Item Search

NameAudit NamePluginCategory
Access data sources across domains - Restricted Sites ZoneMSCT Windows Server v2004 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Do not allow ActiveX controls to run in Protected Mode when Enhanced Protected Mode is enabledMSCT Windows Server v20H2 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Domain member: Digitally sign secure channel data (when possible)MSCT Windows Server v20H2 MS v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Don't run antimalware programs against ActiveX controls - Internet ZoneMSCT Windows Server v20H2 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Download signed ActiveX controls - Internet ZoneMSCT Windows Server v20H2 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EDGE-00-000004 - The list of domains for which Microsoft Defender SmartScreen will not trigger warnings must be allowlisted if used.DISA STIG Edge v2r2Windows

MAINTENANCE

Enable computer and user accounts to be trusted for delegationMSCT Windows Server v20H2 MS v1.0.0Windows

ACCESS CONTROL

Enable local admin password managementMSCT Windows Server v20H2 MS v1.0.0Windows

ACCESS CONTROL

Enable Structured Exception Handling Overwrite Protection (SEHOP)MSCT Windows Server v20H2 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Encryption Oracle RemediationMSCT Windows Server v20H2 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Enumeration policy for external devices incompatible with Kernel DMA ProtectionMSCT Windows Server v20H2 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Include local path when user is uploading files to a server - Internet ZoneMSCT Windows Server v20H2 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Interactive logon: Smart card removal behaviorMSCT Windows Server v20H2 MS v1.0.0Windows

ACCESS CONTROL

Internet Explorer Processes - FEATURE_RESTRICT_ACTIVEXINSTALL - explorer.exeMSCT Windows Server v20H2 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Internet Explorer Processes - FEATURE_RESTRICT_ACTIVEXINSTALL - iexplore.exeMSCT Windows Server v20H2 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Internet Explorer Processes - FEATURE_RESTRICT_FILEDOWNLOAD - explorer.exeMSCT Windows Server v20H2 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Internet Explorer Processes - FEATURE_RESTRICT_FILEDOWNLOAD - iexplore.exeMSCT Windows Server v20H2 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Internet Explorer Processes - FEATURE_SECURITYBAND - explorer.exeMSCT Windows Server v20H2 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Internet Explorer Processes - FEATURE_SECURITYBAND - iexplore.exeMSCT Windows Server v20H2 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Internet Explorer Processes - FEATURE_ZONE_ELEVATION - explorer.exeMSCT Windows Server v20H2 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Java permissions - Locked-Down Intranet ZoneMSCT Windows Server v20H2 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Lock pages in memoryMSCT Windows Server v20H2 MS v1.0.0Windows

ACCESS CONTROL

Logon options - Internet ZoneMSCT Windows Server v20H2 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Manage auditing and security logMSCT Windows Server v20H2 MS v1.0.0Windows

ACCESS CONTROL

MSS: (DisableIPSourceRouting) IP source routing protection level (protects against packet spoofing)MSCT Windows Server v20H2 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS serversMSCT Windows Server v20H2 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Navigate windows and frames across different domains - Restricted Sites ZoneMSCT Windows Server v20H2 MS v1.0.0Windows

ACCESS CONTROL

NetBT NodeType configurationMSCT Windows Server v20H2 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Network access: Allow anonymous SID/Name translationMSCT Windows Server v20H2 MS v1.0.0Windows

ACCESS CONTROL

Network access: Restrict clients allowed to make remote calls to SAMMSCT Windows Server v20H2 MS v1.0.0Windows

ACCESS CONTROL

Network security: Minimum session security for NTLM SSP based (including secure RPC) clientsMSCT Windows Server v20H2 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Network security: Minimum session security for NTLM SSP based (including secure RPC) serversMSCT Windows Server v20H2 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Prevent per-user installation of ActiveX controlsMSCT Windows Server v20H2 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Relax minimum password length limitsMSCT Windows Server v20H2 MS v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Reset account lockout counter afterMSCT Windows Server v20H2 MS v1.0.0Windows

ACCESS CONTROL

Run .NET Framework-reliant components not signed with Authenticode - Restricted Sites ZoneMSCT Windows Server v20H2 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Show security warning for potentially unsafe files - Internet ZoneMSCT Windows Server v20H2 MS v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Show security warning for potentially unsafe files - Restricted Sites ZoneMSCT Windows Server v20H2 MS v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Sign-in and lock last interactive user automatically after a restartMSCT Windows Server v20H2 MS v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Take ownership of files or other objectsMSCT Windows Server v20H2 MS v1.0.0Windows

ACCESS CONTROL

Turn off AutoplayMSCT Windows Server v20H2 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Turn off multicast name resolutionMSCT Windows Server v20H2 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Turn off the Security Settings Check featureMSCT Windows Server v20H2 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Turn On Virtualization Based Security - LsaCfgFlagsMSCT Windows Server v20H2 MS v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Turn On Virtualization Based Security - RequirePlatformSecurityFeaturesMSCT Windows Server v20H2 MS v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

User Account Control: Run all administrators in Admin Approval ModeMSCT Windows Server v20H2 MS v1.0.0Windows

ACCESS CONTROL

User Account Control: Virtualize file and registry write failures to per-user locationsMSCT Windows Server v20H2 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Userdata persistence - Restricted Sites ZoneMSCT Windows Server v20H2 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

VM Tools: guest-8.tools-updatesVMware vSphere Security Configuration and Hardening GuideVMware

CONFIGURATION MANAGEMENT

Web sites in less privileged Web content zones can navigate into this zone - Internet ZoneMSCT Windows Server v20H2 MS v1.0.0Windows

ACCESS CONTROL