Access data sources across domains - Internet Zone | MSCT Windows Server v2004 DC v1.0.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
Accounts: Limit local account use of blank passwords to console logon only | MSCT Windows Server v1909 DC v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
Allow active scripting | MSCT Windows Server v1909 DC v1.0.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
Allow cut, copy or paste operations from the clipboard via script - Restricted Sites Zone | MSCT Windows Server v1909 DC v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
Allow META REFRESH | MSCT Windows Server v1909 DC v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
Allow script-initiated windows without size or position constraints - Internet Zone | MSCT Windows Server v1909 DC v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
Allow software to run or install even if the signature is invalid | MSCT Windows Server v1909 DC v1.0.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
Allow VBScript to run in Internet Explorer - Internet Zone | MSCT Windows Server v1909 DC v1.0.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
Audit Other Account Management Events | MSCT Windows Server v1909 DC v1.0.0 | Windows | AUDIT AND ACCOUNTABILITY |
Audit PNP Activity | MSCT Windows Server v1909 DC v1.0.0 | Windows | AUDIT AND ACCOUNTABILITY |
Audit User Account Management | MSCT Windows Server v1909 DC v1.0.0 | Windows | AUDIT AND ACCOUNTABILITY |
Automatic prompting for file downloads - Restricted Sites Zone | MSCT Windows Server v1909 DC v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
Configure Attack Surface Reduction rules - 92E97FA1-2EDF-4476-BDD6-9DD0B4DDDC7B | MSCT Windows Server v1909 DC v1.0.0 | Windows | SYSTEM AND INFORMATION INTEGRITY |
Configure Attack Surface Reduction rules - 7674ba52-37eb-4a4f-a9a1-f0f9a1619a2c | MSCT Windows Server v1909 DC v1.0.0 | Windows | SYSTEM AND INFORMATION INTEGRITY |
Configure Attack Surface Reduction rules - ExploitGuard_ASR_Rules | MSCT Windows Server v1909 DC v1.0.0 | Windows | SYSTEM AND INFORMATION INTEGRITY |
Debug programs | MSCT Windows Server v1909 DC v1.0.0 | Windows | ACCESS CONTROL |
Disallow Autoplay for non-volume devices | MSCT Windows Server v1909 DC v1.0.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
Disallow WinRM from storing RunAs credentials | MSCT Windows Server v1909 DC v1.0.0 | Windows | ACCESS CONTROL |
Domain member: Require strong (Windows 2000 or later) session key | MSCT Windows Server v1909 DC v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
Download unsigned ActiveX controls - Restricted Sites Zone | MSCT Windows Server v1909 DC v1.0.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
Enable computer and user accounts to be trusted for delegation | MSCT Windows Server v1909 DC v1.0.0 | Windows | ACCESS CONTROL |
Enable dragging of content from different domains across windows - Internet Zone | MSCT Windows Server v1909 DC v1.0.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
Enable dragging of content from different domains within a window - Internet Zone | MSCT Windows Server v1909 DC v1.0.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
Enumeration policy for external devices incompatible with Kernel DMA Protection | MSCT Windows Server v1909 DC v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
Hardened UNC Paths - \\*\NETLOGON | MSCT Windows Server v1909 DC v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
Impersonate a client after authentication | MSCT Windows Server v1909 DC v1.0.0 | Windows | ACCESS CONTROL |
Include local path when user is uploading files to a server - Internet Zone | MSCT Windows Server v1909 DC v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
Initialize and script ActiveX controls not marked as safe - Restricted Sites Zone | MSCT Windows Server v1909 DC v1.0.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
Interactive logon: Machine inactivity limit | MSCT Windows Server v1909 DC v1.0.0 | Windows | ACCESS CONTROL |
Interactive logon: Smart card removal behavior | MSCT Windows Server v1909 DC v1.0.0 | Windows | ACCESS CONTROL |
Internet Explorer Processes - FEATURE_RESTRICT_ACTIVEXINSTALL - (Reserved) | MSCT Windows Server v1909 DC v1.0.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
Internet Explorer Processes - FEATURE_RESTRICT_FILEDOWNLOAD - explorer.exe | MSCT Windows Server v1909 DC v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
Internet Explorer Processes - FEATURE_SECURITYBAND - iexplore.exe | MSCT Windows Server v1909 DC v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
Internet Explorer Processes - FEATURE_WINDOW_RESTRICTIONS - explorer.exe | MSCT Windows Server v1909 DC v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
Java permissions - Locked-Down Intranet Zone | MSCT Windows Server v1909 DC v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
Java permissions - Locked-Down Restricted Sites Zone | MSCT Windows Server v1909 DC v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
Microsoft network client: Digitally sign communications (always) | MSCT Windows Server v1909 DC v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
Network access: Restrict anonymous access to Named Pipes and Shares | MSCT Windows Server v1909 DC v1.0.0 | Windows | ACCESS CONTROL |
Network security: Minimum session security for NTLM SSP based (including secure RPC) clients | MSCT Windows Server v1909 DC v1.0.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
Network security: Minimum session security for NTLM SSP based (including secure RPC) servers | MSCT Windows Server v1909 DC v1.0.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
Restore files and directories | MSCT Windows Server v1909 DC v1.0.0 | Windows | ACCESS CONTROL |
Run ActiveX controls and plugins | MSCT Windows Server v1909 DC v1.0.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
Security Zones: Use only machine settings | MSCT Windows Server v1909 DC v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
Sign-in and lock last interactive user automatically after a restart | MSCT Windows Server v1909 DC v1.0.0 | Windows | IDENTIFICATION AND AUTHENTICATION |
Specify the maximum log file size (KB) - System | MSCT Windows Server v1909 DC v1.0.0 | Windows | AUDIT AND ACCOUNTABILITY |
System objects: Strengthen default permissions of internal system objects (e.g. Symbolic Links) | MSCT Windows Server v1909 DC v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
Turn off Crash Detection | MSCT Windows Server v1909 DC v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
Turn off multicast name resolution | MSCT Windows Server v1909 DC v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
Turn on the auto-complete feature for user names and passwords on forms - Main | MSCT Windows Server v1909 DC v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
Turn On Virtualization Based Security - HVCIMATRequired | MSCT Windows Server v1909 DC v1.0.0 | Windows | SYSTEM AND INFORMATION INTEGRITY |