WN25-00-000030 - Windows Server 2025 administrative accounts must not be used with applications that access the internet, such as web browsers, or with potential internet sources, such as email.

Information

Accounts with administrative privileges using applications that access the internet, or have potential internet sources, expose a system to compromise. If a flaw in an application is exploited while running as a privileged user, the entire system could be compromised. Web browsers and email are common attack vectors for introducing malicious code and must not be run with an administrative account.

Since administrative accounts could change or work around technical restrictions for running a web browser or other applications, it is essential that a policy prohibits administrative accounts accessing the internet or use public-facing applications such as email.

The policy must define specific exceptions for local service administration. These exceptions may include HTTP(S)-based tools that are used for the administration of the local system, services, or attached devices.

Technical methods (such as allow listing) must be used to enforce the policy, except as approved by the AO.

Satisfies: SRG-OS-000480-GPOS-00227, SRG-OS-000205-GPOS-00083

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Establish a policy, at minimum, to prohibit administrative accounts from using applications that access public-facing networks or the internet, such as web browsers, or applications with potential internet sources, such as email.

Ensure the policy is enforced by technical means, such as allow listing via AppLocker or Software Restriction Policies (SRPs).

Document any exceptions to technical enforcement with the information system security officer (ISSO).

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_Server_2025_V1R3_STIG.zip