| WN11-00-000010 - Windows 11 systems must have a Trusted Platform Module (TPM) enabled. | DISA Microsoft Windows 11 STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WN11-00-000045 - The Windows 11 system must use an antivirus program. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-00-000050 - Local volumes must be formatted using NTFS. | DISA Microsoft Windows 11 STIG v2r9 | Windows | ACCESS CONTROL |
| WN11-00-000060 - Non-system-created file shares on a system must limit access to groups that require it. | DISA Microsoft Windows 11 STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WN11-00-000075 - Only accounts responsible for the backup operations must be members of the Backup Operators group. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-00-000080 - Only authorized user accounts must be allowed to create or run virtual machines on Windows 11 systems. | DISA Microsoft Windows 11 STIG v2r9 | Windows | ACCESS CONTROL |
| WN11-00-000095 - Permissions for system files and directories must conform to minimum requirements. | DISA Microsoft Windows 11 STIG v2r9 | Windows | ACCESS CONTROL |
| WN11-00-000105 - Simple Network Management Protocol (SNMP) must not be installed on the system. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-00-000115 - The Telnet Client must not be installed on the system. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-00-000130 - Software certificate installation files must be removed from Windows 11. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-00-000170 - The Server Message Block (SMB) v1 protocol must be disabled on the SMB client. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-00-000395 - Windows 11 must not have portproxy enabled or in use. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-00-000400 - All Wi-Fi Direct adapters must be disabled on the system. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-AC-000005 - Windows 11 account lockout duration must be configured to 15 minutes or greater. | DISA Microsoft Windows 11 STIG v2r9 | Windows | ACCESS CONTROL |
| WN11-AC-000015 - The period of time before the bad logon counter is reset must be configured to 15 minutes. | DISA Microsoft Windows 11 STIG v2r9 | Windows | ACCESS CONTROL |
| WN11-AC-000020 - The password history must be configured to 24 passwords remembered. | DISA Microsoft Windows 11 STIG v2r9 | Windows | IDENTIFICATION AND AUTHENTICATION |
| WN11-AU-000083 - Windows 11 must be configured to audit Object Access - Other Object Access Events successes. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-AU-000107 - The system must be configured to audit Policy Change - Authorization Policy Change successes. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-AU-000500 - The Application event log size must be configured to 32768 KB or greater. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-AU-000510 - The System event log size must be configured to 32768 KB or greater. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-AU-000515 - Windows 11 permissions for the Application event log must prevent access by non-privileged accounts. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-AU-000520 - Windows 11 permissions for the Security event log must prevent access by non-privileged accounts. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-AU-000525 - Windows 11 permissions for the System event log must prevent access by non-privileged accounts. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-AU-000560 - Windows 11 must be configured to audit other Logon/Logoff Events Successes. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-AU-000575 - Windows 11 must be configured to audit MPSSVC Rule-Level Policy Change Successes. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-AU-000589 - Windows 11 must be configured to audit registry failures. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-CC-000020 - IPv6 source routing must be configured to highest protection. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000068 - Windows 11 must be configured to enable Remote host allows delegation of non-exportable credentials. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000100 - Downloading print driver packages over HTTP must be prevented. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000155 - Solicited Remote Assistance must not be allowed. | DISA Microsoft Windows 11 STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WN11-CC-000280 - Remote Desktop Services must always prompt a client for passwords upon connection. | DISA Microsoft Windows 11 STIG v2r9 | Windows | IDENTIFICATION AND AUTHENTICATION |
| WN11-CC-000285 - The Remote Desktop Session Host must require secure RPC communications. | DISA Microsoft Windows 11 STIG v2r9 | Windows | ACCESS CONTROL |
| WN11-CC-000300 - Basic authentication for RSS feeds over HTTP must not be used. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000320 - Users must be notified if a web-based program attempts to install software. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000326 - PowerShell script block logging must be enabled on Windows 11. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-CC-000327 - PowerShell Transcription must be enabled on Windows 11. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-CC-000330 - The Windows Remote Management (WinRM) client must not use Basic authentication. | DISA Microsoft Windows 11 STIG v2r9 | Windows | MAINTENANCE |
| WN11-CC-000335 - The Windows Remote Management (WinRM) client must not allow unencrypted traffic. | DISA Microsoft Windows 11 STIG v2r9 | Windows | MAINTENANCE |
| WN11-CC-000360 - The Windows Remote Management (WinRM) client must not use Digest authentication. | DISA Microsoft Windows 11 STIG v2r9 | Windows | MAINTENANCE |
| WN11-CC-000365 - Windows 11 must be configured to prevent Windows apps from being activated by voice while the system is locked. | DISA Microsoft Windows 11 STIG v2r9 | Windows | ACCESS CONTROL |
| WN11-CC-000391 - Internet Explorer must be disabled for Windows 11. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-PK-000010 - The External Root CA certificates must be installed in the Trusted Root Store on unclassified systems. | DISA Microsoft Windows 11 STIG v2r9 | Windows | IDENTIFICATION AND AUTHENTICATION |
| WN11-SO-000020 - The built-in administrator account must be renamed. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WNDF-AV-000048 - Microsoft Defender AV must audit persistence through WMI event subscription. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000055 - Microsoft Defender AV must randomize scheduled task times. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| WNDF-AV-000056 - Microsoft Defender AV must hide the Family options area. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000057 - Microsoft Defender AV must enable the file hash computation feature. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000070 - Microsoft Defender AV must enable EDR in block mode. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000074 - Microsoft Defender AV must convert warn verdict to block. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000076 - Microsoft Defender AV must scan packed executables. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND INFORMATION INTEGRITY |