| WN11-00-000190 - Orphaned security identifiers (SIDs) must be removed from user rights on Windows 11. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-00-000260 - The Windows 11 time service must synchronize with an appropriate DoW time source. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-AU-000050 - The system must be configured to audit Detailed Tracking - Process Creation successes. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT |
| WN11-AU-000082 - Windows 11 must be configured to audit Object Access - File Share successes. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-AU-000084 - Windows 11 must be configured to audit Object Access - Other Object Access Events failures. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-AU-000140 - The system must be configured to audit System - Security State Change successes. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-AU-000555 - Windows 11 must be configured to audit Other Policy Change Events Failures. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-AU-000570 - Windows 11 must be configured to audit Detailed File Share Failures. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-CC-000025 - The system must be configured to prevent IP source routing. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000035 - The system must be configured to ignore NetBIOS name release requests except from WINS servers. | DISA Microsoft Windows 11 STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WN11-CC-000038 - WDigest Authentication must be disabled. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000040 - Insecure logons to an SMB server must be disabled. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000063 - Windows 11 systems must use either Group Policy or an approved Mobile Device Management (MDM) product to enforce STIG compliance. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000066 - Command line data must be included in process creation events. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-CC-000070 - Virtualization-Based Security (VBS) must be enabled on Windows 11 with the platform security level configured to Secure Boot or Secure Boot with DMA Protection. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000080 - Virtualization-based protection of code integrity must be enabled. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000130 - Local users on domain-joined computers must not be enumerated. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000165 - Unauthenticated RPC clients must be restricted from connecting to the RPC server. | DISA Microsoft Windows 11 STIG v2r9 | Windows | IDENTIFICATION AND AUTHENTICATION |
| WN11-CC-000170 - The setting to allow Microsoft accounts to be optional for modern style apps must be enabled. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000175 - The Application Compatibility Program Inventory must be prevented from collecting data and sending the information to Microsoft. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000180 - Autoplay must be turned off for non-volume devices. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000195 - Enhanced anti-spoofing for facial recognition must be enabled on Windows 11. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000200 - Administrator accounts must not be enumerated during elevation. | DISA Microsoft Windows 11 STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WN11-CC-000205 - Windows Telemetry must not be configured to Full. | DISA Microsoft Windows 11 STIG v2r9 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| WN11-CC-000260 - Windows 11 must be configured to require a minimum PIN length of six characters or greater. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000290 - Remote Desktop Services must be configured with the client connection encryption set to the required level. | DISA Microsoft Windows 11 STIG v2r9 | Windows | ACCESS CONTROL |
| WN11-CC-000325 - Automatically signing in the last interactive user after a system-initiated restart must be disabled. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-CC-000390 - Windows 11 must be configured to prevent users from receiving suggestions for third-party or additional applications. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-EP-000310 - Windows 11 Kernel (Direct Memory Access) DMA Protection must be enabled. | DISA Microsoft Windows 11 STIG v2r9 | Windows | AUDIT AND ACCOUNTABILITY |
| WN11-PK-000015 - The DoW Interoperability Root CA cross-certificates must be installed in the Untrusted Certificates Store on unclassified systems. | DISA Microsoft Windows 11 STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WN11-PK-000020 - The US DoW CCEB Interoperability Root CA cross-certificates must be installed in the Untrusted Certificates Store on unclassified systems. | DISA Microsoft Windows 11 STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WN11-RG-000005 - Default permissions for the HKEY_LOCAL_MACHINE registry hive must be maintained. | DISA Microsoft Windows 11 STIG v2r9 | Windows | ACCESS CONTROL |
| WN11-SO-000010 - The built-in guest account must be disabled. | DISA Microsoft Windows 11 STIG v2r9 | Windows | IDENTIFICATION AND AUTHENTICATION |
| WN11-SO-000045 - Outgoing secure channel traffic must be signed. | DISA Microsoft Windows 11 STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WN11-SO-000120 - The Windows SMB server must be configured to always perform SMB packet signing. | DISA Microsoft Windows 11 STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WN11-SO-000167 - Remote calls to the Security Account Manager (SAM) must be restricted to Administrators. | DISA Microsoft Windows 11 STIG v2r9 | Windows | ACCESS CONTROL |
| WN11-SO-000180 - NTLM must be prevented from falling back to a Null session. | DISA Microsoft Windows 11 STIG v2r9 | Windows | CONFIGURATION MANAGEMENT |
| WN11-SO-000195 - The system must be configured to prevent the storage of the LAN Manager hash of passwords. | DISA Microsoft Windows 11 STIG v2r9 | Windows | IDENTIFICATION AND AUTHENTICATION |
| WN11-SO-000250 - User Account Control must prompt administrators for consent on the secure desktop. | DISA Microsoft Windows 11 STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WN11-SO-000255 - User Account Control must automatically deny elevation requests for standard users. | DISA Microsoft Windows 11 STIG v2r9 | Windows | IDENTIFICATION AND AUTHENTICATION |
| WN11-SO-000275 - User Account Control must virtualize file and registry write failures to per-user locations. | DISA Microsoft Windows 11 STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WN11-SO-000280 - Passwords for enabled local Administrator accounts must be changed at least every 60 days. | DISA Microsoft Windows 11 STIG v2r9 | Windows | IDENTIFICATION AND AUTHENTICATION |
| WN11-UR-000005 - The 'Access Credential Manager as a trusted caller' user right must not be assigned to any groups or accounts. | DISA Microsoft Windows 11 STIG v2r9 | Windows | ACCESS CONTROL |
| WN11-UR-000025 - The 'Allow log on locally' user right must only be assigned to the Administrators and Users groups. | DISA Microsoft Windows 11 STIG v2r9 | Windows | ACCESS CONTROL |
| WN11-UR-000035 - The 'Change the system time' user right must only be assigned to Administrators and Local Service. | DISA Microsoft Windows 11 STIG v2r9 | Windows | ACCESS CONTROL |
| WN11-UR-000050 - The 'Create global objects' user right must only be assigned to Administrators, Service, Local Service, and Network Service. | DISA Microsoft Windows 11 STIG v2r9 | Windows | ACCESS CONTROL |
| WNDF-AV-000071 - Microsoft Defender AV must report Dynamic Signature dropped events. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000075 - Microsoft Defender AV must enable asynchronous inspection. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| WNDF-AV-000077 - Microsoft Defender AV must enable heuristics. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| WNDF-AV-000100 - Microsoft Defender AV must control whether exclusions are visible to Local Admins. | DISA Microsoft Defender Antivirus STIG v2r9 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |