Item Search

NameAudit NamePluginCategory
17.5.1 (L1) Ensure 'Audit Account Lockout' is set to include 'Failure'CIS Microsoft Windows Server 2016 v3.0.0 L1 DCWindows

AUDIT AND ACCOUNTABILITY

17.5.2 (L1) Ensure 'Audit Group Membership' is set to include 'Success'CIS Microsoft Windows Server 2016 v3.0.0 L1 DCWindows

AUDIT AND ACCOUNTABILITY

17.9.1 (L1) Ensure 'Audit IPsec Driver' is set to 'Success and Failure'CIS Microsoft Windows Server 2016 v3.0.0 L1 DCWindows

AUDIT AND ACCOUNTABILITY

18.10.15.3 (L1) Ensure 'Disable OneSettings Downloads' is set to 'Enabled'CIS Microsoft Windows Server 2016 v3.0.0 L1 DCWindows

SYSTEM AND INFORMATION INTEGRITY

18.10.25.1.1 (L1) Ensure 'Application: Control Event Log behavior when the log file reaches its maximum size' is set to 'Disabled'CIS Microsoft Windows Server 2016 v3.0.0 L1 DCWindows

AUDIT AND ACCOUNTABILITY

Configure hash algorithms for certificate logon - Kerberos PKInitSHA512MSCT Windows Server 2025 DC v1.0.0Windows
Configure real-time protection and Security Intelligence Updates during OOBEMSCT Windows Server 2025 DC v1.0.0Windows
Configure registry policy processing - NoBackgroundPolicyMSCT Windows Server 2025 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Control whether exclusions are visible to local usersMSCT Windows Server 2025 DC v1.0.0Windows
Debug programsMSCT Windows Server 2025 DC v1.0.0Windows

ACCESS CONTROL

Don't run antimalware programs against ActiveX controls - Internet ZoneMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Don't run antimalware programs against ActiveX controls - Local Machine ZoneMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Don't run antimalware programs against ActiveX controls - Restricted Sites ZoneMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Download unsigned ActiveX controls - Internet ZoneMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Download unsigned ActiveX controls - Restricted Sites ZoneMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Enable computer and user accounts to be trusted for delegationMSCT Windows Server 2025 DC v1.0.0Windows

ACCESS CONTROL

Enable dragging of content from different domains across windows - Internet ZoneMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Enable dragging of content from different domains within a window - Internet ZoneMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Enable dragging of content from different domains within a window - Restricted Sites ZoneMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Enable Structured Exception Handling Overwrite Protection (SEHOP) - DisableExceptionChainValidationMSCT Windows Server 2025 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Extended Protection for LDAP Authentication (Domain Controllers only) (DEPRECATED)MSCT Windows Server 2025 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Force shutdown from a remote systemMSCT Windows Server 2025 DC v1.0.0Windows

ACCESS CONTROL

Initialize and script ActiveX controls not marked as safe - Trusted Sites ZoneMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Interactive logon: Machine inactivity limit - InactivityTimeoutSecsMSCT Windows Server 2025 DC v1.0.0Windows

ACCESS CONTROL

Interactive logon: Smart card removal behavior - ScRemoveOptionMSCT Windows Server 2025 DC v1.0.0Windows

ACCESS CONTROL

Internet Explorer Processes - FEATURE_MIME_HANDLING - explorer.exeMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Internet Explorer Processes - FEATURE_RESTRICT_ACTIVEXINSTALL - iexplore.exeMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Internet Explorer Processes - FEATURE_SECURITYBAND - explorer.exeMSCT Windows Server 2025 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Internet Explorer Processes - FEATURE_WINDOW_RESTRICTIONS - (Reserved)MSCT Windows Server 2025 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Internet Explorer Processes - FEATURE_ZONE_ELEVATION - (Reserved)MSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Join Microsoft MAPSMSCT Windows Server 2025 DC v1.0.0Windows

ACCESS CONTROL

Mandate the minimum version of SMB - MinSmb2DialectMSCT Windows Server 2025 DC v1.0.0Windows
Microsoft network client: Digitally sign communications (always) - RequireSecuritySignatureMSCT Windows Server 2025 DC v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Network access: Do not allow anonymous enumeration of SAM accounts and shares - RestrictAnonymousMSCT Windows Server 2025 DC v1.0.0Windows

ACCESS CONTROL

Prevent bypassing SmartScreen Filter warningsMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Prevent enabling lock screen camera - NoLockScreenCameraMSCT Windows Server 2025 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Require secure RPC communication - fEncryptRPCTrafficMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Reset account lockout counter afterMSCT Windows Server 2025 DC v1.0.0Windows

ACCESS CONTROL

Run .NET Framework-reliant components not signed with Authenticode - Internet ZoneMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Run .NET Framework-reliant components signed with Authenticode - Internet ZoneMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Scan excluded files and directories during quick scansMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Select the channel for Microsoft Defender daily security intelligence updatesMSCT Windows Server 2025 DC v1.0.0Windows
Show security warning for potentially unsafe files - Restricted Sites ZoneMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Sign-in and lock last interactive user automatically after a restart - DisableAutomaticRestartSignOnMSCT Windows Server 2025 DC v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Take ownership of files or other objectsMSCT Windows Server 2025 DC v1.0.0Windows

ACCESS CONTROL

Turn off Autoplay - NoDriveTypeAutoRunMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Turn on 64-bit tab processes when running in Enhanced Protected Mode on 64-bit versions of WindowsMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Turn on Protected Mode - Restricted Sites ZoneMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Turn on SmartScreen Filter scan - Locked-Down Internet ZoneMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Turn on SmartScreen Filter scan - Restricted Sites ZoneMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY