Description | Tests | Scoring | |||||
---|---|---|---|---|---|---|---|
Pass | Fail | Error | Unkn. | Score | Max | Percent | |
1 Account Policies | 5 | 2 | 0 | 2 | 5.0 | 9.0 | 56% |
1.1 Password Policy | 2 | 2 | 0 | 2 | 2.0 | 6.0 | 33% |
1.2 Account Lockout Policy | 3 | 0 | 0 | 0 | 3.0 | 3.0 | 100% |
2 Local Policies | 92 | 7 | 0 | 1 | 92.0 | 100.0 | 92% |
2.1 Audit Policy | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
2.2 User Rights Assignment | 34 | 3 | 0 | 0 | 34.0 | 37.0 | 92% |
2.3 Security Options | 58 | 4 | 0 | 1 | 58.0 | 63.0 | 92% |
2.3.1 Accounts | 4 | 2 | 0 | 0 | 4.0 | 6.0 | 67% |
2.3.2 Audit | 2 | 0 | 0 | 0 | 2.0 | 2.0 | 100% |
2.3.3 DCOM | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
2.3.4 Devices | 2 | 0 | 0 | 0 | 2.0 | 2.0 | 100% |
2.3.5 Domain controller | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
2.3.6 Domain member | 6 | 0 | 0 | 0 | 6.0 | 6.0 | 100% |
2.3.7 Interactive logon | 8 | 0 | 0 | 0 | 8.0 | 8.0 | 100% |
2.3.8 Microsoft network client | 3 | 0 | 0 | 0 | 3.0 | 3.0 | 100% |
2.3.9 Microsoft network server | 5 | 0 | 0 | 0 | 5.0 | 5.0 | 100% |
2.3.10 Network access | 9 | 1 | 0 | 1 | 9.0 | 11.0 | 82% |
2.3.11 Network security | 8 | 1 | 0 | 0 | 8.0 | 9.0 | 89% |
2.3.12 Recovery console | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
2.3.13 Shutdown | 1 | 0 | 0 | 0 | 1.0 | 1.0 | 100% |
2.3.14 System cryptography | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
2.3.15 System objects | 2 | 0 | 0 | 0 | 2.0 | 2.0 | 100% |
2.3.16 System settings | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
2.3.17 User Account Control | 8 | 0 | 0 | 0 | 8.0 | 8.0 | 100% |
3 Event Log | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
4 Restricted Groups | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
5 System Services | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
6 Registry | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
7 File System | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
8 Wired Network (IEEE 802.3) Policies | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
9 Windows Firewall with Advanced Security | 20 | 6 | 0 | 0 | 20.0 | 26.0 | 77% |
9.1 Domain Profile | 6 | 2 | 0 | 0 | 6.0 | 8.0 | 75% |
9.2 Private Profile | 6 | 2 | 0 | 0 | 6.0 | 8.0 | 75% |
9.3 Public Profile | 8 | 2 | 0 | 0 | 8.0 | 10.0 | 80% |
10 Network List Manager Policies | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
11 Wireless Network (IEEE 802.11) Policies | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
12 Public Key Policies | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
13 Software Restriction Policies | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
14 Network Access Protection NAP Client Configuration | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
15 Application Control Policies | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
16 IP Security Policies | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
17 Advanced Audit Policy Configuration | 0 | 27 | 0 | 0 | 0.0 | 27.0 | 0% |
17.1 Account Logon | 0 | 1 | 0 | 0 | 0.0 | 1.0 | 0% |
17.2 Account Management | 0 | 3 | 0 | 0 | 0.0 | 3.0 | 0% |
17.3 Detailed Tracking | 0 | 2 | 0 | 0 | 0.0 | 2.0 | 0% |
17.4 DS Access | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
17.5 Logon/Logoff | 0 | 6 | 0 | 0 | 0.0 | 6.0 | 0% |
17.6 Object Access | 0 | 4 | 0 | 0 | 0.0 | 4.0 | 0% |
17.7 Policy Change | 0 | 5 | 0 | 0 | 0.0 | 5.0 | 0% |
17.8 Privilege Use | 0 | 1 | 0 | 0 | 0.0 | 1.0 | 0% |
17.9 System | 0 | 5 | 0 | 0 | 0.0 | 5.0 | 0% |
18 Administrative Templates (Computer) | 111 | 7 | 0 | 0 | 111.0 | 118.0 | 94% |
18.1 Control Panel | 3 | 0 | 0 | 0 | 3.0 | 3.0 | 100% |
18.1.1 Personalization | 2 | 0 | 0 | 0 | 2.0 | 2.0 | 100% |
18.1.2 Regional and Language Options | 1 | 0 | 0 | 0 | 1.0 | 1.0 | 100% |
18.1.2.1 Handwriting personalization | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.2 LAPS | 5 | 1 | 0 | 0 | 5.0 | 6.0 | 83% |
18.3 MS Security Guide | 6 | 0 | 0 | 0 | 6.0 | 6.0 | 100% |
18.4 MSS (Legacy) | 8 | 0 | 0 | 0 | 8.0 | 8.0 | 100% |
18.5 Network | 6 | 1 | 0 | 0 | 6.0 | 7.0 | 86% |
18.5.1 Background Intelligent Transfer Service (BITS) | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.5.2 BranchCache | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.5.3 DirectAccess Client Experience Settings | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.5.4 DNS Client | 1 | 0 | 0 | 0 | 1.0 | 1.0 | 100% |
18.5.5 Fonts | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.5.6 Hotspot Authentication | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.5.7 Lanman Server | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.5.8 Lanman Workstation | 1 | 0 | 0 | 0 | 1.0 | 1.0 | 100% |
18.5.9 Link-Layer Topology Discovery | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.5.10 Microsoft Peer-to-Peer Networking Services | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.5.10.1 Peer Name Resolution Protocol | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.5.11 Network Connections | 3 | 0 | 0 | 0 | 3.0 | 3.0 | 100% |
18.5.11.1 Windows Defender Firewall (formerly Windows Firewall) | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.5.12 Network Connectivity Status Indicator | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.5.13 Network Isolation | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.5.14 Network Provider | 1 | 0 | 0 | 0 | 1.0 | 1.0 | 100% |
18.5.15 Offline Files | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.5.16 QoS Packet Scheduler | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.5.17 SNMP | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.5.18 SSL Configuration Settings | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.5.19 TCPIP Settings | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.5.19.1 IPv6 Transition Technologies | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.5.19.2 Parameters | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.5.20 Windows Connect Now | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.5.21 Windows Connection Manager | 0 | 1 | 0 | 0 | 0.0 | 1.0 | 0% |
18.6 Printers | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.7 Start Menu and Taskbar | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.7.1 Notifications | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8 System | 23 | 0 | 0 | 0 | 23.0 | 23.0 | 100% |
18.8.1 Access-Denied Assistance | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.2 App-V | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.3 Audit Process Creation | 1 | 0 | 0 | 0 | 1.0 | 1.0 | 100% |
18.8.4 Credentials Delegation | 2 | 0 | 0 | 0 | 2.0 | 2.0 | 100% |
18.8.5 Device Guard | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.6 Device Health Attestation Service | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.7 Device Installation | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.7.1 Device Installation Restrictions | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.8 Device Redirection | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.9 Disk NV Cache | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.10 Disk Quotas | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.11 Display | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.12 Distributed COM | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.13 Driver Installation | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.14 Early Launch Antimalware | 1 | 0 | 0 | 0 | 1.0 | 1.0 | 100% |
18.8.15 Enhanced Storage Access | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.16 File Classification Infrastructure | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.17 File Share Shadow Copy Agent | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.18 File Share Shadow Copy Provider | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.19 Filesystem (formerly NTFS Filesystem) | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.20 Folder Redirection | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.21 Group Policy | 4 | 0 | 0 | 0 | 4.0 | 4.0 | 100% |
18.8.21.1 Logging and tracing | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.22 Internet Communication Management | 2 | 0 | 0 | 0 | 2.0 | 2.0 | 100% |
18.8.22.1 Internet Communication settings | 2 | 0 | 0 | 0 | 2.0 | 2.0 | 100% |
18.8.23 iSCSI | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.24 KDC | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.25 Kerberos | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.26 Kernel DMA Protection | 1 | 0 | 0 | 0 | 1.0 | 1.0 | 100% |
18.8.27 Locale Services | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.28 Logon | 7 | 0 | 0 | 0 | 7.0 | 7.0 | 100% |
18.8.29 Mitigation Options | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.30 Net Logon | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.31 OS Policies | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.32 Performance Control Panel | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.33 PIN Complexity | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.34 Power Management | 2 | 0 | 0 | 0 | 2.0 | 2.0 | 100% |
18.8.34.1 Button Settings | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.34.2 Energy Saver Settings | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.34.3 Hard Disk Settings | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.34.4 Notification Settings | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.34.5 Power Throttling Settings | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.34.6 Sleep Settings | 2 | 0 | 0 | 0 | 2.0 | 2.0 | 100% |
18.8.35 Recovery | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.36 Remote Assistance | 2 | 0 | 0 | 0 | 2.0 | 2.0 | 100% |
18.8.37 Remote Procedure Call | 1 | 0 | 0 | 0 | 1.0 | 1.0 | 100% |
18.8.38 Removable Storage Access | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.39 Scripts | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.40 Server Manager | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.41 Service Control Manager Settings | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.42 Shutdown | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.43 Shutdown Options | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.44 Storage Health | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.45 Storage Sense | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.46 System Restore | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.47 Troubleshooting and Diagnostics | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.47.1 Application Compatibility Diagnostics | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.47.2 Corrupted File Recovery | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.47.3 Disk Diagnostic | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.47.4 Fault Tolerant Heap | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.47.5 Microsoft Support Diagnostic Tool | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.47.6 MSI Corrupted File Recovery | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.47.7 Scheduled Maintenance | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.47.8 Scripted Diagnostics | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.47.9 Windows Boot Performance Diagnostics | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.47.10 Windows Memory Leak Diagnosis | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.47.11 Windows Performance PerfTrack | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.48 Trusted Platform Module Services | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.49 User Profiles | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.50 Windows File Protection | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.51 Windows HotStart | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.52 Windows Time Service | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.8.52.1 Time Providers | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9 Windows Components | 60 | 5 | 0 | 0 | 60.0 | 65.0 | 92% |
18.9.1 Active Directory Federation Services | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.2 ActiveX Installer Service | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.3 Add features to Windows 8 / 8.1 / 10 (formerly Windows Anytime Upgrade) | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.4 App Package Deployment | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.5 App Privacy | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.6 App runtime | 1 | 0 | 0 | 0 | 1.0 | 1.0 | 100% |
18.9.7 Application Compatibility | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.8 AutoPlay Policies | 3 | 0 | 0 | 0 | 3.0 | 3.0 | 100% |
18.9.9 Backup | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.10 Biometrics | 1 | 0 | 0 | 0 | 1.0 | 1.0 | 100% |
18.9.10.1 Facial Features | 1 | 0 | 0 | 0 | 1.0 | 1.0 | 100% |
18.9.11 BitLocker Drive Encryption | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.12 Camera | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.13 Cloud Content | 1 | 0 | 0 | 0 | 1.0 | 1.0 | 100% |
18.9.14 Connect | 1 | 0 | 0 | 0 | 1.0 | 1.0 | 100% |
18.9.15 Credential User Interface | 2 | 0 | 0 | 0 | 2.0 | 2.0 | 100% |
18.9.16 Data Collection and Preview Builds | 3 | 0 | 0 | 0 | 3.0 | 3.0 | 100% |
18.9.17 Delivery Optimization | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.18 Desktop Gadgets | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.19 Desktop Window Manager | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.20 Device and Driver Compatibility | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.21 Device Registration (formerly Workplace Join) | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.22 Digital Locker | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.23 Edge UI | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.24 EMET | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.25 Event Forwarding | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.26 Event Log Service | 8 | 0 | 0 | 0 | 8.0 | 8.0 | 100% |
18.9.26.1 Application | 2 | 0 | 0 | 0 | 2.0 | 2.0 | 100% |
18.9.26.2 Security | 2 | 0 | 0 | 0 | 2.0 | 2.0 | 100% |
18.9.26.3 Setup | 2 | 0 | 0 | 0 | 2.0 | 2.0 | 100% |
18.9.26.4 System | 2 | 0 | 0 | 0 | 2.0 | 2.0 | 100% |
18.9.27 Event Logging | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.28 Event Viewer | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.29 Family Safety (formerly Parental Controls) | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.30 File Explorer (formerly Windows Explorer) | 3 | 0 | 0 | 0 | 3.0 | 3.0 | 100% |
18.9.30.1 Previous Versions | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.31 File History | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.32 Find My Device | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.33 Game Explorer | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.34 Handwriting | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.35 HomeGroup | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.36 Import Video | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.37 Internet Explorer | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.38 Internet Information Services | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.39 Location and Sensors | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.39.1 Windows Location Provider | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.40 Maintenance Scheduler | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.41 Maps | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.42 MDM | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.43 Messaging | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.44 Microsoft account | 1 | 0 | 0 | 0 | 1.0 | 1.0 | 100% |
18.9.45 Microsoft Edge | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.46 Microsoft FIDO Authentication | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.47 Microsoft Secondary Authentication Factor | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.48 Microsoft User Experience Virtualization | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.49 NetMeeting | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.50 Network Access Protection | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.51 Network Projector | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.52 OneDrive (formerly SkyDrive) | 1 | 0 | 0 | 0 | 1.0 | 1.0 | 100% |
18.9.53 Online Assistance | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.54 OOBE | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.55 Password Synchronization | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.56 Portable Operating System | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.57 Presentation Settings | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.58 Push To Install | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.59 Remote Desktop Services (formerly Terminal Services) | 5 | 4 | 0 | 0 | 5.0 | 9.0 | 56% |
18.9.59.1 RD Licensing (formerly TS Licensing) | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.59.2 Remote Desktop Connection Client | 1 | 0 | 0 | 0 | 1.0 | 1.0 | 100% |
18.9.59.2.1 RemoteFX USB Device Redirection | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.59.3 Remote Desktop Session Host (formerly Terminal Server) | 4 | 4 | 0 | 0 | 4.0 | 8.0 | 50% |
18.9.59.3.1 Application Compatibility | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.59.3.2 Connections | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.59.3.3 Device and Resource Redirection | 0 | 1 | 0 | 0 | 0.0 | 1.0 | 0% |
18.9.59.3.4 Licensing | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.59.3.5 Printer Redirection | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.59.3.6 Profiles | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.59.3.7 RD Connection Broker (formerly TS Connection Broker) | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.59.3.8 Remote Session Environment | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.59.3.9 Security | 2 | 3 | 0 | 0 | 2.0 | 5.0 | 40% |
18.9.59.3.10 Session Time Limits | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.59.3.11 Temporary folders | 2 | 0 | 0 | 0 | 2.0 | 2.0 | 100% |
18.9.60 RSS Feeds | 1 | 0 | 0 | 0 | 1.0 | 1.0 | 100% |
18.9.61 Search | 1 | 0 | 0 | 0 | 1.0 | 1.0 | 100% |
18.9.61.1 OCR | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.62 Security Center | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.63 Server for NIS | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.64 Shutdown Options | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.65 Smart Card | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.66 Software Protection Platform | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.67 Sound Recorder | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.68 Speech | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.69 Store | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.70 Sync your settings | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.71 Tablet PC | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.72 Task Scheduler | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.73 Text Input | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.74 Windows Calendar | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.75 Windows Color System | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.76 Windows Customer Experience Improvement Program | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.77 Windows Defender Antivirus (formerly Windows Defender) | 9 | 0 | 0 | 0 | 9.0 | 9.0 | 100% |
18.9.77.1 Client Interface | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.77.2 Exclusions | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.77.3 MAPS | 1 | 0 | 0 | 0 | 1.0 | 1.0 | 100% |
18.9.77.4 MpEngine | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.77.5 Network Inspection System | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.77.6 Quarantine | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.77.7 Real-time Protection | 1 | 0 | 0 | 0 | 1.0 | 1.0 | 100% |
18.9.77.8 Remediation | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.77.9 Reporting | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.77.10 Scan | 2 | 0 | 0 | 0 | 2.0 | 2.0 | 100% |
18.9.77.11 Security Intelligence Updates (formerly Signature Updates) | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.77.12 Threats | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.77.13 Windows Defender Exploit Guard | 3 | 0 | 0 | 0 | 3.0 | 3.0 | 100% |
18.9.77.13.1 Attack Surface Reduction | 2 | 0 | 0 | 0 | 2.0 | 2.0 | 100% |
18.9.77.13.2 Controlled Folder Access | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.77.13.3 Network Protection | 1 | 0 | 0 | 0 | 1.0 | 1.0 | 100% |
18.9.78 Windows Defender Application Guard | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.79 Windows Defender Exploit Guard | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.80 Windows Defender SmartScreen | 1 | 0 | 0 | 0 | 1.0 | 1.0 | 100% |
18.9.80.1 Explorer | 1 | 0 | 0 | 0 | 1.0 | 1.0 | 100% |
18.9.81 Windows Error Reporting | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.82 Windows Game Recording and Broadcasting | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.83 Windows Hello for Business (formerly Microsoft Passport for Work) | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.84 Windows Ink Workspace | 1 | 0 | 0 | 0 | 1.0 | 1.0 | 100% |
18.9.85 Windows Installer | 2 | 0 | 0 | 0 | 2.0 | 2.0 | 100% |
18.9.86 Windows Logon Options | 1 | 0 | 0 | 0 | 1.0 | 1.0 | 100% |
18.9.87 Windows Mail | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.88 Windows Media Center | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.89 Windows Media Digital Rights Management | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.90 Windows Media Player | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.91 Windows Meeting Space | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.92 Windows Messenger | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.93 Windows Mobility Center | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.94 Windows Movie Maker | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.95 Windows PowerShell | 2 | 0 | 0 | 0 | 2.0 | 2.0 | 100% |
18.9.96 Windows Reliability Analysis | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.97 Windows Remote Management (WinRM) | 6 | 0 | 0 | 0 | 6.0 | 6.0 | 100% |
18.9.97.1 WinRM Client | 3 | 0 | 0 | 0 | 3.0 | 3.0 | 100% |
18.9.97.2 WinRM Service | 3 | 0 | 0 | 0 | 3.0 | 3.0 | 100% |
18.9.98 Windows Remote Shell | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.99 Windows Security (formerly Windows Defender Security Center) | 1 | 0 | 0 | 0 | 1.0 | 1.0 | 100% |
18.9.99.1 Account protection | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.99.2 App and browser protection | 1 | 0 | 0 | 0 | 1.0 | 1.0 | 100% |
18.9.100 Windows SideShow | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.101 Windows System Resource Manager | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
18.9.102 Windows Update | 5 | 1 | 0 | 0 | 5.0 | 6.0 | 83% |
18.9.102.1 Windows Update for Business (formerly Defer Windows Updates) | 3 | 0 | 0 | 0 | 3.0 | 3.0 | 100% |
19 Administrative Templates (User) | 7 | 4 | 0 | 0 | 7.0 | 11.0 | 64% |
19.1 Control Panel | 0 | 4 | 0 | 0 | 0.0 | 4.0 | 0% |
19.1.1 Add or Remove Programs | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.1.2 Display | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.1.3 Personalization (formerly Desktop Themes) | 0 | 4 | 0 | 0 | 0.0 | 4.0 | 0% |
19.2 Desktop | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.3 Network | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.4 Shared Folders | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.5 Start Menu and Taskbar | 1 | 0 | 0 | 0 | 1.0 | 1.0 | 100% |
19.5.1 Notifications | 1 | 0 | 0 | 0 | 1.0 | 1.0 | 100% |
19.6 System | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.6.1 Ctrl+Alt+Del Options | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.6.2 Display | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.6.3 Driver Installation | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.6.4 Folder Redirection | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.6.5 Group Policy | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.6.6 Internet Communication Management | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.6.6.1 Internet Communication settings | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7 Windows Components | 6 | 0 | 0 | 0 | 6.0 | 6.0 | 100% |
19.7.1 Add features to Windows 8 / 8.1 / 10 (formerly Windows Anytime Upgrade) | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.2 App runtime | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.3 Application Compatibility | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.4 Attachment Manager | 2 | 0 | 0 | 0 | 2.0 | 2.0 | 100% |
19.7.5 AutoPlay Policies | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.6 Backup | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.7 Cloud Content | 2 | 0 | 0 | 0 | 2.0 | 2.0 | 100% |
19.7.8 Credential User Interface | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.9 Data Collection and Preview Builds | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.10 Desktop Gadgets | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.11 Desktop Window Manager | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.12 Digital Locker | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.13 Edge UI | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.14 File Explorer (formerly Windows Explorer) | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.15 File Revocation | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.16 IME | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.17 Import Video | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.18 Instant Search | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.19 Internet Explorer | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.20 Location and Sensors | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.21 Microsoft Edge | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.22 Microsoft Management Console | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.23 Microsoft User Experience Virtualization | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.24 NetMeeting | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.25 Network Projector | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.26 Network Sharing | 1 | 0 | 0 | 0 | 1.0 | 1.0 | 100% |
19.7.27 OOBE | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.28 Presentation Settings | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.29 Remote Desktop Services (formerly Terminal Services) | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.30 RSS Feeds | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.31 Search | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.32 Sound Recorder | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.33 Store | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.34 Tablet PC | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.35 Task Scheduler | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.36 Windows Calendar | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.37 Windows Color System | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.38 Windows Defender SmartScreen | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.39 Windows Error Reporting | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.40 Windows Hello for Business (formerly Microsoft Passport for Work) | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.41 Windows Installer | 1 | 0 | 0 | 0 | 1.0 | 1.0 | 100% |
19.7.42 Windows Logon Options | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.43 Windows Mail | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.44 Windows Media Center | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.45 Windows Media Player | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.45.1 Networking | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
19.7.45.2 Playback | 0 | 0 | 0 | 0 | 0.0 | 0.0 | 0% |
Total | 235 | 53 | 0 | 3 | 235.0 | 291.0 | 81% |
Note: Actual scores are subject to rounding errors. The sum of these values may not result in the exact overall score.
This benchmark contains 6 profiles.The Level 1 - Member Server profile was used for this assessment.
