Item Search

NameAudit NamePluginCategory
3.1.1 (L1) Ensure Microsoft 365 audit log search is EnabledCIS Microsoft 365 Foundations v5.0.0 L1 E5microsoft_azure

AUDIT AND ACCOUNTABILITY

Configure hash algorithms for certificate logon - Kerberos PKInitSHA512MSCT Windows Server 2025 MS v1.0.0Windows
Control whether or not exclusions are visible to Local AdminsMSCT Windows Server 2025 MS v1.0.0Windows
Create a token objectMSCT Windows Server 2025 MS v1.0.0Windows

ACCESS CONTROL

Disallow Digest authentication - Client - AllowDigestMSCT Windows Server 2025 MS v1.0.0Windows

ACCESS CONTROL

Do not allow passwords to be saved - DisablePasswordSavingMSCT Windows Server 2025 MS v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Domain member: Digitally encrypt secure channel data (when possible) - sealsecurechannelMSCT Windows Server 2025 MS v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Don't run antimalware programs against ActiveX controls - Local Machine ZoneMSCT Windows Server 2025 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Download signed ActiveX controls - Restricted Sites ZoneMSCT Windows Server 2025 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Download unsigned ActiveX controls - Internet ZoneMSCT Windows Server 2025 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Enable Structured Exception Handling Overwrite Protection (SEHOP) - DisableExceptionChainValidationMSCT Windows Server 2025 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Impersonate a client after authenticationMSCT Windows Server 2025 MS v1.0.0Windows

ACCESS CONTROL

Include local path when user is uploading files to a server - Restricted Sites ZoneMSCT Windows Server 2025 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Interactive logon: Machine inactivity limit - InactivityTimeoutSecsMSCT Windows Server 2025 MS v1.0.0Windows

ACCESS CONTROL

Internet Explorer Processes - FEATURE_MIME_SNIFFING - (Reserved)MSCT Windows Server 2025 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Internet Explorer Processes - FEATURE_MIME_SNIFFING - iexplore.exeMSCT Windows Server 2025 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Internet Explorer Processes - FEATURE_SECURITYBAND - explorer.exeMSCT Windows Server 2025 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Internet Explorer Processes - FEATURE_SECURITYBAND - iexplore.exeMSCT Windows Server 2025 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Internet Explorer Processes - FEATURE_WINDOW_RESTRICTIONS - explorer.exeMSCT Windows Server 2025 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Java permissions - Locked-Down Local Machine ZoneMSCT Windows Server 2025 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Java permissions - Locked-Down Restricted Sites ZoneMSCT Windows Server 2025 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Java permissions - Restricted Sites ZoneMSCT Windows Server 2025 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Microsoft network client: Send unencrypted password to third-party SMB servers - EnablePlainTextPasswordMSCT Windows Server 2025 MS v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Modify firmware environment valuesMSCT Windows Server 2025 MS v1.0.0Windows

ACCESS CONTROL

MSS: (DisableIPSourceRouting IPv6) IP source routing protection level - DisableIPSourceRoutingMSCT Windows Server 2025 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Navigate windows and frames across different domains - Restricted Sites ZoneMSCT Windows Server 2025 MS v1.0.0Windows

ACCESS CONTROL

Network access: Restrict anonymous access to Named Pipes and Shares - RestrictNullSessAccessMSCT Windows Server 2025 MS v1.0.0Windows

ACCESS CONTROL

Network security: Allow LocalSystem NULL session fallback - allownullsessionfallbackMSCT Windows Server 2025 MS v1.0.0Windows

ACCESS CONTROL

Network security: LAN Manager authentication level - LmCompatibilityLevelMSCT Windows Server 2025 MS v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Profile single processMSCT Windows Server 2025 MS v1.0.0Windows

ACCESS CONTROL

Remote host allows delegation of non-exportable credentials - AllowProtectedCredsMSCT Windows Server 2025 MS v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Run .NET Framework-reliant components not signed with Authenticode - Internet ZoneMSCT Windows Server 2025 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Run .NET Framework-reliant components signed with Authenticode - Restricted Sites ZoneMSCT Windows Server 2025 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Scripting of Java appletsMSCT Windows Server 2025 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Select the channel for Microsoft Defender daily security intelligence updatesMSCT Windows Server 2025 MS v1.0.0Windows
Show security warning for potentially unsafe files - Restricted Sites ZoneMSCT Windows Server 2025 MS v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Specify the maximum log file size (KB) - SecurityMSCT Windows Server 2025 MS v1.0.0Windows

AUDIT AND ACCOUNTABILITY

Specify use of ActiveX Installer Service for installation of ActiveX controlsMSCT Windows Server 2025 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

This security setting determines whether the builtin Administrator account is subject to account lockout policy - AllowAdministratorLockoutMSCT Windows Server 2025 MS v1.0.0Windows

ACCESS CONTROL

Turn off the Security Settings Check featureMSCT Windows Server 2025 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Turn on Enhanced Protected ModeMSCT Windows Server 2025 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Turn on script scanningMSCT Windows Server 2025 MS v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Turn on the auto-complete feature for user names and passwords on forms - FormSuggest PW AskMSCT Windows Server 2025 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Turn On Virtualization Based Security - HypervisorEnforcedCodeIntegrityMSCT Windows Server 2025 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Turn On Virtualization Based Security - LsaCfgFlagsMSCT Windows Server 2025 MS v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Use Pop-up Blocker - Internet ZoneMSCT Windows Server 2025 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

User Account Control: Detect application installations and prompt for elevation - EnableInstallerDetectionMSCT Windows Server 2025 MS v1.0.0Windows

ACCESS CONTROL

User Account Control: Virtualize file and registry write failures to per-user locations - EnableVirtualizationMSCT Windows Server 2025 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Web sites in less privileged Web content zones can navigate into this zone - Internet ZoneMSCT Windows Server 2025 MS v1.0.0Windows

ACCESS CONTROL

Web sites in less privileged Web content zones can navigate into this zone - Restricted Sites ZoneMSCT Windows Server 2025 MS v1.0.0Windows

ACCESS CONTROL