WN11-CC-000060 - Connections to non-domain networks when connected to a domain authenticated network must be blocked.

Information

Multiple network connections can provide additional attack vectors to a system and must be limited. When connected to a domain, communication must go through the domain connection.

Solution

Configure the policy value for Computer Configuration >> Administrative Templates >> Network >> Windows Connection Manager >> 'Prohibit connection to non-domain networks when connected to domain authenticated network' to 'Enabled'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_11_V2R3_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-253365r991589_rule, STIG-ID|WN11-CC-000060, Vuln-ID|V-253365

Plugin: Windows

Control ID: 83a2648a0c4769173619800be22f5e00cba0212a593d215ce4c65436fc20f6d6