Title | Description |
---|---|
Level 1 - Domain Controller |
Items in this profile apply to Domain Controllers and intend to:
Show
Profile XML
<xccdf:Profile xmlns="http://checklists.nist.gov/xccdf/1.2" xmlns:ae="http://benchmarks.cisecurity.org/ae/0.5" xmlns:cc6="http://cisecurity.org/20-cc/v6.1" xmlns:cc7="http://cisecurity.org/20-cc/v7.0" xmlns:ciscf="https://benchmarks.cisecurity.org/ciscf/1.0" xmlns:notes="http://benchmarks.cisecurity.org/notes" xmlns:xccdf="http://checklists.nist.gov/xccdf/1.2" xmlns:xhtml="http://www.w3.org/1999/xhtml" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" id="xccdf_org.cisecurity.benchmarks_profile_Level_1_-_Domain_Controller"> <xccdf:title xml:lang="en">Level 1 - Domain Controller</xccdf:title> <xccdf:description xml:lang="en"> <xhtml:p>Items in this profile apply to Domain Controllers and intend to:</xhtml:p> <xhtml:ul> <xhtml:li>be practical and prudent;</xhtml:li> <xhtml:li>provide a clear security benefit; and</xhtml:li> <xhtml:li>not inhibit the utility of the technology beyond acceptable means.</xhtml:li> </xhtml:ul> </xccdf:description> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.1.1_L1_Ensure_Enforce_password_history_is_set_to_24_or_more_passwords" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.1.2_L1_Ensure_Maximum_password_age_is_set_to_60_or_fewer_days_but_not_0" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.1.3_L1_Ensure_Minimum_password_age_is_set_to_1_or_more_days" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.1.4_L1_Ensure_Minimum_password_length_is_set_to_14_or_more_characters" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.1.5_L1_Ensure_Password_must_meet_complexity_requirements_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.1.6_L1_Ensure_Store_passwords_using_reversible_encryption_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.2.1_L1_Ensure_Account_lockout_duration_is_set_to_15_or_more_minutes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.2.2_L1_Ensure_Account_lockout_threshold_is_set_to_10_or_fewer_invalid_logon_attempts_but_not_0" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.2.3_L1_Ensure_Reset_account_lockout_counter_after_is_set_to_15_or_more_minutes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.1_L1_Ensure_Access_Credential_Manager_as_a_trusted_caller_is_set_to_No_One" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.2_L1_Ensure_Access_this_computer_from_the_network_is_set_to_Administrators_Authenticated_Users_ENTERPRISE_DOMAIN_CONTROLLERS_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.4_L1_Ensure_Act_as_part_of_the_operating_system_is_set_to_No_One" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.5_L1_Ensure_Add_workstations_to_domain_is_set_to_Administrators_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.6_L1_Ensure_Adjust_memory_quotas_for_a_process_is_set_to_Administrators_LOCAL_SERVICE_NETWORK_SERVICE" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.7_L1_Ensure_Allow_log_on_locally_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.8_L1_Ensure_Allow_log_on_through_Remote_Desktop_Services_is_set_to_Administrators_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.10_L1_Ensure_Back_up_files_and_directories_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.11_L1_Ensure_Change_the_system_time_is_set_to_Administrators_LOCAL_SERVICE" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.12_L1_Ensure_Change_the_time_zone_is_set_to_Administrators_LOCAL_SERVICE" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.13_L1_Ensure_Create_a_pagefile_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.14_L1_Ensure_Create_a_token_object_is_set_to_No_One" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.15_L1_Ensure_Create_global_objects_is_set_to_Administrators_LOCAL_SERVICE_NETWORK_SERVICE_SERVICE" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.16_L1_Ensure_Create_permanent_shared_objects_is_set_to_No_One" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.17_L1_Ensure_Create_symbolic_links_is_set_to_Administrators_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.19_L1_Ensure_Debug_programs_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.20_L1_Ensure_Deny_access_to_this_computer_from_the_network_to_include_Guests_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.22_L1_Ensure_Deny_log_on_as_a_batch_job_to_include_Guests" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.23_L1_Ensure_Deny_log_on_as_a_service_to_include_Guests" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.24_L1_Ensure_Deny_log_on_locally_to_include_Guests" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.25_L1_Ensure_Deny_log_on_through_Remote_Desktop_Services_to_include_Guests_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.27_L1_Ensure_Enable_computer_and_user_accounts_to_be_trusted_for_delegation_is_set_to_Administrators_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.29_L1_Ensure_Force_shutdown_from_a_remote_system_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.30_L1_Ensure_Generate_security_audits_is_set_to_LOCAL_SERVICE_NETWORK_SERVICE" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.31_L1_Ensure_Impersonate_a_client_after_authentication_is_set_to_Administrators_LOCAL_SERVICE_NETWORK_SERVICE_SERVICE_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.33_L1_Ensure_Increase_scheduling_priority_is_set_to_Administrators_Window_ManagerWindow_Manager_Group" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.34_L1_Ensure_Load_and_unload_device_drivers_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.35_L1_Ensure_Lock_pages_in_memory_is_set_to_No_One" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.37_L1_Ensure_Manage_auditing_and_security_log_is_set_to_Administrators_and_when_Exchange_is_running_in_the_environment_Exchange_Servers_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.39_L1_Ensure_Modify_an_object_label_is_set_to_No_One" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.40_L1_Ensure_Modify_firmware_environment_values_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.41_L1_Ensure_Perform_volume_maintenance_tasks_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.42_L1_Ensure_Profile_single_process_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.43_L1_Ensure_Profile_system_performance_is_set_to_Administrators_NT_SERVICEWdiServiceHost" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.44_L1_Ensure_Replace_a_process_level_token_is_set_to_LOCAL_SERVICE_NETWORK_SERVICE" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.45_L1_Ensure_Restore_files_and_directories_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.46_L1_Ensure_Shut_down_the_system_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.47_L1_Ensure_Synchronize_directory_service_data_is_set_to_No_One_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.48_L1_Ensure_Take_ownership_of_files_or_other_objects_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.1.2_L1_Ensure_Accounts_Block_Microsoft_accounts_is_set_to_Users_cant_add_or_log_on_with_Microsoft_accounts" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.1.4_L1_Ensure_Accounts_Limit_local_account_use_of_blank_passwords_to_console_logon_only_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.1.5_L1_Configure_Accounts_Rename_administrator_account" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.1.6_L1_Configure_Accounts_Rename_guest_account" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.2.1_L1_Ensure_Audit_Force_audit_policy_subcategory_settings_Windows_Vista_or_later_to_override_audit_policy_category_settings_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.2.2_L1_Ensure_Audit_Shut_down_system_immediately_if_unable_to_log_security_audits_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.4.1_L1_Ensure_Devices_Allowed_to_format_and_eject_removable_media_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.4.2_L1_Ensure_Devices_Prevent_users_from_installing_printer_drivers_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.5.1_L1_Ensure_Domain_controller_Allow_server_operators_to_schedule_tasks_is_set_to_Disabled_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.5.2_L1_Ensure_Domain_controller_LDAP_server_signing_requirements_is_set_to_Require_signing_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.5.3_L1_Ensure_Domain_controller_Refuse_machine_account_password_changes_is_set_to_Disabled_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.6.1_L1_Ensure_Domain_member_Digitally_encrypt_or_sign_secure_channel_data_always_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.6.2_L1_Ensure_Domain_member_Digitally_encrypt_secure_channel_data_when_possible_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.6.3_L1_Ensure_Domain_member_Digitally_sign_secure_channel_data_when_possible_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.6.4_L1_Ensure_Domain_member_Disable_machine_account_password_changes_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.6.5_L1_Ensure_Domain_member_Maximum_machine_account_password_age_is_set_to_30_or_fewer_days_but_not_0" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.6.6_L1_Ensure_Domain_member_Require_strong_Windows_2000_or_later_session_key_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.7.1_L1_Ensure_Interactive_logon_Do_not_require_CTRLALTDEL_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.7.2_L1_Ensure_Interactive_logon_Dont_display_last_signed-in_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.7.3_L1_Ensure_Interactive_logon_Machine_inactivity_limit_is_set_to_900_or_fewer_seconds_but_not_0" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.7.4_L1_Configure_Interactive_logon_Message_text_for_users_attempting_to_log_on" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.7.5_L1_Configure_Interactive_logon_Message_title_for_users_attempting_to_log_on" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.7.7_L1_Ensure_Interactive_logon_Prompt_user_to_change_password_before_expiration_is_set_to_between_5_and_14_days" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.7.9_L1_Ensure_Interactive_logon_Smart_card_removal_behavior_is_set_to_Lock_Workstation_or_higher" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.8.1_L1_Ensure_Microsoft_network_client_Digitally_sign_communications_always_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.8.2_L1_Ensure_Microsoft_network_client_Digitally_sign_communications_if_server_agrees_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.8.3_L1_Ensure_Microsoft_network_client_Send_unencrypted_password_to_third-party_SMB_servers_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.9.1_L1_Ensure_Microsoft_network_server_Amount_of_idle_time_required_before_suspending_session_is_set_to_15_or_fewer_minutes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.9.2_L1_Ensure_Microsoft_network_server_Digitally_sign_communications_always_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.9.3_L1_Ensure_Microsoft_network_server_Digitally_sign_communications_if_client_agrees_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.9.4_L1_Ensure_Microsoft_network_server_Disconnect_clients_when_logon_hours_expire_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.1_L1_Ensure_Network_access_Allow_anonymous_SIDName_translation_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.5_L1_Ensure_Network_access_Let_Everyone_permissions_apply_to_anonymous_users_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.6_L1_Configure_Network_access_Named_Pipes_that_can_be_accessed_anonymously_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.8_L1_Configure_Network_access_Remotely_accessible_registry_paths" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.9_L1_Configure_Network_access_Remotely_accessible_registry_paths_and_sub-paths" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.10_L1_Ensure_Network_access_Restrict_anonymous_access_to_Named_Pipes_and_Shares_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.12_L1_Ensure_Network_access_Shares_that_can_be_accessed_anonymously_is_set_to_None" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.13_L1_Ensure_Network_access_Sharing_and_security_model_for_local_accounts_is_set_to_Classic_-_local_users_authenticate_as_themselves" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.1_L1_Ensure_Network_security_Allow_Local_System_to_use_computer_identity_for_NTLM_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.2_L1_Ensure_Network_security_Allow_LocalSystem_NULL_session_fallback_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.3_L1_Ensure_Network_Security_Allow_PKU2U_authentication_requests_to_this_computer_to_use_online_identities_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.4_L1_Ensure_Network_security_Configure_encryption_types_allowed_for_Kerberos_is_set_to_AES128_HMAC_SHA1_AES256_HMAC_SHA1_Future_encryption_types" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.5_L1_Ensure_Network_security_Do_not_store_LAN_Manager_hash_value_on_next_password_change_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.6_L1_Ensure_Network_security_Force_logoff_when_logon_hours_expire_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.7_L1_Ensure_Network_security_LAN_Manager_authentication_level_is_set_to_Send_NTLMv2_response_only._Refuse_LM__NTLM" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.8_L1_Ensure_Network_security_LDAP_client_signing_requirements_is_set_to_Negotiate_signing_or_higher" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.9_L1_Ensure_Network_security_Minimum_session_security_for_NTLM_SSP_based_including_secure_RPC_clients_is_set_to_Require_NTLMv2_session_security_Require_128-bit_encryption" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.10_L1_Ensure_Network_security_Minimum_session_security_for_NTLM_SSP_based_including_secure_RPC_servers_is_set_to_Require_NTLMv2_session_security_Require_128-bit_encryption" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.13.1_L1_Ensure_Shutdown_Allow_system_to_be_shut_down_without_having_to_log_on_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.15.1_L1_Ensure_System_objects_Require_case_insensitivity_for_non-Windows_subsystems_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.15.2_L1_Ensure_System_objects_Strengthen_default_permissions_of_internal_system_objects_e.g._Symbolic_Links_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.17.1_L1_Ensure_User_Account_Control_Admin_Approval_Mode_for_the_Built-in_Administrator_account_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.17.2_L1_Ensure_User_Account_Control_Behavior_of_the_elevation_prompt_for_administrators_in_Admin_Approval_Mode_is_set_to_Prompt_for_consent_on_the_secure_desktop" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.17.3_L1_Ensure_User_Account_Control_Behavior_of_the_elevation_prompt_for_standard_users_is_set_to_Automatically_deny_elevation_requests" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.17.4_L1_Ensure_User_Account_Control_Detect_application_installations_and_prompt_for_elevation_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.17.5_L1_Ensure_User_Account_Control_Only_elevate_UIAccess_applications_that_are_installed_in_secure_locations_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.17.6_L1_Ensure_User_Account_Control_Run_all_administrators_in_Admin_Approval_Mode_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.17.7_L1_Ensure_User_Account_Control_Switch_to_the_secure_desktop_when_prompting_for_elevation_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.17.8_L1_Ensure_User_Account_Control_Virtualize_file_and_registry_write_failures_to_per-user_locations_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.1.1_L1_Ensure_Windows_Firewall_Domain_Firewall_state_is_set_to_On_recommended" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.1.2_L1_Ensure_Windows_Firewall_Domain_Inbound_connections_is_set_to_Block_default" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.1.3_L1_Ensure_Windows_Firewall_Domain_Outbound_connections_is_set_to_Allow_default" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.1.4_L1_Ensure_Windows_Firewall_Domain_Settings_Display_a_notification_is_set_to_No" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.1.5_L1_Ensure_Windows_Firewall_Domain_Logging_Name_is_set_to_SystemRootSystem32logfilesfirewalldomainfw.log" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.1.6_L1_Ensure_Windows_Firewall_Domain_Logging_Size_limit_KB_is_set_to_16384_KB_or_greater" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.1.7_L1_Ensure_Windows_Firewall_Domain_Logging_Log_dropped_packets_is_set_to_Yes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.1.8_L1_Ensure_Windows_Firewall_Domain_Logging_Log_successful_connections_is_set_to_Yes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.2.1_L1_Ensure_Windows_Firewall_Private_Firewall_state_is_set_to_On_recommended" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.2.2_L1_Ensure_Windows_Firewall_Private_Inbound_connections_is_set_to_Block_default" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.2.3_L1_Ensure_Windows_Firewall_Private_Outbound_connections_is_set_to_Allow_default" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.2.4_L1_Ensure_Windows_Firewall_Private_Settings_Display_a_notification_is_set_to_No" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.2.5_L1_Ensure_Windows_Firewall_Private_Logging_Name_is_set_to_SystemRootSystem32logfilesfirewallprivatefw.log" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.2.6_L1_Ensure_Windows_Firewall_Private_Logging_Size_limit_KB_is_set_to_16384_KB_or_greater" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.2.7_L1_Ensure_Windows_Firewall_Private_Logging_Log_dropped_packets_is_set_to_Yes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.2.8_L1_Ensure_Windows_Firewall_Private_Logging_Log_successful_connections_is_set_to_Yes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.1_L1_Ensure_Windows_Firewall_Public_Firewall_state_is_set_to_On_recommended" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.2_L1_Ensure_Windows_Firewall_Public_Inbound_connections_is_set_to_Block_default" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.3_L1_Ensure_Windows_Firewall_Public_Outbound_connections_is_set_to_Allow_default" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.4_L1_Ensure_Windows_Firewall_Public_Settings_Display_a_notification_is_set_to_No" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.5_L1_Ensure_Windows_Firewall_Public_Settings_Apply_local_firewall_rules_is_set_to_No" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.6_L1_Ensure_Windows_Firewall_Public_Settings_Apply_local_connection_security_rules_is_set_to_No" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.7_L1_Ensure_Windows_Firewall_Public_Logging_Name_is_set_to_SystemRootSystem32logfilesfirewallpublicfw.log" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.8_L1_Ensure_Windows_Firewall_Public_Logging_Size_limit_KB_is_set_to_16384_KB_or_greater" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.9_L1_Ensure_Windows_Firewall_Public_Logging_Log_dropped_packets_is_set_to_Yes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.10_L1_Ensure_Windows_Firewall_Public_Logging_Log_successful_connections_is_set_to_Yes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.1.1_L1_Ensure_Audit_Credential_Validation_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.1.2_L1_Ensure_Audit_Kerberos_Authentication_Service_is_set_to_Success_and_Failure_DC_Only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.1.3_L1_Ensure_Audit_Kerberos_Service_Ticket_Operations_is_set_to_Success_and_Failure_DC_Only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.2.1_L1_Ensure_Audit_Application_Group_Management_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.2.2_L1_Ensure_Audit_Computer_Account_Management_is_set_to_include_Success_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.2.3_L1_Ensure_Audit_Distribution_Group_Management_is_set_to_include_Success_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.2.4_L1_Ensure_Audit_Other_Account_Management_Events_is_set_to_include_Success_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.2.5_L1_Ensure_Audit_Security_Group_Management_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.2.6_L1_Ensure_Audit_User_Account_Management_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.3.1_L1_Ensure_Audit_PNP_Activity_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.3.2_L1_Ensure_Audit_Process_Creation_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.4.1_L1_Ensure_Audit_Directory_Service_Access_is_set_to_include_Failure_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.4.2_L1_Ensure_Audit_Directory_Service_Changes_is_set_to_include_Success_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.5.1_L1_Ensure_Audit_Account_Lockout_is_set_to_include_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.5.2_L1_Ensure_Audit_Group_Membership_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.5.3_L1_Ensure_Audit_Logoff_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.5.4_L1_Ensure_Audit_Logon_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.5.5_L1_Ensure_Audit_Other_LogonLogoff_Events_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.5.6_L1_Ensure_Audit_Special_Logon_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.6.1_L1_Ensure_Audit_Detailed_File_Share_is_set_to_include_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.6.2_L1_Ensure_Audit_File_Share_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.6.3_L1_Ensure_Audit_Other_Object_Access_Events_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.6.4_L1_Ensure_Audit_Removable_Storage_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.7.1_L1_Ensure_Audit_Audit_Policy_Change_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.7.2_L1_Ensure_Audit_Authentication_Policy_Change_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.7.3_L1_Ensure_Audit_Authorization_Policy_Change_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.7.4_L1_Ensure_Audit_MPSSVC_Rule-Level_Policy_Change_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.7.5_L1_Ensure_Audit_Other_Policy_Change_Events_is_set_to_include_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.8.1_L1_Ensure_Audit_Sensitive_Privilege_Use_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.9.1_L1_Ensure_Audit_IPsec_Driver_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.9.2_L1_Ensure_Audit_Other_System_Events_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.9.3_L1_Ensure_Audit_Security_State_Change_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.9.4_L1_Ensure_Audit_Security_System_Extension_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.9.5_L1_Ensure_Audit_System_Integrity_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.1.1.1_L1_Ensure_Prevent_enabling_lock_screen_camera_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.1.1.2_L1_Ensure_Prevent_enabling_lock_screen_slide_show_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.1.2.2_L1_Ensure_Allow_users_to_enable_online_speech_recognition_services_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.3.2_L1_Ensure_Configure_SMB_v1_client_driver_is_set_to_Enabled_Disable_driver_recommended" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.3.3_L1_Ensure_Configure_SMB_v1_server_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.3.4_L1_Ensure_Enable_Structured_Exception_Handling_Overwrite_Protection_SEHOP_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.3.5_L1_Ensure_Extended_Protection_for_LDAP_Authentication_Domain_Controllers_only_is_set_to_Enabled_Enabled_always_recommended_DC_Only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.3.6_L1_Ensure_NetBT_NodeType_configuration_is_set_to_Enabled_P-node_recommended" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.3.7_L1_Ensure_WDigest_Authentication_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.1_L1_Ensure_MSS_AutoAdminLogon_Enable_Automatic_Logon_not_recommended_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.2_L1_Ensure_MSS_DisableIPSourceRouting_IPv6_IP_source_routing_protection_level_protects_against_packet_spoofing_is_set_to_Enabled_Highest_protection_source_routing_is_completely_disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.3_L1_Ensure_MSS_DisableIPSourceRouting_IP_source_routing_protection_level_protects_against_packet_spoofing_is_set_to_Enabled_Highest_protection_source_routing_is_completely_disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.4_L1_Ensure_MSS_EnableICMPRedirect_Allow_ICMP_redirects_to_override_OSPF_generated_routes_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.6_L1_Ensure_MSS_NoNameReleaseOnDemand_Allow_the_computer_to_ignore_NetBIOS_name_release_requests_except_from_WINS_servers_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.8_L1_Ensure_MSS_SafeDllSearchMode_Enable_Safe_DLL_search_mode_recommended_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.9_L1_Ensure_MSS_ScreenSaverGracePeriod_The_time_in_seconds_before_the_screen_saver_grace_period_expires_0_recommended_is_set_to_Enabled_5_or_fewer_seconds" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.12_L1_Ensure_MSS_WarningLevel_Percentage_threshold_for_the_security_event_log_at_which_the_system_will_generate_a_warning_is_set_to_Enabled_90_or_less" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.4.1_L1_Ensure_Turn_off_multicast_name_resolution_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.8.1_L1_Ensure_Enable_insecure_guest_logons_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.11.2_L1_Ensure_Prohibit_installation_and_configuration_of_Network_Bridge_on_your_DNS_domain_network_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.11.3_L1_Ensure_Prohibit_use_of_Internet_Connection_Sharing_on_your_DNS_domain_network_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.11.4_L1_Ensure_Require_domain_users_to_elevate_when_setting_a_networks_location_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.14.1_L1_Ensure_Hardened_UNC_Paths_is_set_to_Enabled_with_Require_Mutual_Authentication_and_Require_Integrity_set_for_all_NETLOGON_and_SYSVOL_shares" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.21.1_L1_Ensure_Minimize_the_number_of_simultaneous_connections_to_the_Internet_or_a_Windows_Domain_is_set_to_Enabled_3__Prevent_Wi-Fi_when_on_Ethernet" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.3.1_L1_Ensure_Include_command_line_in_process_creation_events_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.4.1_L1_Ensure_Encryption_Oracle_Remediation_is_set_to_Enabled_Force_Updated_Clients" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.4.2_L1_Ensure_Remote_host_allows_delegation_of_non-exportable_credentials_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.14.1_L1_Ensure_Boot-Start_Driver_Initialization_Policy_is_set_to_Enabled_Good_unknown_and_bad_but_critical" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.21.2_L1_Ensure_Configure_registry_policy_processing_Do_not_apply_during_periodic_background_processing_is_set_to_Enabled_FALSE" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.21.3_L1_Ensure_Configure_registry_policy_processing_Process_even_if_the_Group_Policy_objects_have_not_changed_is_set_to_Enabled_TRUE" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.21.4_L1_Ensure_Continue_experiences_on_this_device_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.21.5_L1_Ensure_Turn_off_background_refresh_of_Group_Policy_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.22.1.1_L1_Ensure_Turn_off_downloading_of_print_drivers_over_HTTP_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.22.1.5_L1_Ensure_Turn_off_Internet_download_for_Web_publishing_and_online_ordering_wizards_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.26.1_L1_Ensure_Enumeration_policy_for_external_devices_incompatible_with_Kernel_DMA_Protection_is_set_to_Enabled_Block_All" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.28.1_L1_Ensure_Block_user_from_showing_account_details_on_sign-in_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.28.2_L1_Ensure_Do_not_display_network_selection_UI_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.28.3_L1_Ensure_Do_not_enumerate_connected_users_on_domain-joined_computers_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.28.5_L1_Ensure_Turn_off_app_notifications_on_the_lock_screen_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.28.6_L1_Ensure_Turn_off_picture_password_sign-in_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.28.7_L1_Ensure_Turn_on_convenience_PIN_sign-in_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.34.6.3_L1_Ensure_Require_a_password_when_a_computer_wakes_on_battery_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.34.6.4_L1_Ensure_Require_a_password_when_a_computer_wakes_plugged_in_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.36.1_L1_Ensure_Configure_Offer_Remote_Assistance_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.36.2_L1_Ensure_Configure_Solicited_Remote_Assistance_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.6.1_L1_Ensure_Allow_Microsoft_accounts_to_be_optional_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.8.1_L1_Ensure_Disallow_Autoplay_for_non-volume_devices_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.8.2_L1_Ensure_Set_the_default_behavior_for_AutoRun_is_set_to_Enabled_Do_not_execute_any_autorun_commands" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.8.3_L1_Ensure_Turn_off_Autoplay_is_set_to_Enabled_All_drives" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.10.1.1_L1_Ensure_Configure_enhanced_anti-spoofing_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.13.1_L1_Ensure_Turn_off_Microsoft_consumer_experiences_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.14.1_L1_Ensure_Require_pin_for_pairing_is_set_to_Enabled_First_Time_OR_Enabled_Always" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.15.1_L1_Ensure_Do_not_display_the_password_reveal_button_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.15.2_L1_Ensure_Enumerate_administrator_accounts_on_elevation_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.16.1_L1_Ensure_Allow_Telemetry_is_set_to_Enabled_0_-_Security_Enterprise_Only_or_Enabled_1_-_Basic" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.16.3_L1_Ensure_Do_not_show_feedback_notifications_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.16.4_L1_Ensure_Toggle_user_control_over_Insider_builds_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.26.1.1_L1_Ensure_Application_Control_Event_Log_behavior_when_the_log_file_reaches_its_maximum_size_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.26.1.2_L1_Ensure_Application_Specify_the_maximum_log_file_size_KB_is_set_to_Enabled_32768_or_greater" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.26.2.1_L1_Ensure_Security_Control_Event_Log_behavior_when_the_log_file_reaches_its_maximum_size_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.26.2.2_L1_Ensure_Security_Specify_the_maximum_log_file_size_KB_is_set_to_Enabled_196608_or_greater" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.26.3.1_L1_Ensure_Setup_Control_Event_Log_behavior_when_the_log_file_reaches_its_maximum_size_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.26.3.2_L1_Ensure_Setup_Specify_the_maximum_log_file_size_KB_is_set_to_Enabled_32768_or_greater" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.26.4.1_L1_Ensure_System_Control_Event_Log_behavior_when_the_log_file_reaches_its_maximum_size_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.26.4.2_L1_Ensure_System_Specify_the_maximum_log_file_size_KB_is_set_to_Enabled_32768_or_greater" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.30.2_L1_Ensure_Turn_off_Data_Execution_Prevention_for_Explorer_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.30.3_L1_Ensure_Turn_off_heap_termination_on_corruption_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.30.4_L1_Ensure_Turn_off_shell_protocol_protected_mode_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.44.1_L1_Ensure_Block_all_consumer_Microsoft_account_user_authentication_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.52.1_L1_Ensure_Prevent_the_usage_of_OneDrive_for_file_storage_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.2.2_L1_Ensure_Do_not_allow_passwords_to_be_saved_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.3.2_L1_Ensure_Do_not_allow_drive_redirection_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.9.1_L1_Ensure_Always_prompt_for_password_upon_connection_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.9.2_L1_Ensure_Require_secure_RPC_communication_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.9.3_L1_Ensure_Require_use_of_specific_security_layer_for_remote_RDP_connections_is_set_to_Enabled_SSL" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.9.4_L1_Ensure_Require_user_authentication_for_remote_connections_by_using_Network_Level_Authentication_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.9.5_L1_Ensure_Set_client_connection_encryption_level_is_set_to_Enabled_High_Level" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.11.1_L1_Ensure_Do_not_delete_temp_folders_upon_exit_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.11.2_L1_Ensure_Do_not_use_temporary_folders_per_session_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.60.1_L1_Ensure_Prevent_downloading_of_enclosures_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.61.3_L1_Ensure_Allow_indexing_of_encrypted_files_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.3.1_L1_Ensure_Configure_local_setting_override_for_reporting_to_Microsoft_MAPS_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.7.1_L1_Ensure_Turn_on_behavior_monitoring_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.10.1_L1_Ensure_Scan_removable_drives_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.10.2_L1_Ensure_Turn_on_e-mail_scanning_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.13.1.1_L1_Ensure_Configure_Attack_Surface_Reduction_rules_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.13.1.2_L1_Ensure_Configure_Attack_Surface_Reduction_rules_Set_the_state_for_each_ASR_rule_is_configured" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.13.3.1_L1_Ensure_Prevent_users_and_apps_from_accessing_dangerous_websites_is_set_to_Enabled_Block" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.14_L1_Ensure_Configure_detection_for_potentially_unwanted_applications_is_set_to_Enabled_Block" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.15_L1_Ensure_Turn_off_Windows_Defender_AntiVirus_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.80.1.1_L1_Ensure_Configure_Windows_Defender_SmartScreen_is_set_to_Enabled_Warn_and_prevent_bypass" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.84.2_L1_Ensure_Allow_Windows_Ink_Workspace_is_set_to_Enabled_On_but_disallow_access_above_lock_OR_Disabled_but_not_Enabled_On" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.85.1_L1_Ensure_Allow_user_control_over_installs_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.85.2_L1_Ensure_Always_install_with_elevated_privileges_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.86.1_L1_Ensure_Sign-in_and_lock_last_interactive_user_automatically_after_a_restart_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.95.1_L1_Ensure_Turn_on_PowerShell_Script_Block_Logging_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.95.2_L1_Ensure_Turn_on_PowerShell_Transcription_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.97.1.1_L1_Ensure_Allow_Basic_authentication_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.97.1.2_L1_Ensure_Allow_unencrypted_traffic_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.97.1.3_L1_Ensure_Disallow_Digest_authentication_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.97.2.1_L1_Ensure_Allow_Basic_authentication_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.97.2.3_L1_Ensure_Allow_unencrypted_traffic_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.97.2.4_L1_Ensure_Disallow_WinRM_from_storing_RunAs_credentials_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.99.2.1_L1_Ensure_Prevent_users_from_modifying_settings_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.102.1.1_L1_Ensure_Manage_preview_builds_is_set_to_Enabled_Disable_preview_builds" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.102.1.2_L1_Ensure_Select_when_Preview_Builds_and_Feature_Updates_are_received_is_set_to_Enabled_Semi-Annual_Channel_180_or_more_days" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.102.1.3_L1_Ensure_Select_when_Quality_Updates_are_received_is_set_to_Enabled_0_days" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.102.2_L1_Ensure_Configure_Automatic_Updates_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.102.3_L1_Ensure_Configure_Automatic_Updates_Scheduled_install_day_is_set_to_0_-_Every_day" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.102.4_L1_Ensure_No_auto-restart_with_logged_on_users_for_scheduled_automatic_updates_installations_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.1.3.1_L1_Ensure_Enable_screen_saver_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.1.3.2_L1_Ensure_Force_specific_screen_saver_Screen_saver_executable_name_is_set_to_Enabled_scrnsave.scr" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.1.3.3_L1_Ensure_Password_protect_the_screen_saver_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.1.3.4_L1_Ensure_Screen_saver_timeout_is_set_to_Enabled_900_seconds_or_fewer_but_not_0" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.5.1.1_L1_Ensure_Turn_off_toast_notifications_on_the_lock_screen_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.7.4.1_L1_Ensure_Do_not_preserve_zone_information_in_file_attachments_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.7.4.2_L1_Ensure_Notify_antivirus_programs_when_opening_attachments_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.7.7.1_L1_Ensure_Configure_Windows_spotlight_on_lock_screen_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.7.7.2_L1_Ensure_Do_not_suggest_third-party_content_in_Windows_spotlight_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.7.26.1_L1_Ensure_Prevent_users_from_sharing_files_within_their_profile._is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.7.41.1_L1_Ensure_Always_install_with_elevated_privileges_is_set_to_Disabled" selected="true"/> </xccdf:Profile> |
Level 1 - Member Server |
Items in this profile apply to Member Servers and intend to:
Items in this profile also apply to Member Servers that have the following Roles enabled:
Show
Profile XML
<xccdf:Profile xmlns="http://checklists.nist.gov/xccdf/1.2" xmlns:ae="http://benchmarks.cisecurity.org/ae/0.5" xmlns:cc6="http://cisecurity.org/20-cc/v6.1" xmlns:cc7="http://cisecurity.org/20-cc/v7.0" xmlns:ciscf="https://benchmarks.cisecurity.org/ciscf/1.0" xmlns:notes="http://benchmarks.cisecurity.org/notes" xmlns:xccdf="http://checklists.nist.gov/xccdf/1.2" xmlns:xhtml="http://www.w3.org/1999/xhtml" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" id="xccdf_org.cisecurity.benchmarks_profile_Level_1_-_Member_Server"> <xccdf:title xml:lang="en">Level 1 - Member Server</xccdf:title> <xccdf:description xml:lang="en"> <xhtml:p>Items in this profile apply to Member Servers and intend to:</xhtml:p> <xhtml:ul> <xhtml:li>be practical and prudent;</xhtml:li> <xhtml:li>provide a clear security benefit; and</xhtml:li> <xhtml:li>not inhibit the utility of the technology beyond acceptable means.</xhtml:li> </xhtml:ul> <xhtml:p>Items in this profile also apply to Member Servers that have the following Roles enabled:</xhtml:p> <xhtml:ul> <xhtml:li>AD Certificate Services</xhtml:li> <xhtml:li>DHCP Server</xhtml:li> <xhtml:li>DNS Server</xhtml:li> <xhtml:li>File Server</xhtml:li> <xhtml:li>Hyper-V</xhtml:li> <xhtml:li>Network Policy and Access Services</xhtml:li> <xhtml:li>Print Server</xhtml:li> <xhtml:li>Remote Access Services</xhtml:li> <xhtml:li>Remote Desktop Services</xhtml:li> <xhtml:li>Web Server</xhtml:li> </xhtml:ul> </xccdf:description> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.1.1_L1_Ensure_Enforce_password_history_is_set_to_24_or_more_passwords" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.1.2_L1_Ensure_Maximum_password_age_is_set_to_60_or_fewer_days_but_not_0" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.1.3_L1_Ensure_Minimum_password_age_is_set_to_1_or_more_days" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.1.4_L1_Ensure_Minimum_password_length_is_set_to_14_or_more_characters" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.1.5_L1_Ensure_Password_must_meet_complexity_requirements_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.1.6_L1_Ensure_Store_passwords_using_reversible_encryption_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.2.1_L1_Ensure_Account_lockout_duration_is_set_to_15_or_more_minutes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.2.2_L1_Ensure_Account_lockout_threshold_is_set_to_10_or_fewer_invalid_logon_attempts_but_not_0" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.2.3_L1_Ensure_Reset_account_lockout_counter_after_is_set_to_15_or_more_minutes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.1_L1_Ensure_Access_Credential_Manager_as_a_trusted_caller_is_set_to_No_One" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.3_L1_Ensure_Access_this_computer_from_the_network__is_set_to_Administrators_Authenticated_Users_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.4_L1_Ensure_Act_as_part_of_the_operating_system_is_set_to_No_One" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.6_L1_Ensure_Adjust_memory_quotas_for_a_process_is_set_to_Administrators_LOCAL_SERVICE_NETWORK_SERVICE" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.7_L1_Ensure_Allow_log_on_locally_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.9_L1_Ensure_Allow_log_on_through_Remote_Desktop_Services_is_set_to_Administrators_Remote_Desktop_Users_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.10_L1_Ensure_Back_up_files_and_directories_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.11_L1_Ensure_Change_the_system_time_is_set_to_Administrators_LOCAL_SERVICE" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.12_L1_Ensure_Change_the_time_zone_is_set_to_Administrators_LOCAL_SERVICE" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.13_L1_Ensure_Create_a_pagefile_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.14_L1_Ensure_Create_a_token_object_is_set_to_No_One" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.15_L1_Ensure_Create_global_objects_is_set_to_Administrators_LOCAL_SERVICE_NETWORK_SERVICE_SERVICE" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.16_L1_Ensure_Create_permanent_shared_objects_is_set_to_No_One" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.18_L1_Ensure_Create_symbolic_links_is_set_to_Administrators_NT_VIRTUAL_MACHINEVirtual_Machines_