106.1.3 Ensure 'Device Health: Code integrity' is set to 'Require'

Information

This policy setting ensures that Code Integrity is enabled on Windows devices. Code Integrity is a Windows kernel-level feature that validates the digital signatures of drivers and system files each time they are loaded into memory.

The recommended state for this setting is: Require.

Code Integrity prevents malicious or unauthorized kernel-mode drivers and system files from loading, significantly reducing the attack surface for rootkits, bootkits, and malicious driver exploits. Without code integrity enforcement, an attacker who gains sufficient privilege can load an unsigned malicious driver that operates invisibly at the kernel level.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To establish the recommended configuration from Microsoft Intune Admin Center:

- Navigate to Endpoint security > Compliance policies.
- Create or edit a Compliance policy.
- Under Device Health, set Code integrity to Require.

Impact:

Devices that do not have Code Integrity enabled, including devices where HVCI cannot be enabled due to hardware limitations will be marked non-compliant. Non-compliant devices may lose access to corporate resources until Secure Boot is confirmed.

See Also

https://workbench.cisecurity.org/benchmarks/27291

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-16

Plugin: Windows

Control ID: de142988371f8456198ba543c30c2f1178b01d1410d4779db7b0899b7cce4bae