1.121 WN11-CC-000060

Information

Connections to non-domain networks when connected to a domain authenticated network must be blocked.

GROUP ID: V-253365
RULE ID: SV-253365r991589

Multiple network connections can provide additional attack vectors to a system and must be limited. When connected to a domain, communication must go through the domain connection.

Solution

Configure the policy value for

Computer Configuration >> Administrative Templates >> Network >> Windows Connection Manager >> 'Prohibit connection to non-domain networks when connected to domain authenticated network'

to 'Enabled'.

See Also

https://workbench.cisecurity.org/benchmarks/27756