-00-000310 - A host-based firewall must be installed and enabled on the system.
Informational Update
  • WN16-00-000310 - A host-based firewall must be installed and enabled on the system.
Added
  • WN16-00-000100 - Windows Server 2016 domain-joined systems must have a Trusted Platform Module (TPM) enabled and ready for use - TpmPresent
  • WN16-00-000100 - Windows Server 2016 domain-joined systems must have a Trusted Platform Module (TPM) enabled and ready for use - TpmReady
Removed
  • WN16-00-000100 - Windows Server 2016 domain-joined systems must have a Trusted Platform Module (TPM) enabled and ready for use - TPM enabled and ready for use.
Revision 1.3

Jul 12, 2022

Miscellaneous
  • Metadata updated.
Revision 1.2

Jul 7, 2022

Miscellaneous
  • Metadata updated.
Revision 1.1

Jul 7, 2022

Miscellaneous
  • Platform check updated.