Item Search

NameAudit NamePluginCategory
WN11-00-000005 - Domain-joined systems must use Windows 11 Enterprise Edition 64-bit version.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-00-000015 - Windows 11 systems must have Unified Extensible Firmware Interface (UEFI) firmware and be configured to run in UEFI mode, not Legacy BIOS.DISA Microsoft Windows 11 STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN11-00-000020 - Secure Boot must be enabled on Windows 11 systems.DISA Microsoft Windows 11 STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN11-00-000032 - Windows 11 systems must use a BitLocker PIN with a minimum length of six digits for pre-boot authentication.DISA Microsoft Windows 11 STIG v2r9Windows

IDENTIFICATION AND AUTHENTICATION

WN11-00-000035 - The operating system must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-00-000040 - Windows 11 systems must be maintained at a supported servicing level.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-00-000055 - Alternate operating systems must not be permitted on the same system.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-00-000070 - Only accounts responsible for the administration of a system must have Administrator rights on the system.DISA Microsoft Windows 11 STIG v2r9Windows

ACCESS CONTROL

WN11-00-000085 - Standard local user accounts must not exist on a system in a domain.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-00-000090 - Accounts must be configured to require password expiration.DISA Microsoft Windows 11 STIG v2r9Windows

IDENTIFICATION AND AUTHENTICATION

WN11-00-000110 - Simple TCP/IP Services must not be installed on the system.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-00-000125 - Copilot must be disabled for Windows 11.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-00-000126 - Windows 11 systems must block consumer account user authentication.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-00-000140 - Inbound exceptions to the firewall on Windows 11 domain workstations must only allow authorized remote management hosts.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-00-000165 - The Server Message Block (SMB) v1 protocol must be disabled on the SMB server.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-00-000240 - Administrative accounts must not be used with applications that access the internet, such as web browsers, or with potential internet sources, such as email.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-AC-000025 - The maximum password age must be configured to 60 days or less.DISA Microsoft Windows 11 STIG v2r9Windows

IDENTIFICATION AND AUTHENTICATION

WN11-AC-000040 - The built-in Microsoft password complexity filter must be enabled.DISA Microsoft Windows 11 STIG v2r9Windows

IDENTIFICATION AND AUTHENTICATION

WN11-AU-000045 - The system must be configured to audit Detailed Tracking - PNP Activity successes.DISA Microsoft Windows 11 STIG v2r9Windows

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

WN11-AU-000060 - The system must be configured to audit Logon/Logoff - Group Membership successes.DISA Microsoft Windows 11 STIG v2r9Windows

AUDIT AND ACCOUNTABILITY

WN11-AU-000080 - The system must be configured to audit Logon/Logoff - Special Logon successes.DISA Microsoft Windows 11 STIG v2r9Windows

AUDIT AND ACCOUNTABILITY

WN11-AU-000090 - The system must be configured to audit Object Access - Removable Storage successes.DISA Microsoft Windows 11 STIG v2r9Windows

AUDIT AND ACCOUNTABILITY

WN11-AU-000160 - The system must be configured to audit System - System Integrity successes.DISA Microsoft Windows 11 STIG v2r9Windows

AUDIT AND ACCOUNTABILITY

WN11-AU-000585 - Windows 11 must have command line process auditing events enabled for failures.DISA Microsoft Windows 11 STIG v2r9Windows

ACCESS CONTROL

WN11-AU-000587 - Windows 11 must be configured to audit sensitive privilege use successes.DISA Microsoft Windows 11 STIG v2r9Windows

AUDIT AND ACCOUNTABILITY

WN11-CC-000007 - Windows 11 must cover or disable the built-in or attached camera when not in use.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-CC-000010 - The display of slide shows on the lock screen must be disabled.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-CC-000037 - Local administrator accounts must have their privileged token filtered to prevent elevated privileges from being used over the network on domain systems.DISA Microsoft Windows 11 STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN11-CC-000044 - Internet connection sharing must be disabled.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-CC-000050 - Hardened UNC Paths must be defined to require mutual authentication and integrity for at least the \\*\SYSVOL and \\*\NETLOGON shares.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-CC-000052 - Windows 11 must be configured to prioritize ECC Curves with longer key lengths first.DISA Microsoft Windows 11 STIG v2r9Windows

IDENTIFICATION AND AUTHENTICATION

WN11-CC-000055 - Simultaneous connections to the internet or a Windows domain must be limited.DISA Microsoft Windows 11 STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN11-CC-000075 - Credential Guard must be running on Windows 11 systems.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-CC-000090 - Group Policy objects must be reprocessed even if they have not changed.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-CC-000105 - Web publishing and online ordering wizards must be prevented from downloading a list of providers.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-CC-000110 - Printing over HTTP must be prevented.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-CC-000120 - The network selection user interface (UI) must not be displayed on the logon screen.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-CC-000210 - The Microsoft Defender SmartScreen for Explorer must be enabled.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-CC-000252 - Windows 11 must be configured to disable Windows Game Recording and Broadcasting.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-CC-000255 - The use of a hardware security device with Windows Hello for Business must be enabled.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-CC-000275 - Local drives must be prevented from sharing with Remote Desktop Session Hosts.DISA Microsoft Windows 11 STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN11-CC-000315 - The Windows Installer feature 'Always install with elevated privileges' must be disabled.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-CC-000345 - The Windows Remote Management (WinRM) service must not use Basic authentication.DISA Microsoft Windows 11 STIG v2r9Windows

MAINTENANCE

WN11-CC-000350 - The Windows Remote Management (WinRM) service must not allow unencrypted traffic.DISA Microsoft Windows 11 STIG v2r9Windows

MAINTENANCE

WN11-CC-000385 - Windows Ink Workspace must be configured to disallow access above the lock.DISA Microsoft Windows 11 STIG v2r9Windows

ACCESS CONTROL

WN11-PK-000005 - The DoW Root CA certificates must be installed in the Trusted Root Store.DISA Microsoft Windows 11 STIG v2r9Windows

IDENTIFICATION AND AUTHENTICATION

WN11-SO-000025 - The built-in guest account must be renamed.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WNDF-AV-000050 - Microsoft Defender AV must block Office communication application from creating child processes.DISA Microsoft Defender Antivirus STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WNDF-AV-000065 - Microsoft Defender AV must enable real-time protection and Security Intelligence Updates during OOBE.DISA Microsoft Defender Antivirus STIG v2r9Windows

SYSTEM AND INFORMATION INTEGRITY

WNDF-AV-000068 - Microsoft Defender AV must enable network protection to be configured into block or audit mode on Windows Server.DISA Microsoft Defender Antivirus STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION