MSCT Windows Server 2019 DC v1.0.0

Audit Details

Name: MSCT Windows Server 2019 DC v1.0.0

Updated: 5/31/2023

Authority: MSCT

Plugin: Windows

Revision: 1.13

Estimated Item Count: 322

File Details

Filename: MSCT_Windows_Server_2019_DC_v1.0.0.audit

Size: 566 kB

MD5: 32f61fbeb83d98875afe5ca3eb1e2aa1
SHA256: 0cbd70c9e1dc33f392126e97ab59b17b2d25bc9de50ef89628a398d6132bbde6

Audit Items

DescriptionCategories
Access Credential Manager as a trusted caller

ACCESS CONTROL

Access data sources across domains - Internet Zone

SYSTEM AND COMMUNICATIONS PROTECTION

Access data sources across domains - Restricted Sites Zone

SYSTEM AND COMMUNICATIONS PROTECTION

Access this computer from the network

ACCESS CONTROL

Account lockout duration

ACCESS CONTROL

Accounts: Limit local account use of blank passwords to console logon only

IDENTIFICATION AND AUTHENTICATION

Act as part of the operating system

ACCESS CONTROL

Allow active scripting

SYSTEM AND COMMUNICATIONS PROTECTION

Allow Basic authentication - WinRM Client

ACCESS CONTROL

Allow Basic authentication - WinRM Service

ACCESS CONTROL

Allow binary and script behaviors

CONFIGURATION MANAGEMENT

Allow cut, copy or paste operations from the clipboard via script - Internet Zone

CONFIGURATION MANAGEMENT

Allow cut, copy or paste operations from the clipboard via script - Restricted Sites Zone

CONFIGURATION MANAGEMENT

Allow drag and drop or copy and paste files - Internet Zone

CONFIGURATION MANAGEMENT

Allow drag and drop or copy and paste files - Restricted Sites Zone

CONFIGURATION MANAGEMENT

Allow fallback to SSL 3.0 (Internet Explorer)

SYSTEM AND COMMUNICATIONS PROTECTION

Allow file downloads

CONFIGURATION MANAGEMENT

Allow indexing of encrypted files

CONFIGURATION MANAGEMENT

Allow loading of XAML files - Internet Zone

SYSTEM AND COMMUNICATIONS PROTECTION

Allow loading of XAML files - Restricted Sites Zone

SYSTEM AND COMMUNICATIONS PROTECTION

Allow log on locally

ACCESS CONTROL

Allow log on through Remote Desktop Services

ACCESS CONTROL

Allow META REFRESH

CONFIGURATION MANAGEMENT

Allow only approved domains to use ActiveX controls without prompt - Internet Zone

SYSTEM AND COMMUNICATIONS PROTECTION

Allow only approved domains to use ActiveX controls without prompt - Restricted Sites Zone

SYSTEM AND COMMUNICATIONS PROTECTION

Allow only approved domains to use the TDC ActiveX control - Internet Zone

CONFIGURATION MANAGEMENT

Allow only approved domains to use the TDC ActiveX control - Restricted Sites Zone

CONFIGURATION MANAGEMENT

Allow script-initiated windows without size or position constraints - Internet Zone

CONFIGURATION MANAGEMENT

Allow script-initiated windows without size or position constraints - Restricted Sites Zone

CONFIGURATION MANAGEMENT

Allow scripting of Internet Explorer WebBrowser controls - Internet Zone

CONFIGURATION MANAGEMENT

Allow scripting of Internet Explorer WebBrowser controls - Restricted Sites Zone

CONFIGURATION MANAGEMENT

Allow scriptlets - Internet Zone

CONFIGURATION MANAGEMENT

Allow scriptlets - Restricted Sites Zone

CONFIGURATION MANAGEMENT

Allow software to run or install even if the signature is invalid

SYSTEM AND COMMUNICATIONS PROTECTION

Allow unencrypted traffic - WinRM Client

ACCESS CONTROL

Allow unencrypted traffic - WinRM Service

ACCESS CONTROL

Allow updates to status bar via script - Internet Zone

CONFIGURATION MANAGEMENT

Allow updates to status bar via script - Restricted Sites Zone

CONFIGURATION MANAGEMENT

Allow user control over installs

ACCESS CONTROL

Allow VBScript to run in Internet Explorer - Internet Zone

SYSTEM AND COMMUNICATIONS PROTECTION

Allow VBScript to run in Internet Explorer - Restricted Sites Zone

SYSTEM AND COMMUNICATIONS PROTECTION

Allow Windows Ink Workspace

CONFIGURATION MANAGEMENT

Always install with elevated privileges

ACCESS CONTROL

Always prompt for password upon connection

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

Audit Account Lockout

AUDIT AND ACCOUNTABILITY

Audit Audit Policy Change

AUDIT AND ACCOUNTABILITY

Audit Authentication Policy Change

AUDIT AND ACCOUNTABILITY

Audit Computer Account Management

AUDIT AND ACCOUNTABILITY

Audit Credential Validation

AUDIT AND ACCOUNTABILITY

Audit Detailed File Share

AUDIT AND ACCOUNTABILITY