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.19_L1_Ensure_Debug_programs_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.21_L1_Ensure_Deny_access_to_this_computer_from_the_network_to_include_Guests_Local_account_and_member_of_Administrators_group_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.22_L1_Ensure_Deny_log_on_as_a_batch_job_to_include_Guests" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.23_L1_Ensure_Deny_log_on_as_a_service_to_include_Guests" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.24_L1_Ensure_Deny_log_on_locally_to_include_Guests" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.26_L1_Ensure_Deny_log_on_through_Remote_Desktop_Services_is_set_to_Guests_Local_account_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.28_L1_Ensure_Enable_computer_and_user_accounts_to_be_trusted_for_delegation_is_set_to_No_One_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.29_L1_Ensure_Force_shutdown_from_a_remote_system_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.30_L1_Ensure_Generate_security_audits_is_set_to_LOCAL_SERVICE_NETWORK_SERVICE" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.32_L1_Ensure_Impersonate_a_client_after_authentication_is_set_to_Administrators_LOCAL_SERVICE_NETWORK_SERVICE_SERVICE_and_when_the_Web_Server_IIS_Role_with_Web_Services_Role_Service_is_installed_IIS_IUSRS_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.33_L1_Ensure_Increase_scheduling_priority_is_set_to_Administrators_Window_ManagerWindow_Manager_Group" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.34_L1_Ensure_Load_and_unload_device_drivers_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.35_L1_Ensure_Lock_pages_in_memory_is_set_to_No_One" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.38_L1_Ensure_Manage_auditing_and_security_log_is_set_to_Administrators_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.39_L1_Ensure_Modify_an_object_label_is_set_to_No_One" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.40_L1_Ensure_Modify_firmware_environment_values_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.41_L1_Ensure_Perform_volume_maintenance_tasks_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.42_L1_Ensure_Profile_single_process_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.43_L1_Ensure_Profile_system_performance_is_set_to_Administrators_NT_SERVICEWdiServiceHost" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.44_L1_Ensure_Replace_a_process_level_token_is_set_to_LOCAL_SERVICE_NETWORK_SERVICE" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.45_L1_Ensure_Restore_files_and_directories_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.46_L1_Ensure_Shut_down_the_system_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.48_L1_Ensure_Take_ownership_of_files_or_other_objects_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.1.1_L1_Ensure_Accounts_Administrator_account_status_is_set_to_Disabled_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.1.2_L1_Ensure_Accounts_Block_Microsoft_accounts_is_set_to_Users_cant_add_or_log_on_with_Microsoft_accounts" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.1.3_L1_Ensure_Accounts_Guest_account_status_is_set_to_Disabled_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.1.4_L1_Ensure_Accounts_Limit_local_account_use_of_blank_passwords_to_console_logon_only_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.1.5_L1_Configure_Accounts_Rename_administrator_account" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.1.6_L1_Configure_Accounts_Rename_guest_account" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.2.1_L1_Ensure_Audit_Force_audit_policy_subcategory_settings_Windows_Vista_or_later_to_override_audit_policy_category_settings_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.2.2_L1_Ensure_Audit_Shut_down_system_immediately_if_unable_to_log_security_audits_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.4.1_L1_Ensure_Devices_Allowed_to_format_and_eject_removable_media_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.4.2_L1_Ensure_Devices_Prevent_users_from_installing_printer_drivers_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.6.1_L1_Ensure_Domain_member_Digitally_encrypt_or_sign_secure_channel_data_always_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.6.2_L1_Ensure_Domain_member_Digitally_encrypt_secure_channel_data_when_possible_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.6.3_L1_Ensure_Domain_member_Digitally_sign_secure_channel_data_when_possible_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.6.4_L1_Ensure_Domain_member_Disable_machine_account_password_changes_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.6.5_L1_Ensure_Domain_member_Maximum_machine_account_password_age_is_set_to_30_or_fewer_days_but_not_0" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.6.6_L1_Ensure_Domain_member_Require_strong_Windows_2000_or_later_session_key_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.7.1_L1_Ensure_Interactive_logon_Do_not_require_CTRLALTDEL_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.7.2_L1_Ensure_Interactive_logon_Dont_display_last_signed-in_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.7.3_L1_Ensure_Interactive_logon_Machine_inactivity_limit_is_set_to_900_or_fewer_seconds_but_not_0" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.7.4_L1_Configure_Interactive_logon_Message_text_for_users_attempting_to_log_on" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.7.5_L1_Configure_Interactive_logon_Message_title_for_users_attempting_to_log_on" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.7.7_L1_Ensure_Interactive_logon_Prompt_user_to_change_password_before_expiration_is_set_to_between_5_and_14_days" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.7.8_L1_Ensure_Interactive_logon_Require_Domain_Controller_Authentication_to_unlock_workstation_is_set_to_Enabled_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.7.9_L1_Ensure_Interactive_logon_Smart_card_removal_behavior_is_set_to_Lock_Workstation_or_higher" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.8.1_L1_Ensure_Microsoft_network_client_Digitally_sign_communications_always_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.8.2_L1_Ensure_Microsoft_network_client_Digitally_sign_communications_if_server_agrees_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.8.3_L1_Ensure_Microsoft_network_client_Send_unencrypted_password_to_third-party_SMB_servers_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.9.1_L1_Ensure_Microsoft_network_server_Amount_of_idle_time_required_before_suspending_session_is_set_to_15_or_fewer_minutes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.9.2_L1_Ensure_Microsoft_network_server_Digitally_sign_communications_always_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.9.3_L1_Ensure_Microsoft_network_server_Digitally_sign_communications_if_client_agrees_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.9.4_L1_Ensure_Microsoft_network_server_Disconnect_clients_when_logon_hours_expire_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.9.5_L1_Ensure_Microsoft_network_server_Server_SPN_target_name_validation_level_is_set_to_Accept_if_provided_by_client_or_higher_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.1_L1_Ensure_Network_access_Allow_anonymous_SIDName_translation_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.2_L1_Ensure_Network_access_Do_not_allow_anonymous_enumeration_of_SAM_accounts_is_set_to_Enabled_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.3_L1_Ensure_Network_access_Do_not_allow_anonymous_enumeration_of_SAM_accounts_and_shares_is_set_to_Enabled_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.5_L1_Ensure_Network_access_Let_Everyone_permissions_apply_to_anonymous_users_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.7_L1_Configure_Network_access_Named_Pipes_that_can_be_accessed_anonymously_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.8_L1_Configure_Network_access_Remotely_accessible_registry_paths" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.9_L1_Configure_Network_access_Remotely_accessible_registry_paths_and_sub-paths" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.10_L1_Ensure_Network_access_Restrict_anonymous_access_to_Named_Pipes_and_Shares_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.11_L1_Ensure_Network_access_Restrict_clients_allowed_to_make_remote_calls_to_SAM_is_set_to_Administrators_Remote_Access_Allow_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.12_L1_Ensure_Network_access_Shares_that_can_be_accessed_anonymously_is_set_to_None" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.13_L1_Ensure_Network_access_Sharing_and_security_model_for_local_accounts_is_set_to_Classic_-_local_users_authenticate_as_themselves" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.1_L1_Ensure_Network_security_Allow_Local_System_to_use_computer_identity_for_NTLM_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.2_L1_Ensure_Network_security_Allow_LocalSystem_NULL_session_fallback_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.3_L1_Ensure_Network_Security_Allow_PKU2U_authentication_requests_to_this_computer_to_use_online_identities_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.4_L1_Ensure_Network_security_Configure_encryption_types_allowed_for_Kerberos_is_set_to_AES128_HMAC_SHA1_AES256_HMAC_SHA1_Future_encryption_types" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.5_L1_Ensure_Network_security_Do_not_store_LAN_Manager_hash_value_on_next_password_change_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.6_L1_Ensure_Network_security_Force_logoff_when_logon_hours_expire_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.7_L1_Ensure_Network_security_LAN_Manager_authentication_level_is_set_to_Send_NTLMv2_response_only._Refuse_LM__NTLM" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.8_L1_Ensure_Network_security_LDAP_client_signing_requirements_is_set_to_Negotiate_signing_or_higher" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.9_L1_Ensure_Network_security_Minimum_session_security_for_NTLM_SSP_based_including_secure_RPC_clients_is_set_to_Require_NTLMv2_session_security_Require_128-bit_encryption" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.10_L1_Ensure_Network_security_Minimum_session_security_for_NTLM_SSP_based_including_secure_RPC_servers_is_set_to_Require_NTLMv2_session_security_Require_128-bit_encryption" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.13.1_L1_Ensure_Shutdown_Allow_system_to_be_shut_down_without_having_to_log_on_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.15.1_L1_Ensure_System_objects_Require_case_insensitivity_for_non-Windows_subsystems_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.15.2_L1_Ensure_System_objects_Strengthen_default_permissions_of_internal_system_objects_e.g._Symbolic_Links_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.17.1_L1_Ensure_User_Account_Control_Admin_Approval_Mode_for_the_Built-in_Administrator_account_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.17.2_L1_Ensure_User_Account_Control_Behavior_of_the_elevation_prompt_for_administrators_in_Admin_Approval_Mode_is_set_to_Prompt_for_consent_on_the_secure_desktop" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.17.3_L1_Ensure_User_Account_Control_Behavior_of_the_elevation_prompt_for_standard_users_is_set_to_Automatically_deny_elevation_requests" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.17.4_L1_Ensure_User_Account_Control_Detect_application_installations_and_prompt_for_elevation_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.17.5_L1_Ensure_User_Account_Control_Only_elevate_UIAccess_applications_that_are_installed_in_secure_locations_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.17.6_L1_Ensure_User_Account_Control_Run_all_administrators_in_Admin_Approval_Mode_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.17.7_L1_Ensure_User_Account_Control_Switch_to_the_secure_desktop_when_prompting_for_elevation_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.17.8_L1_Ensure_User_Account_Control_Virtualize_file_and_registry_write_failures_to_per-user_locations_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.1.1_L1_Ensure_Windows_Firewall_Domain_Firewall_state_is_set_to_On_recommended" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.1.2_L1_Ensure_Windows_Firewall_Domain_Inbound_connections_is_set_to_Block_default" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.1.3_L1_Ensure_Windows_Firewall_Domain_Outbound_connections_is_set_to_Allow_default" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.1.4_L1_Ensure_Windows_Firewall_Domain_Settings_Display_a_notification_is_set_to_No" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.1.5_L1_Ensure_Windows_Firewall_Domain_Logging_Name_is_set_to_SystemRootSystem32logfilesfirewalldomainfw.log" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.1.6_L1_Ensure_Windows_Firewall_Domain_Logging_Size_limit_KB_is_set_to_16384_KB_or_greater" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.1.7_L1_Ensure_Windows_Firewall_Domain_Logging_Log_dropped_packets_is_set_to_Yes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.1.8_L1_Ensure_Windows_Firewall_Domain_Logging_Log_successful_connections_is_set_to_Yes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.2.1_L1_Ensure_Windows_Firewall_Private_Firewall_state_is_set_to_On_recommended" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.2.2_L1_Ensure_Windows_Firewall_Private_Inbound_connections_is_set_to_Block_default" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.2.3_L1_Ensure_Windows_Firewall_Private_Outbound_connections_is_set_to_Allow_default" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.2.4_L1_Ensure_Windows_Firewall_Private_Settings_Display_a_notification_is_set_to_No" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.2.5_L1_Ensure_Windows_Firewall_Private_Logging_Name_is_set_to_SystemRootSystem32logfilesfirewallprivatefw.log" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.2.6_L1_Ensure_Windows_Firewall_Private_Logging_Size_limit_KB_is_set_to_16384_KB_or_greater" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.2.7_L1_Ensure_Windows_Firewall_Private_Logging_Log_dropped_packets_is_set_to_Yes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.2.8_L1_Ensure_Windows_Firewall_Private_Logging_Log_successful_connections_is_set_to_Yes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.1_L1_Ensure_Windows_Firewall_Public_Firewall_state_is_set_to_On_recommended" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.2_L1_Ensure_Windows_Firewall_Public_Inbound_connections_is_set_to_Block_default" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.3_L1_Ensure_Windows_Firewall_Public_Outbound_connections_is_set_to_Allow_default" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.4_L1_Ensure_Windows_Firewall_Public_Settings_Display_a_notification_is_set_to_No" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.5_L1_Ensure_Windows_Firewall_Public_Settings_Apply_local_firewall_rules_is_set_to_No" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.6_L1_Ensure_Windows_Firewall_Public_Settings_Apply_local_connection_security_rules_is_set_to_No" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.7_L1_Ensure_Windows_Firewall_Public_Logging_Name_is_set_to_SystemRootSystem32logfilesfirewallpublicfw.log" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.8_L1_Ensure_Windows_Firewall_Public_Logging_Size_limit_KB_is_set_to_16384_KB_or_greater" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.9_L1_Ensure_Windows_Firewall_Public_Logging_Log_dropped_packets_is_set_to_Yes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.10_L1_Ensure_Windows_Firewall_Public_Logging_Log_successful_connections_is_set_to_Yes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.1.1_L1_Ensure_Audit_Credential_Validation_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.2.1_L1_Ensure_Audit_Application_Group_Management_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.2.5_L1_Ensure_Audit_Security_Group_Management_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.2.6_L1_Ensure_Audit_User_Account_Management_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.3.1_L1_Ensure_Audit_PNP_Activity_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.3.2_L1_Ensure_Audit_Process_Creation_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.5.1_L1_Ensure_Audit_Account_Lockout_is_set_to_include_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.5.2_L1_Ensure_Audit_Group_Membership_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.5.3_L1_Ensure_Audit_Logoff_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.5.4_L1_Ensure_Audit_Logon_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.5.5_L1_Ensure_Audit_Other_LogonLogoff_Events_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.5.6_L1_Ensure_Audit_Special_Logon_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.6.1_L1_Ensure_Audit_Detailed_File_Share_is_set_to_include_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.6.2_L1_Ensure_Audit_File_Share_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.6.3_L1_Ensure_Audit_Other_Object_Access_Events_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.6.4_L1_Ensure_Audit_Removable_Storage_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.7.1_L1_Ensure_Audit_Audit_Policy_Change_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.7.2_L1_Ensure_Audit_Authentication_Policy_Change_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.7.3_L1_Ensure_Audit_Authorization_Policy_Change_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.7.4_L1_Ensure_Audit_MPSSVC_Rule-Level_Policy_Change_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.7.5_L1_Ensure_Audit_Other_Policy_Change_Events_is_set_to_include_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.8.1_L1_Ensure_Audit_Sensitive_Privilege_Use_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.9.1_L1_Ensure_Audit_IPsec_Driver_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.9.2_L1_Ensure_Audit_Other_System_Events_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.9.3_L1_Ensure_Audit_Security_State_Change_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.9.4_L1_Ensure_Audit_Security_System_Extension_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.9.5_L1_Ensure_Audit_System_Integrity_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.1.1.1_L1_Ensure_Prevent_enabling_lock_screen_camera_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.1.1.2_L1_Ensure_Prevent_enabling_lock_screen_slide_show_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.1.2.2_L1_Ensure_Allow_users_to_enable_online_speech_recognition_services_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.2.1_L1_Ensure_LAPS_AdmPwd_GPO_Extension__CSE_is_installed_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.2.2_L1_Ensure_Do_not_allow_password_expiration_time_longer_than_required_by_policy_is_set_to_Enabled_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.2.3_L1_Ensure_Enable_Local_Admin_Password_Management_is_set_to_Enabled_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.2.4_L1_Ensure_Password_Settings_Password_Complexity_is_set_to_Enabled_Large_letters__small_letters__numbers__special_characters_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.2.5_L1_Ensure_Password_Settings_Password_Length_is_set_to_Enabled_15_or_more_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.2.6_L1_Ensure_Password_Settings_Password_Age_Days_is_set_to_Enabled_30_or_fewer_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.3.1_L1_Ensure_Apply_UAC_restrictions_to_local_accounts_on_network_logons_is_set_to_Enabled_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.3.2_L1_Ensure_Configure_SMB_v1_client_driver_is_set_to_Enabled_Disable_driver_recommended" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.3.3_L1_Ensure_Configure_SMB_v1_server_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.3.4_L1_Ensure_Enable_Structured_Exception_Handling_Overwrite_Protection_SEHOP_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.3.6_L1_Ensure_NetBT_NodeType_configuration_is_set_to_Enabled_P-node_recommended" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.3.7_L1_Ensure_WDigest_Authentication_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.1_L1_Ensure_MSS_AutoAdminLogon_Enable_Automatic_Logon_not_recommended_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.2_L1_Ensure_MSS_DisableIPSourceRouting_IPv6_IP_source_routing_protection_level_protects_against_packet_spoofing_is_set_to_Enabled_Highest_protection_source_routing_is_completely_disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.3_L1_Ensure_MSS_DisableIPSourceRouting_IP_source_routing_protection_level_protects_against_packet_spoofing_is_set_to_Enabled_Highest_protection_source_routing_is_completely_disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.4_L1_Ensure_MSS_EnableICMPRedirect_Allow_ICMP_redirects_to_override_OSPF_generated_routes_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.6_L1_Ensure_MSS_NoNameReleaseOnDemand_Allow_the_computer_to_ignore_NetBIOS_name_release_requests_except_from_WINS_servers_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.8_L1_Ensure_MSS_SafeDllSearchMode_Enable_Safe_DLL_search_mode_recommended_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.9_L1_Ensure_MSS_ScreenSaverGracePeriod_The_time_in_seconds_before_the_screen_saver_grace_period_expires_0_recommended_is_set_to_Enabled_5_or_fewer_seconds" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.12_L1_Ensure_MSS_WarningLevel_Percentage_threshold_for_the_security_event_log_at_which_the_system_will_generate_a_warning_is_set_to_Enabled_90_or_less" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.4.1_L1_Ensure_Turn_off_multicast_name_resolution_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.8.1_L1_Ensure_Enable_insecure_guest_logons_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.11.2_L1_Ensure_Prohibit_installation_and_configuration_of_Network_Bridge_on_your_DNS_domain_network_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.11.3_L1_Ensure_Prohibit_use_of_Internet_Connection_Sharing_on_your_DNS_domain_network_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.11.4_L1_Ensure_Require_domain_users_to_elevate_when_setting_a_networks_location_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.14.1_L1_Ensure_Hardened_UNC_Paths_is_set_to_Enabled_with_Require_Mutual_Authentication_and_Require_Integrity_set_for_all_NETLOGON_and_SYSVOL_shares" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.21.1_L1_Ensure_Minimize_the_number_of_simultaneous_connections_to_the_Internet_or_a_Windows_Domain_is_set_to_Enabled_3__Prevent_Wi-Fi_when_on_Ethernet" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.3.1_L1_Ensure_Include_command_line_in_process_creation_events_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.4.1_L1_Ensure_Encryption_Oracle_Remediation_is_set_to_Enabled_Force_Updated_Clients" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.4.2_L1_Ensure_Remote_host_allows_delegation_of_non-exportable_credentials_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.14.1_L1_Ensure_Boot-Start_Driver_Initialization_Policy_is_set_to_Enabled_Good_unknown_and_bad_but_critical" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.21.2_L1_Ensure_Configure_registry_policy_processing_Do_not_apply_during_periodic_background_processing_is_set_to_Enabled_FALSE" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.21.3_L1_Ensure_Configure_registry_policy_processing_Process_even_if_the_Group_Policy_objects_have_not_changed_is_set_to_Enabled_TRUE" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.21.4_L1_Ensure_Continue_experiences_on_this_device_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.21.5_L1_Ensure_Turn_off_background_refresh_of_Group_Policy_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.22.1.1_L1_Ensure_Turn_off_downloading_of_print_drivers_over_HTTP_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.22.1.5_L1_Ensure_Turn_off_Internet_download_for_Web_publishing_and_online_ordering_wizards_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.26.1_L1_Ensure_Enumeration_policy_for_external_devices_incompatible_with_Kernel_DMA_Protection_is_set_to_Enabled_Block_All" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.28.1_L1_Ensure_Block_user_from_showing_account_details_on_sign-in_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.28.2_L1_Ensure_Do_not_display_network_selection_UI_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.28.3_L1_Ensure_Do_not_enumerate_connected_users_on_domain-joined_computers_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.28.4_L1_Ensure_Enumerate_local_users_on_domain-joined_computers_is_set_to_Disabled_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.28.5_L1_Ensure_Turn_off_app_notifications_on_the_lock_screen_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.28.6_L1_Ensure_Turn_off_picture_password_sign-in_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.28.7_L1_Ensure_Turn_on_convenience_PIN_sign-in_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.34.6.3_L1_Ensure_Require_a_password_when_a_computer_wakes_on_battery_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.34.6.4_L1_Ensure_Require_a_password_when_a_computer_wakes_plugged_in_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.36.1_L1_Ensure_Configure_Offer_Remote_Assistance_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.36.2_L1_Ensure_Configure_Solicited_Remote_Assistance_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.37.1_L1_Ensure_Enable_RPC_Endpoint_Mapper_Client_Authentication_is_set_to_Enabled_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.6.1_L1_Ensure_Allow_Microsoft_accounts_to_be_optional_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.8.1_L1_Ensure_Disallow_Autoplay_for_non-volume_devices_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.8.2_L1_Ensure_Set_the_default_behavior_for_AutoRun_is_set_to_Enabled_Do_not_execute_any_autorun_commands" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.8.3_L1_Ensure_Turn_off_Autoplay_is_set_to_Enabled_All_drives" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.10.1.1_L1_Ensure_Configure_enhanced_anti-spoofing_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.13.1_L1_Ensure_Turn_off_Microsoft_consumer_experiences_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.14.1_L1_Ensure_Require_pin_for_pairing_is_set_to_Enabled_First_Time_OR_Enabled_Always" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.15.1_L1_Ensure_Do_not_display_the_password_reveal_button_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.15.2_L1_Ensure_Enumerate_administrator_accounts_on_elevation_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.16.1_L1_Ensure_Allow_Telemetry_is_set_to_Enabled_0_-_Security_Enterprise_Only_or_Enabled_1_-_Basic" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.16.3_L1_Ensure_Do_not_show_feedback_notifications_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.16.4_L1_Ensure_Toggle_user_control_over_Insider_builds_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.26.1.1_L1_Ensure_Application_Control_Event_Log_behavior_when_the_log_file_reaches_its_maximum_size_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.26.1.2_L1_Ensure_Application_Specify_the_maximum_log_file_size_KB_is_set_to_Enabled_32768_or_greater" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.26.2.1_L1_Ensure_Security_Control_Event_Log_behavior_when_the_log_file_reaches_its_maximum_size_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.26.2.2_L1_Ensure_Security_Specify_the_maximum_log_file_size_KB_is_set_to_Enabled_196608_or_greater" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.26.3.1_L1_Ensure_Setup_Control_Event_Log_behavior_when_the_log_file_reaches_its_maximum_size_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.26.3.2_L1_Ensure_Setup_Specify_the_maximum_log_file_size_KB_is_set_to_Enabled_32768_or_greater" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.26.4.1_L1_Ensure_System_Control_Event_Log_behavior_when_the_log_file_reaches_its_maximum_size_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.26.4.2_L1_Ensure_System_Specify_the_maximum_log_file_size_KB_is_set_to_Enabled_32768_or_greater" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.30.2_L1_Ensure_Turn_off_Data_Execution_Prevention_for_Explorer_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.30.3_L1_Ensure_Turn_off_heap_termination_on_corruption_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.30.4_L1_Ensure_