Item Search

NameAudit NamePluginCategory
4.10.9.1.4 (BL) Ensure 'Prevent installation of devices using drivers that match these device setup classes' is set to 'Enabled'CIS Microsoft Intune for Windows 10 v4.0.0 BLWindows

MEDIA PROTECTION

4.10.9.1.5 (BL) Ensure 'Prevent installation of devices using drivers that match these device setup classes: Also apply to matching devices that are already installed.' is set to 'True' (checked)CIS Microsoft Intune for Windows 10 v4.0.0 BLWindows

SYSTEM AND INFORMATION INTEGRITY

18.8.7.1.1 Ensure 'Prevent installation of devices using drivers that match these device setup classes' is set to 'Enabled'CIS Windows 7 Workstation Level 2 + Bitlocker v3.2.0Windows

MEDIA PROTECTION

18.8.7.1.3 Ensure 'Prevent installation of devices using drivers that match these device setup classes: Also apply to matching devices that are already installed.' is set to 'True' (checked)CIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0Windows

MEDIA PROTECTION

18.8.7.1.6 (BL) Ensure 'Prevent installation of devices using drivers that match these device setup classes: Also apply to matching devices that are already installed.' is set to 'True' (checked)CIS Microsoft Windows 8.1 v2.4.1 L2 BitlockerWindows

MEDIA PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION

18.9.7.1.4 (BL) Ensure 'Prevent installation of devices using drivers that match these device setup classes' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise v4.0.0 L1 BL NGWindows

MEDIA PROTECTION

18.9.7.1.6 (BL) Ensure 'Prevent installation of devices using drivers that match these device setup classes: Also apply to matching devices that are already installed.' is set to 'True' (checked)CIS Microsoft Windows 10 Enterprise v4.0.0 L1 BL NGWindows

SYSTEM AND INFORMATION INTEGRITY

18.9.7.1.10 (L1) Ensure 'Prevent installation of devices using drivers that match these device setup classes: Also apply to matching devices that are already installed.' is set to 'True' (checked)CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

SYSTEM AND INFORMATION INTEGRITY

Allow scripting of Internet Explorer WebBrowser controls - Restricted Sites ZoneMSCT Windows Server 2025 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Allow unencrypted traffic - Client - AllowUnencryptedTrafficMSCT Windows Server 2025 MS v1.0.0Windows

ACCESS CONTROL

Audit client does not support encryption - AuditClientDoesNotSupportEncryptionMSCT Windows Server 2025 MS v1.0.0Windows

AUDIT AND ACCOUNTABILITY

Audit Detailed File ShareMSCT Windows Server 2025 MS v1.0.0Windows

AUDIT AND ACCOUNTABILITY

Automatic prompting for file downloads - Internet ZoneMSCT Windows Server 2025 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Configure hash algorithms for certificate logon - KDC PKINITSHA384MSCT Windows Server 2025 MS v1.0.0Windows
Configure hash algorithms for certificate logon - Kerberos PKInitSHA1MSCT Windows Server 2025 MS v1.0.0Windows
Configure hash algorithms for certificate logon - Kerberos PKInitSHA384MSCT Windows Server 2025 MS v1.0.0Windows
Configure registry policy processing - NoGPOListChangesMSCT Windows Server 2025 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Configure RPC listener settings - ForceKerberosForRpcMSCT Windows Server 2025 MS v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Configure RPC listener settings - RpcProtocolsMSCT Windows Server 2025 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Configure SMB v1 client driver - StartMSCT Windows Server 2025 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Control whether exclusions are visible to local usersMSCT Windows Server 2025 MS v1.0.0Windows
Deny log on through Remote Desktop ServicesMSCT Windows Server 2025 MS v1.0.0Windows

ACCESS CONTROL

Don't run antimalware programs against ActiveX controls - Internet ZoneMSCT Windows Server 2025 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Don't run antimalware programs against ActiveX controls - Restricted Sites ZoneMSCT Windows Server 2025 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EDGE-00-000043 - The Password Manager must be disabled.DISA STIG Edge v2r2Windows

IDENTIFICATION AND AUTHENTICATION

Enable authentication rate limiter - EnableAuthRateLimiterMSCT Windows Server 2025 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Enable dragging of content from different domains within a window - Internet ZoneMSCT Windows Server 2025 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Force shutdown from a remote systemMSCT Windows Server 2025 MS v1.0.0Windows

ACCESS CONTROL

Internet Explorer Processes - FEATURE_DISABLE_MK_PROTOCOL - explorer.exeMSCT Windows Server 2025 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Internet Explorer Processes - FEATURE_DISABLE_MK_PROTOCOL - iexplore.exeMSCT Windows Server 2025 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Internet Explorer Processes - FEATURE_RESTRICT_FILEDOWNLOAD - explorer.exeMSCT Windows Server 2025 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Internet Explorer Processes - FEATURE_WINDOW_RESTRICTIONS - iexplore.exeMSCT Windows Server 2025 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Java permissions - Internet ZoneMSCT Windows Server 2025 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Java permissions - Locked-Down Trusted Sites ZoneMSCT Windows Server 2025 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Java permissions - Trusted Sites ZoneMSCT Windows Server 2025 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Logon options - Internet ZoneMSCT Windows Server 2025 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Manage auditing and security log (DEPRECATED)MSCT Windows Server 2025 MS v1.0.0Windows

ACCESS CONTROL

Mandate the minimum version of SMB - MinSmb2DialectMSCT Windows Server 2025 MS v1.0.0Windows
MSS: (DisableIPSourceRouting) IP source routing protection level - DisableIPSourceRoutingMSCT Windows Server 2025 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Network access: Allow anonymous SID/Name translationMSCT Windows Server 2025 MS v1.0.0Windows

ACCESS CONTROL

PANW-AG-000036 - The Palo Alto Networks security platform must disable WMI probing if it is not used.DISA STIG Palo Alto ALG v3r4Palo_Alto

CONFIGURATION MANAGEMENT

Prevent bypassing Windows Defender SmartScreen prompts for sitesMSCT Windows 10 1903 v1.19.9Windows

SYSTEM AND INFORMATION INTEGRITY

Prevent bypassing Windows Defender SmartScreen prompts for sitesMSCT Windows 10 v21H1 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Profile single processMSCT Windows Server 2019 MS v1.0.0Windows

ACCESS CONTROL

Run .NET Framework-reliant components not signed with Authenticode - Internet ZoneMSCT Windows Server 2019 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Sign-in last interactive user automatically after a system-initiated restartMSCT Windows Server 2019 MS v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Turn off the Security Settings Check featureMSCT Windows Server 2019 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Turn on SmartScreen Filter scan - Internet ZoneMSCT Windows Server 2019 MS v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Turn On Virtualization Based Security - ConfigureSystemGuardLaunchMSCT Windows Server 2019 MS v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Turn On Virtualization Based Security - EnableVirtualizationBasedSecurityMSCT Windows Server 2019 MS v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY