Item Search

NameAudit NamePluginCategory
Configure Attack Surface Reduction rules - be9ba2d9-53ea-4cdc-84e5-9b1eeee46550MSCT Windows Server v20H2 DC v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Configure Attack Surface Reduction rules - ExploitGuard_ASR_RulesMSCT Windows Server v20H2 DC v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Configure Windows Defender SmartScreen - EnableSmartScreenMSCT Windows Server v20H2 DC v1.0.0Windows

ACCESS CONTROL

Configure Windows Defender SmartScreen - ShellSmartScreenLevelMSCT Windows Server v20H2 DC v1.0.0Windows

ACCESS CONTROL

Create a token objectMSCT Windows Server v20H2 DC v1.0.0Windows

ACCESS CONTROL

Don't run antimalware programs against ActiveX controls - Trusted Sites ZoneMSCT Windows Server v20H2 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Enable dragging of content from different domains across windows - Restricted Sites ZoneMSCT Windows Server v20H2 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Enable dragging of content from different domains within a window - Internet ZoneMSCT Windows Server v20H2 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Extended Protection for LDAP Authentication (Domain Controllers only) (DEPRECATED)MSCT Windows Server v20H2 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Hardened UNC Paths - \\*\NETLOGONMSCT Windows Server v20H2 DC v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Impersonate a client after authenticationMSCT Windows Server v20H2 DC v1.0.0Windows

ACCESS CONTROL

Internet Explorer Processes - FEATURE_MIME_HANDLING - explorer.exeMSCT Windows Server v20H2 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Internet Explorer Processes - FEATURE_RESTRICT_ACTIVEXINSTALL - iexplore.exeMSCT Windows Server v20H2 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Internet Explorer Processes - FEATURE_RESTRICT_FILEDOWNLOAD - (Reserved)MSCT Windows Server v20H2 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Internet Explorer Processes - FEATURE_RESTRICT_FILEDOWNLOAD - explorer.exeMSCT Windows Server v20H2 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Internet Explorer Processes - FEATURE_WINDOW_RESTRICTIONS - explorer.exeMSCT Windows Server 2025 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Internet Explorer Processes - FEATURE_WINDOW_RESTRICTIONS - iexplore.exeMSCT Windows Server 2025 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Java permissions - Intranet ZoneMSCT Windows Server v20H2 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Java permissions - Local Machine ZoneMSCT Windows Server 2025 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Java permissions - Locked-Down Trusted Sites ZoneMSCT Windows Server 2025 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Java permissions - Locked-Down Trusted Sites ZoneMSCT Windows Server v20H2 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Launching applications and files in an IFRAME - Internet ZoneMSCT Windows Server 2025 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Network access: Do not allow anonymous enumeration of SAM accounts - RestrictAnonymousSAMMSCT Windows Server 2025 DC v1.0.0Windows

ACCESS CONTROL

Network security: Allow LocalSystem NULL session fallback - allownullsessionfallbackMSCT Windows Server 2025 DC v1.0.0Windows

ACCESS CONTROL

Password must meet complexity requirementsMSCT Windows Server 2025 DC v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Prevent bypassing SmartScreen Filter warnings about files that are not commonly downloaded from the InternetMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Prevent ignoring certificate errorsMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Prevent per-user installation of ActiveX controlsMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Remove 'Run this time' button for outdated ActiveX controls in Internet ExplorerMSCT Windows Server 2025 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Run .NET Framework-reliant components not signed with Authenticode - Restricted Sites ZoneMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Scan all downloaded files and attachmentsMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Scripting of Java appletsMSCT Windows Server 2025 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Select the channel for Microsoft Defender monthly platform updatesMSCT Windows Server 2025 DC v1.0.0Windows
Set client connection encryption level - MinEncryptionLevelMSCT Windows Server 2025 DC v1.0.0Windows

ACCESS CONTROL

Specify use of ActiveX Installer Service for installation of ActiveX controlsMSCT Windows Server 2025 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

System objects: Strengthen default permissions of internal system objects (e.g. Symbolic Links) - ProtectionModeMSCT Windows Server 2025 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Turn off multicast name resolution - EnableMulticastMSCT Windows Server 2025 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Turn off the Security Settings Check featureMSCT Windows Server 2025 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Turn on behavior monitoringMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Turn on Cross-Site Scripting Filter - Internet ZoneMSCT Windows Server 2025 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Turn on PowerShell Script Block Logging - EnableScriptBlockInvocationLoggingMSCT Windows Server 2025 DC v1.0.0Windows

ACCESS CONTROL

Turn On Virtualization Based Security - EnableVirtualizationBasedSecurityMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Turn On Virtualization Based Security - HypervisorEnforcedCodeIntegrityMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Turn On Virtualization Based Security - LsaCfgFlagsMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Use Pop-up Blocker - Internet ZoneMSCT Windows Server 2025 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Use Pop-up Blocker - Restricted Sites ZoneMSCT Windows Server 2025 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

User Account Control: Run all administrators in Admin Approval Mode - EnableLUAMSCT Windows Server 2025 DC v1.0.0Windows

ACCESS CONTROL

Userdata persistence - Internet ZoneMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Userdata persistence - Restricted Sites ZoneMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Web sites in less privileged Web content zones can navigate into this zone - Internet ZoneMSCT Windows Server 2025 DC v1.0.0Windows

ACCESS CONTROL