18.11.2 Ensure 'Disable HTTP proxy features: Disable proxy authentication' is set to 'Enabled: Disable authentication over loopback interfaces' or higher

Information

This policy setting determines whether Windows can authenticate over a loopback interface.

The recommended state for this setting is: Enabled: Disable authentication over loopback interfaces . Configuring this setting to Disable all authentication protocols and loopback authentication also conforms to the benchmark.

It is best to limit the sign-in interface to only known and trusted services, so malicious actors can't impersonate them.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Disable authentication over loopback interfaces or Disable all authentication protocols and loopback authentication :

Computer Configuration\Policies\Administrative Templates\Center for Internet Security (CIS)\Additional Benchmark Settings\Disable HTTP proxy features: Disable proxy authentication

Note: This Group Policy path is NOT provided by Microsoft. The Group Policy template CIS.admx/adml is included with the CIS Microsoft Windows Build Kits published after January 2026.

Impact:

Windows will not be able to authenticate over a loopback interface

See Also

https://workbench.cisecurity.org/benchmarks/25733

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Windows

Control ID: 3f26635cc077cccc9e523383da88fdd907c0e7ea0d9ab772e364b87ee874f22d