| WN11-00-000005 - Domain-joined systems must use Windows 11 Enterprise Edition 64-bit version. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-00-000015 - Windows 11 systems must have Unified Extensible Firmware Interface (UEFI) firmware and be configured to run in UEFI mode, not Legacy BIOS. | DISA Microsoft Windows 11 STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WN11-00-000020 - Secure Boot must be enabled on Windows 11 systems. | DISA Microsoft Windows 11 STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WN11-00-000032 - Windows 11 systems must use a BitLocker PIN with a minimum length of six digits for pre-boot authentication. | DISA Microsoft Windows 11 STIG v2r9 | Windows | IDENTIFICATION AND AUTHENTICATION |
| WN11-00-000035 - The operating system must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-00-000040 - Windows 11 systems must be maintained at a supported servicing level. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-00-000055 - Alternate operating systems must not be permitted on the same system. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-00-000070 - Only accounts responsible for the administration of a system must have Administrator rights on the system. | DISA Microsoft Windows 11 STIG v2r9 | Windows | ACCESS CONTROL |
| WN11-00-000085 - Standard local user accounts must not exist on a system in a domain. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-00-000090 - Accounts must be configured to require password expiration. | DISA Microsoft Windows 11 STIG v2r9 | Windows | IDENTIFICATION AND AUTHENTICATION |
| WN11-00-000110 - Simple TCP/IP Services must not be installed on the system. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-00-000125 - Copilot must be disabled for Windows 11. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-00-000126 - Windows 11 systems must block consumer account user authentication. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-00-000140 - Inbound exceptions to the firewall on Windows 11 domain workstations must only allow authorized remote management hosts. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-00-000165 - The Server Message Block (SMB) v1 protocol must be disabled on the SMB server. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-00-000240 - Administrative accounts must not be used with applications that access the internet, such as web browsers, or with potential internet sources, such as email. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-AC-000025 - The maximum password age must be configured to 60 days or less. | DISA Microsoft Windows 11 STIG v2r9 | Windows | IDENTIFICATION AND AUTHENTICATION |
| WN11-AC-000040 - The built-in Microsoft password complexity filter must be enabled. | DISA Microsoft Windows 11 STIG v2r9 | Windows | IDENTIFICATION AND AUTHENTICATION |
| WN11-AU-000045 - The system must be configured to audit Detailed Tracking - PNP Activity successes. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT |
| WN11-AU-000060 - The system must be configured to audit Logon/Logoff - Group Membership successes. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-AU-000080 - The system must be configured to audit Logon/Logoff - Special Logon successes. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-AU-000090 - The system must be configured to audit Object Access - Removable Storage successes. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-AU-000160 - The system must be configured to audit System - System Integrity successes. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-AU-000585 - Windows 11 must have command line process auditing events enabled for failures. | DISA Microsoft Windows 11 STIG v2r9 | Windows | ACCESS CONTROL |
| WN11-AU-000587 - Windows 11 must be configured to audit sensitive privilege use successes. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-CC-000007 - Windows 11 must cover or disable the built-in or attached camera when not in use. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000010 - The display of slide shows on the lock screen must be disabled. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000037 - Local administrator accounts must have their privileged token filtered to prevent elevated privileges from being used over the network on domain systems. | DISA Microsoft Windows 11 STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WN11-CC-000044 - Internet connection sharing must be disabled. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000050 - Hardened UNC Paths must be defined to require mutual authentication and integrity for at least the \\*\SYSVOL and \\*\NETLOGON shares. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000052 - Windows 11 must be configured to prioritize ECC Curves with longer key lengths first. | DISA Microsoft Windows 11 STIG v2r9 | Windows | IDENTIFICATION AND AUTHENTICATION |
| WN11-CC-000055 - Simultaneous connections to the internet or a Windows domain must be limited. | DISA Microsoft Windows 11 STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WN11-CC-000075 - Credential Guard must be running on Windows 11 systems. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000090 - Group Policy objects must be reprocessed even if they have not changed. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000105 - Web publishing and online ordering wizards must be prevented from downloading a list of providers. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000110 - Printing over HTTP must be prevented. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000120 - The network selection user interface (UI) must not be displayed on the logon screen. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000210 - The Microsoft Defender SmartScreen for Explorer must be enabled. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000252 - Windows 11 must be configured to disable Windows Game Recording and Broadcasting. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000255 - The use of a hardware security device with Windows Hello for Business must be enabled. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000275 - Local drives must be prevented from sharing with Remote Desktop Session Hosts. | DISA Microsoft Windows 11 STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WN11-CC-000315 - The Windows Installer feature 'Always install with elevated privileges' must be disabled. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000345 - The Windows Remote Management (WinRM) service must not use Basic authentication. | DISA Microsoft Windows 11 STIG v2r9 | Windows | MAINTENANCE |
| WN11-CC-000350 - The Windows Remote Management (WinRM) service must not allow unencrypted traffic. | DISA Microsoft Windows 11 STIG v2r9 | Windows | MAINTENANCE |
| WN11-CC-000385 - Windows Ink Workspace must be configured to disallow access above the lock. | DISA Microsoft Windows 11 STIG v2r9 | Windows | ACCESS CONTROL |
| WN11-PK-000005 - The DoW Root CA certificates must be installed in the Trusted Root Store. | DISA Microsoft Windows 11 STIG v2r9 | Windows | IDENTIFICATION AND AUTHENTICATION |
| WN11-SO-000025 - The built-in guest account must be renamed. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WNDF-AV-000050 - Microsoft Defender AV must block Office communication application from creating child processes. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000065 - Microsoft Defender AV must enable real-time protection and Security Intelligence Updates during OOBE. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| WNDF-AV-000068 - Microsoft Defender AV must enable network protection to be configured into block or audit mode on Windows Server. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |