WN12-AD-000010-DC - Windows services that are critical for directory server operation must be configured for automatic startup

Information

Active Directory (AD) is dependent on several Windows services. If one or more of these services is not configured for automatic startup, AD functions may be partially or completely unavailable until the services are manually started. This could result in a failure to replicate data or to support client authentication and authorization requests.

Solution

Ensure the following services that are critical for directory server operation are configured for automatic startup.

- Active Directory Domain Services
- DFS Replication
- DNS Client
- DNS server
- Group Policy Client
- Intersite Messaging
- Kerberos Key Distribution Center
- NetLogon
- Windows Time (not required if another time synchronization tool is implemented to start automatically)

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_2012_and_2012_R2_DC_V3R7_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-226079r794798_rule, STIG-ID|WN12-AD-000010-DC, STIG-Legacy|SV-51184, STIG-Legacy|V-8327, Vuln-ID|V-226079

Plugin: Windows

Control ID: 6f4f3be0db469079f6ef982779dc0cf017aeafd718e55496cc578503fd63cba9