Item Search

NameAudit NamePluginCategory
2.3.11.3 (L1) Ensure 'Network Security: Allow PKU2U authentication requests to this computer to use online identities' is set to 'Disabled'CIS Microsoft Windows 10 Enterprise v4.0.0 L1Windows

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.3.11.3 (L1) Ensure 'Network Security: Allow PKU2U authentication requests to this computer to use online identities' is set to 'Disabled'CIS Microsoft Windows 10 Enterprise v4.0.0 L1 BL NGWindows

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.3.11.3 (L1) Ensure 'Network Security: Allow PKU2U authentication requests to this computer to use online identities' is set to 'Disabled'CIS Microsoft Windows 11 Enterprise v4.0.0 L1Windows

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.3.11.3 (L1) Ensure 'Network Security: Allow PKU2U authentication requests to this computer to use online identities' is set to 'Disabled'CIS Microsoft Windows 11 Stand-alone v4.0.0 L1Windows

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.3.11.3 (L1) Ensure 'Network Security: Allow PKU2U authentication requests to this computer to use online identities' is set to 'Disabled'CIS Microsoft Windows 11 Stand-alone v4.0.0 L1 BLWindows

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.3.11.3 (L1) Ensure 'Network Security: Allow PKU2U authentication requests to this computer to use online identities' is set to 'Disabled'CIS Microsoft Windows 10 Stand-alone v4.0.0 L1 BL NGWindows

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.3.11.6 Ensure 'Network security: LAN Manager authentication level' is set to 'Send NTLMv2 response only. Refuse LM & NTLM' - Send NTLMv2 response only. Refuse LM & NTLMCIS Azure Compute Microsoft Windows Server 2022 v1.0.0 L1 DCWindows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.3.11.7 Ensure 'Network security: LAN Manager authentication level' is set to 'Send NTLMv2 response only. Refuse LM & NTLM'CIS Microsoft Windows 8.1 v2.4.1 L1Windows

IDENTIFICATION AND AUTHENTICATION

8.12 (L1) VMware Tools must limit the use of MSI transforms when reconfiguring VMware ToolsCIS VMware ESXi 8.0 v1.2.0 L1VMware

CONFIGURATION MANAGEMENT

18.8.37.1 Ensure 'Enable RPC Endpoint Mapper Client Authentication' is set to 'Enabled'CIS Microsoft Windows 8.1 v2.4.1 L1Windows

CONFIGURATION MANAGEMENT

18.8.37.1 Ensure 'Enable RPC Endpoint Mapper Client Authentication' is set to 'Enabled' (MS only) - EnabledCIS Azure Compute Microsoft Windows Server 2022 v1.0.0 L1 MSWindows

CONFIGURATION MANAGEMENT

Access data sources across domains - Internet ZoneMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Accounts: Limit local account use of blank passwords to console logon only - LimitBlankPasswordUseMSCT Windows Server 2025 DC v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Allow indexing of encrypted files - AllowIndexingEncryptedStoresOrItemsMSCT Windows Server 2025 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Allow only approved domains to use ActiveX controls without prompt - Internet ZoneMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Allow unencrypted traffic - Client - AllowUnencryptedTrafficMSCT Windows Server 2025 DC v1.0.0Windows

ACCESS CONTROL

Allow VBScript to run in Internet Explorer - Internet ZoneMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Audit Account LockoutMSCT Windows Server 2025 DC v1.0.0Windows

AUDIT AND ACCOUNTABILITY

Audit Authentication Policy ChangeMSCT Windows Server 2025 DC v1.0.0Windows

AUDIT AND ACCOUNTABILITY

Audit Credential ValidationMSCT Windows Server 2025 DC v1.0.0Windows

AUDIT AND ACCOUNTABILITY

Audit insecure guest logon - LanmanServer AuditInsecureGuestLogonMSCT Windows Server 2025 DC v1.0.0Windows

AUDIT AND ACCOUNTABILITY

Audit Kerberos Service Ticket OperationsMSCT Windows Server 2025 DC v1.0.0Windows

AUDIT AND ACCOUNTABILITY

Audit Security Group ManagementMSCT Windows Server 2025 DC v1.0.0Windows

AUDIT AND ACCOUNTABILITY

Audit Security System ExtensionMSCT Windows Server 2025 DC v1.0.0Windows

AUDIT AND ACCOUNTABILITY

Audit System IntegrityMSCT Windows Server 2025 DC v1.0.0Windows

AUDIT AND ACCOUNTABILITY

Audit User Account ManagementMSCT Windows Server 2025 DC v1.0.0Windows

AUDIT AND ACCOUNTABILITY

Boot-Start Driver Initialization Policy - DriverLoadPolicyMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Configure Attack Surface Reduction rules - e6db77e5-3df2-4cf1-b95a-636979351e5bMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Configure detection for potentially unwanted applicationsMSCT Windows Server 2025 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Configure enhanced anti-spoofing - EnhancedAntiSpoofingMSCT Windows Server 2025 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Configure hash algorithms for certificate logon - KDC PKINITSHA1MSCT Windows Server 2025 DC v1.0.0Windows
Configure hash algorithms for certificate logon - Kerberos PKInitSHA256MSCT Windows Server 2025 DC v1.0.0Windows
Configure hash algorithms for certificate logon - Kerberos PKInitSHA512MSCT Windows Server 2025 DC v1.0.0Windows
Configure real-time protection and Security Intelligence Updates during OOBEMSCT Windows Server 2025 DC v1.0.0Windows
Configure registry policy processing - NoBackgroundPolicyMSCT Windows Server 2025 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Configure Windows Defender SmartScreen - EnableSmartScreenMSCT Windows Server 2025 DC v1.0.0Windows

ACCESS CONTROL

Control whether exclusions are visible to local usersMSCT Windows Server 2025 DC v1.0.0Windows
Debug programsMSCT Windows Server 2025 DC v1.0.0Windows

ACCESS CONTROL

Don't run antimalware programs against ActiveX controls - Internet ZoneMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Don't run antimalware programs against ActiveX controls - Local Machine ZoneMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Don't run antimalware programs against ActiveX controls - Restricted Sites ZoneMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Download unsigned ActiveX controls - Internet ZoneMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Download unsigned ActiveX controls - Restricted Sites ZoneMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EDGE-00-000031 - Personalization of ads, search, and news by sending browsing history to Microsoft must be disabled.DISA STIG Edge v2r2Windows

CONFIGURATION MANAGEMENT

Enable computer and user accounts to be trusted for delegationMSCT Windows Server 2025 DC v1.0.0Windows

ACCESS CONTROL

Enable dragging of content from different domains across windows - Internet ZoneMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Enable dragging of content from different domains within a window - Internet ZoneMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Enable dragging of content from different domains within a window - Restricted Sites ZoneMSCT Windows Server 2025 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Enable Structured Exception Handling Overwrite Protection (SEHOP) - DisableExceptionChainValidationMSCT Windows Server 2025 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Extended Protection for LDAP Authentication (Domain Controllers only) (DEPRECATED)MSCT Windows Server 2025 DC v1.0.0Windows

CONFIGURATION MANAGEMENT