18.11.2 Ensure 'Disable HTTP proxy features: Disable proxy authentication' is set to 'Enabled: Disable authentication over loopback interfaces' or higher

Information

This policy setting determines whether Windows can authenticate over a loopback interface.

The recommended state for this setting is: Enabled: Disable authentication over loopback interfaces . Configuring this setting to Disable all authentication protocols and loopback authentication also conforms to the benchmark.

It is best to limit the sign-in interface to only known and trusted services, so malicious actors can't impersonate them.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Disable authentication over loopback interfaces or Disable all authentication protocols and loopback authentication :

Computer Configuration\Policies\Administrative Templates\Center for Internet Security (CIS)\Additional Benchmark Settings\Disable HTTP proxy features: Disable proxy authentication

Note: This Group Policy path is NOT provided by Microsoft. The Group Policy template CIS.admx/adml is included with the CIS Microsoft Windows Build Kits published after January 2026.

Impact:

Windows will not be able to authenticate over a loopback interface

See Also

https://workbench.cisecurity.org/benchmarks/25708

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Windows

Control ID: 2461f1f2ed2a047503d58c41ac30ca0fedd2707f0601e1dac12645ea19cb83bd