Item Search

NameAudit NamePluginCategory
2.2.9 (L1) Ensure 'Allow log on through Remote Desktop Services' is set to 'Administrators' (DC only)CIS Microsoft Windows Server 2016 v4.0.0 L1 DCWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.9 Ensure 'Allow log on through Remote Desktop Services' is set to 'Administrators' (DC only)CIS Microsoft Windows Server 2019 v5.0.0 L1 DCWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.9 Ensure 'Allow log on through Remote Desktop Services' is set to 'Administrators' (DC only)CIS Microsoft Windows Server 2025 v2.1.0 L1 DCWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

18.9.7.2 Ensure 'Prevent automatic download of applications associated with device metadata' is set to 'Enabled'CIS Microsoft Windows 11 Stand-alone v5.0.0 L1 BLWindows

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

18.9.7.2 Ensure 'Prevent automatic download of applications associated with device metadata' is set to 'Enabled'CIS Microsoft Windows Server 2019 v5.0.0 L1 DCWindows

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

18.9.7.2 Ensure 'Prevent automatic download of applications associated with device metadata' is set to 'Enabled'CIS Microsoft Windows Server 2019 v5.0.0 L1 MSWindows

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

18.9.7.2 Ensure 'Prevent automatic download of applications associated with device metadata' is set to 'Enabled'CIS Microsoft Windows 11 Enterprise v5.1.0 L1 BLWindows

CONFIGURATION MANAGEMENT

18.9.7.2 Ensure 'Prevent automatic download of applications associated with device metadata' is set to 'Enabled'CIS Microsoft Windows Server 2022 v5.1.0 L1 MSWindows

CONFIGURATION MANAGEMENT

18.9.7.2 Ensure 'Prevent automatic download of applications associated with device metadata' is set to 'Enabled'CIS Microsoft Windows 11 Stand-alone v5.0.0 L1Windows

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

18.9.7.2 Ensure 'Prevent automatic download of applications associated with device metadata' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise v5.0.0 L1 BL NGWindows

CONFIGURATION MANAGEMENT

18.9.7.2 Ensure 'Prevent automatic download of applications associated with device metadata' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise v5.0.0 L1 NGWindows

CONFIGURATION MANAGEMENT

18.9.7.2 Ensure 'Prevent automatic download of applications associated with device metadata' is set to 'Enabled'CIS Microsoft Windows Server 2025 Stand-alone v2.0.0 L1 MSWindows

CONFIGURATION MANAGEMENT

18.9.7.2 Ensure 'Prevent automatic download of applications associated with device metadata' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise v5.0.0 L1Windows

CONFIGURATION MANAGEMENT

Default Protections for Recommended Software - AcrobatMSCT Windows Server 2012 R2 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Default Protections for Recommended Software - AcrobatReaderMSCT Windows Server 2012 R2 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Default Protections for Recommended Software - InfoPathMSCT Windows Server 2012 R2 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Default Protections for Recommended Software - jre7_javawsMSCT Windows Server 2012 R2 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Default Protections for Recommended Software - VisioViewerMSCT Windows Server 2012 R2 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Default Protections for Recommended Software - WordpadMSCT Windows Server 2012 R2 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Deny log on as a serviceMSCT Windows Server 2012 R2 DC v1.0.0Windows

ACCESS CONTROL

Deny log on through Remote Desktop ServicesMSCT Windows Server 2012 R2 DC v1.0.0Windows

ACCESS CONTROL

Domain controller: LDAP server signing requirementsMSCT Windows Server 2012 R2 DC v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Domain member: Disable machine account password changesMSCT Windows Server 2012 R2 DC v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Lock pages in memoryMSCT Windows Server 2012 R2 DC v1.0.0Windows

ACCESS CONTROL

Manage auditing and security logMSCT Windows Server 2012 R2 DC v1.0.0Windows

ACCESS CONTROL

Microsoft network client: Send unencrypted password to third-party SMB servers - EnablePlainTextPasswordMSCT Windows Server 2012 R2 DC v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Microsoft network server: Amount of idle time required before suspending sessionMSCT Windows Server 2012 R2 DC v1.0.0Windows

ACCESS CONTROL

Modify an object labelMSCT Windows Server 2012 R2 DC v1.0.0Windows

ACCESS CONTROL

Modify firmware environment valuesMSCT Windows Server 2012 R2 DC v1.0.0Windows

ACCESS CONTROL

Network access: Let Everyone permissions apply to anonymous usersMSCT Windows Server 2012 R2 DC v1.0.0Windows

ACCESS CONTROL

Network security: LAN Manager authentication levelMSCT Windows 11 v24H2 v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Network security: LAN Manager authentication levelMSCT Windows 10 v1507 v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Network security: LAN Manager authentication levelMSCT Windows 10 1909 v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Network security: LAN Manager authentication levelMSCT Windows 10 v21H1 v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Network security: LAN Manager authentication levelMSCT Windows 10 v21H2 v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Network security: LAN Manager authentication levelMSCT Windows Server v2004 DC v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Network security: Minimum session security for NTLM SSP based (including secure RPC) clientsMSCT Windows Server 2012 R2 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Network security: Minimum session security for NTLM SSP based (including secure RPC) serversMSCT Windows Server 2012 R2 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Replace a process level tokenMSCT Windows Server 2012 R2 DC v1.0.0Windows

ACCESS CONTROL

Sign-in last interactive user automatically after a system-initiated restartMSCT Windows Server 2012 R2 DC v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Specify the maximum log file size (KB) - SecurityMSCT Windows Server 2012 R2 DC v1.0.0Windows

AUDIT AND ACCOUNTABILITY

Synchronize directory service dataMSCT Windows Server 2012 R2 DC v1.0.0Windows

ACCESS CONTROL

System DEPMSCT Windows Server 2012 R2 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

System objects: Require case insensitivity for non-Windows subsystemsMSCT Windows Server 2012 R2 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

System settings: Use Certificate Rules on Windows Executables for Software Restriction PoliciesMSCT Windows Server 2012 R2 DC v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

User Account Control: Admin Approval Mode for the Built-in Administrator accountMSCT Windows Server 2012 R2 DC v1.0.0Windows

ACCESS CONTROL

User Account Control: Detect application installations and prompt for elevationMSCT Windows Server 2012 R2 DC v1.0.0Windows

ACCESS CONTROL

User Account Control: Only elevate UIAccess applications that are installed in secure locationsMSCT Windows Server 2012 R2 DC v1.0.0Windows

ACCESS CONTROL

User Account Control: Run all administrators in Admin Approval ModeMSCT Windows Server 2012 R2 DC v1.0.0Windows

ACCESS CONTROL

User Account Control: Switch to the secure desktop when prompting for elevationMSCT Windows Server 2012 R2 DC v1.0.0Windows

ACCESS CONTROL