MSCT Windows Server 2025 MS v1.0.0

Audit Details

Name: MSCT Windows Server 2025 MS v1.0.0

Updated: 6/11/2025

Authority: MSCT

Plugin: Windows

Revision: 1.0

Estimated Item Count: 339

File Details

Filename: MSCT_Windows_Server_2025_MS_v1.0.0.audit

Size: 643 kB

MD5: d1fc326318b379e9dbbe18cf2b284584
SHA256: 72943e84a291a4fe2d93a28a29f593ca1c7cf094d2ebb07fa832b06e81a5619b

Audit Items

DescriptionCategories
Access Credential Manager as a trusted caller

ACCESS CONTROL

Access data sources across domains - Internet Zone

SYSTEM AND COMMUNICATIONS PROTECTION

Access data sources across domains - Restricted Sites Zone

SYSTEM AND COMMUNICATIONS PROTECTION

Access this computer from the network

ACCESS CONTROL

Account lockout duration

ACCESS CONTROL

Accounts: Limit local account use of blank passwords to console logon only - LimitBlankPasswordUse

IDENTIFICATION AND AUTHENTICATION

Act as part of the operating system

ACCESS CONTROL

Allow active scripting

SYSTEM AND COMMUNICATIONS PROTECTION

Allow Basic authentication - Client - AllowBasic

ACCESS CONTROL

Allow Basic authentication - Service - AllowBasic

ACCESS CONTROL

Allow binary and script behaviors

CONFIGURATION MANAGEMENT

Allow Custom SSPs and APs to be loaded into LSASS - AllowCustomSSPsAPs
Allow cut copy or paste operations from the clipboard via script - Internet Zone

CONFIGURATION MANAGEMENT

Allow cut copy or paste operations from the clipboard via script - Restricted Sites Zone

CONFIGURATION MANAGEMENT

Allow drag and drop or copy and paste files - Internet Zone

CONFIGURATION MANAGEMENT

Allow drag and drop or copy and paste files - Restricted Sites Zone

CONFIGURATION MANAGEMENT

Allow fallback to SSL 3.0 (Internet Explorer)

SYSTEM AND COMMUNICATIONS PROTECTION

Allow file downloads

CONFIGURATION MANAGEMENT

Allow indexing of encrypted files - AllowIndexingEncryptedStoresOrItems

CONFIGURATION MANAGEMENT

Allow loading of XAML files - Internet Zone

SYSTEM AND COMMUNICATIONS PROTECTION

Allow loading of XAML files - Restricted Sites Zone

SYSTEM AND COMMUNICATIONS PROTECTION

Allow log on locally

ACCESS CONTROL

Allow META REFRESH

CONFIGURATION MANAGEMENT

Allow only approved domains to use ActiveX controls without prompt - Internet Zone

SYSTEM AND COMMUNICATIONS PROTECTION

Allow only approved domains to use ActiveX controls without prompt - Restricted Sites Zone

SYSTEM AND COMMUNICATIONS PROTECTION

Allow only approved domains to use the TDC ActiveX control - Internet Zone

CONFIGURATION MANAGEMENT

Allow only approved domains to use the TDC ActiveX control - Restricted Sites Zone

CONFIGURATION MANAGEMENT

Allow script-initiated windows without size or position constraints - Internet Zone

CONFIGURATION MANAGEMENT

Allow script-initiated windows without size or position constraints - Restricted Sites Zone

CONFIGURATION MANAGEMENT

Allow scripting of Internet Explorer WebBrowser controls - Internet Zone

CONFIGURATION MANAGEMENT

Allow scripting of Internet Explorer WebBrowser controls - Restricted Sites Zone

CONFIGURATION MANAGEMENT

Allow scriptlets - Internet Zone

CONFIGURATION MANAGEMENT

Allow scriptlets - Restricted Sites Zone

CONFIGURATION MANAGEMENT

Allow software to run or install even if the signature is invalid

SYSTEM AND COMMUNICATIONS PROTECTION

Allow unencrypted traffic - Client - AllowUnencryptedTraffic

ACCESS CONTROL

Allow unencrypted traffic - Service - AllowUnencryptedTraffic

ACCESS CONTROL

Allow updates to status bar via script - Internet Zone

CONFIGURATION MANAGEMENT

Allow updates to status bar via script - Restricted Sites Zone

CONFIGURATION MANAGEMENT

Allow user control over installs - EnableUserControl

ACCESS CONTROL

Allow VBScript to run in Internet Explorer - Internet Zone

SYSTEM AND COMMUNICATIONS PROTECTION

Allow VBScript to run in Internet Explorer - Restricted Sites Zone

SYSTEM AND COMMUNICATIONS PROTECTION

Allow Windows Ink Workspace - AllowWindowsInkWorkspace

CONFIGURATION MANAGEMENT

Always install with elevated privileges - AlwaysInstallElevated

ACCESS CONTROL

Always prompt for password upon connection - fPromptForPassword

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

Apply UAC restrictions to local accounts on network logons

ACCESS CONTROL

Audit Account Lockout

AUDIT AND ACCOUNTABILITY

Audit Audit Policy Change

AUDIT AND ACCOUNTABILITY

Audit Authentication Policy Change

AUDIT AND ACCOUNTABILITY

Audit client does not support encryption - AuditClientDoesNotSupportEncryption

AUDIT AND ACCOUNTABILITY

Audit client does not support signing - AuditClientDoesNotSupportSigning

AUDIT AND ACCOUNTABILITY