Windows Server 2022 Windows Remote Management (WinRM) client must not use Digest authentication. GROUP ID: V-254380 RULE ID: SV-254380r958510 Digest authentication is not as strong as other options and may be subject to man-in-the-middle attacks. Disallowing Digest authentication will reduce this potential.
Solution
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Windows Remote Management (WinRM) >> WinRM Client >> Disallow Digest authentication to 'Enabled'