Turn_off_shell_protocol_protected_mode_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.44.1_L1_Ensure_Block_all_consumer_Microsoft_account_user_authentication_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.52.1_L1_Ensure_Prevent_the_usage_of_OneDrive_for_file_storage_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.2.2_L1_Ensure_Do_not_allow_passwords_to_be_saved_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.3.2_L1_Ensure_Do_not_allow_drive_redirection_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.9.1_L1_Ensure_Always_prompt_for_password_upon_connection_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.9.2_L1_Ensure_Require_secure_RPC_communication_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.9.3_L1_Ensure_Require_use_of_specific_security_layer_for_remote_RDP_connections_is_set_to_Enabled_SSL" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.9.4_L1_Ensure_Require_user_authentication_for_remote_connections_by_using_Network_Level_Authentication_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.9.5_L1_Ensure_Set_client_connection_encryption_level_is_set_to_Enabled_High_Level" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.11.1_L1_Ensure_Do_not_delete_temp_folders_upon_exit_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.11.2_L1_Ensure_Do_not_use_temporary_folders_per_session_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.60.1_L1_Ensure_Prevent_downloading_of_enclosures_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.61.3_L1_Ensure_Allow_indexing_of_encrypted_files_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.3.1_L1_Ensure_Configure_local_setting_override_for_reporting_to_Microsoft_MAPS_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.7.1_L1_Ensure_Turn_on_behavior_monitoring_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.10.1_L1_Ensure_Scan_removable_drives_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.10.2_L1_Ensure_Turn_on_e-mail_scanning_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.13.1.1_L1_Ensure_Configure_Attack_Surface_Reduction_rules_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.13.1.2_L1_Ensure_Configure_Attack_Surface_Reduction_rules_Set_the_state_for_each_ASR_rule_is_configured" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.13.3.1_L1_Ensure_Prevent_users_and_apps_from_accessing_dangerous_websites_is_set_to_Enabled_Block" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.14_L1_Ensure_Configure_detection_for_potentially_unwanted_applications_is_set_to_Enabled_Block" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.15_L1_Ensure_Turn_off_Windows_Defender_AntiVirus_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.80.1.1_L1_Ensure_Configure_Windows_Defender_SmartScreen_is_set_to_Enabled_Warn_and_prevent_bypass" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.84.2_L1_Ensure_Allow_Windows_Ink_Workspace_is_set_to_Enabled_On_but_disallow_access_above_lock_OR_Disabled_but_not_Enabled_On" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.85.1_L1_Ensure_Allow_user_control_over_installs_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.85.2_L1_Ensure_Always_install_with_elevated_privileges_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.86.1_L1_Ensure_Sign-in_and_lock_last_interactive_user_automatically_after_a_restart_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.95.1_L1_Ensure_Turn_on_PowerShell_Script_Block_Logging_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.95.2_L1_Ensure_Turn_on_PowerShell_Transcription_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.97.1.1_L1_Ensure_Allow_Basic_authentication_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.97.1.2_L1_Ensure_Allow_unencrypted_traffic_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.97.1.3_L1_Ensure_Disallow_Digest_authentication_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.97.2.1_L1_Ensure_Allow_Basic_authentication_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.97.2.3_L1_Ensure_Allow_unencrypted_traffic_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.97.2.4_L1_Ensure_Disallow_WinRM_from_storing_RunAs_credentials_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.99.2.1_L1_Ensure_Prevent_users_from_modifying_settings_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.102.1.1_L1_Ensure_Manage_preview_builds_is_set_to_Enabled_Disable_preview_builds" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.102.1.2_L1_Ensure_Select_when_Preview_Builds_and_Feature_Updates_are_received_is_set_to_Enabled_Semi-Annual_Channel_180_or_more_days" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.102.1.3_L1_Ensure_Select_when_Quality_Updates_are_received_is_set_to_Enabled_0_days" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.102.2_L1_Ensure_Configure_Automatic_Updates_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.102.3_L1_Ensure_Configure_Automatic_Updates_Scheduled_install_day_is_set_to_0_-_Every_day" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.102.4_L1_Ensure_No_auto-restart_with_logged_on_users_for_scheduled_automatic_updates_installations_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.1.3.1_L1_Ensure_Enable_screen_saver_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.1.3.2_L1_Ensure_Force_specific_screen_saver_Screen_saver_executable_name_is_set_to_Enabled_scrnsave.scr" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.1.3.3_L1_Ensure_Password_protect_the_screen_saver_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.1.3.4_L1_Ensure_Screen_saver_timeout_is_set_to_Enabled_900_seconds_or_fewer_but_not_0" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.5.1.1_L1_Ensure_Turn_off_toast_notifications_on_the_lock_screen_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.7.4.1_L1_Ensure_Do_not_preserve_zone_information_in_file_attachments_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.7.4.2_L1_Ensure_Notify_antivirus_programs_when_opening_attachments_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.7.7.1_L1_Ensure_Configure_Windows_spotlight_on_lock_screen_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.7.7.2_L1_Ensure_Do_not_suggest_third-party_content_in_Windows_spotlight_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.7.26.1_L1_Ensure_Prevent_users_from_sharing_files_within_their_profile._is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.7.41.1_L1_Ensure_Always_install_with_elevated_privileges_is_set_to_Disabled" selected="true"/> </xccdf:Profile> |
Level 2 - Domain Controller |
This profile extends the "Level 1 - Domain Controller" profile. Items in this profile exhibit one or more of the following characteristics:
Show
Profile XML
<xccdf:Profile xmlns="http://checklists.nist.gov/xccdf/1.2" xmlns:ae="http://benchmarks.cisecurity.org/ae/0.5" xmlns:cc6="http://cisecurity.org/20-cc/v6.1" xmlns:cc7="http://cisecurity.org/20-cc/v7.0" xmlns:ciscf="https://benchmarks.cisecurity.org/ciscf/1.0" xmlns:notes="http://benchmarks.cisecurity.org/notes" xmlns:xccdf="http://checklists.nist.gov/xccdf/1.2" xmlns:xhtml="http://www.w3.org/1999/xhtml" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" id="xccdf_org.cisecurity.benchmarks_profile_Level_2_-_Domain_Controller"> <xccdf:title xml:lang="en">Level 2 - Domain Controller</xccdf:title> <xccdf:description xml:lang="en"> <xhtml:p>This profile extends the "Level 1 - Domain Controller" profile. Items in this profile exhibit one or more of the following characteristics:</xhtml:p> <xhtml:ul> <xhtml:li>are intended for environments or use cases where security is paramount</xhtml:li> <xhtml:li>acts as defense in depth measure</xhtml:li> <xhtml:li>may negatively inhibit the utility or performance of the technology</xhtml:li> </xhtml:ul> </xccdf:description> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.1.1_L1_Ensure_Enforce_password_history_is_set_to_24_or_more_passwords" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.1.2_L1_Ensure_Maximum_password_age_is_set_to_60_or_fewer_days_but_not_0" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.1.3_L1_Ensure_Minimum_password_age_is_set_to_1_or_more_days" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.1.4_L1_Ensure_Minimum_password_length_is_set_to_14_or_more_characters" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.1.5_L1_Ensure_Password_must_meet_complexity_requirements_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.1.6_L1_Ensure_Store_passwords_using_reversible_encryption_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.2.1_L1_Ensure_Account_lockout_duration_is_set_to_15_or_more_minutes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.2.2_L1_Ensure_Account_lockout_threshold_is_set_to_10_or_fewer_invalid_logon_attempts_but_not_0" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.2.3_L1_Ensure_Reset_account_lockout_counter_after_is_set_to_15_or_more_minutes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.1_L1_Ensure_Access_Credential_Manager_as_a_trusted_caller_is_set_to_No_One" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.2_L1_Ensure_Access_this_computer_from_the_network_is_set_to_Administrators_Authenticated_Users_ENTERPRISE_DOMAIN_CONTROLLERS_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.4_L1_Ensure_Act_as_part_of_the_operating_system_is_set_to_No_One" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.5_L1_Ensure_Add_workstations_to_domain_is_set_to_Administrators_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.6_L1_Ensure_Adjust_memory_quotas_for_a_process_is_set_to_Administrators_LOCAL_SERVICE_NETWORK_SERVICE" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.7_L1_Ensure_Allow_log_on_locally_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.8_L1_Ensure_Allow_log_on_through_Remote_Desktop_Services_is_set_to_Administrators_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.10_L1_Ensure_Back_up_files_and_directories_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.11_L1_Ensure_Change_the_system_time_is_set_to_Administrators_LOCAL_SERVICE" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.12_L1_Ensure_Change_the_time_zone_is_set_to_Administrators_LOCAL_SERVICE" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.13_L1_Ensure_Create_a_pagefile_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.14_L1_Ensure_Create_a_token_object_is_set_to_No_One" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.15_L1_Ensure_Create_global_objects_is_set_to_Administrators_LOCAL_SERVICE_NETWORK_SERVICE_SERVICE" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.16_L1_Ensure_Create_permanent_shared_objects_is_set_to_No_One" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.17_L1_Ensure_Create_symbolic_links_is_set_to_Administrators_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.19_L1_Ensure_Debug_programs_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.20_L1_Ensure_Deny_access_to_this_computer_from_the_network_to_include_Guests_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.22_L1_Ensure_Deny_log_on_as_a_batch_job_to_include_Guests" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.23_L1_Ensure_Deny_log_on_as_a_service_to_include_Guests" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.24_L1_Ensure_Deny_log_on_locally_to_include_Guests" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.25_L1_Ensure_Deny_log_on_through_Remote_Desktop_Services_to_include_Guests_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.27_L1_Ensure_Enable_computer_and_user_accounts_to_be_trusted_for_delegation_is_set_to_Administrators_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.29_L1_Ensure_Force_shutdown_from_a_remote_system_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.30_L1_Ensure_Generate_security_audits_is_set_to_LOCAL_SERVICE_NETWORK_SERVICE" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.31_L1_Ensure_Impersonate_a_client_after_authentication_is_set_to_Administrators_LOCAL_SERVICE_NETWORK_SERVICE_SERVICE_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.33_L1_Ensure_Increase_scheduling_priority_is_set_to_Administrators_Window_ManagerWindow_Manager_Group" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.34_L1_Ensure_Load_and_unload_device_drivers_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.35_L1_Ensure_Lock_pages_in_memory_is_set_to_No_One" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.36_L2_Ensure_Log_on_as_a_batch_job_is_set_to_Administrators_DC_Only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.37_L1_Ensure_Manage_auditing_and_security_log_is_set_to_Administrators_and_when_Exchange_is_running_in_the_environment_Exchange_Servers_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.39_L1_Ensure_Modify_an_object_label_is_set_to_No_One" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.40_L1_Ensure_Modify_firmware_environment_values_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.41_L1_Ensure_Perform_volume_maintenance_tasks_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.42_L1_Ensure_Profile_single_process_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.43_L1_Ensure_Profile_system_performance_is_set_to_Administrators_NT_SERVICEWdiServiceHost" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.44_L1_Ensure_Replace_a_process_level_token_is_set_to_LOCAL_SERVICE_NETWORK_SERVICE" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.45_L1_Ensure_Restore_files_and_directories_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.46_L1_Ensure_Shut_down_the_system_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.47_L1_Ensure_Synchronize_directory_service_data_is_set_to_No_One_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.48_L1_Ensure_Take_ownership_of_files_or_other_objects_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.1.2_L1_Ensure_Accounts_Block_Microsoft_accounts_is_set_to_Users_cant_add_or_log_on_with_Microsoft_accounts" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.1.4_L1_Ensure_Accounts_Limit_local_account_use_of_blank_passwords_to_console_logon_only_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.1.5_L1_Configure_Accounts_Rename_administrator_account" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.1.6_L1_Configure_Accounts_Rename_guest_account" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.2.1_L1_Ensure_Audit_Force_audit_policy_subcategory_settings_Windows_Vista_or_later_to_override_audit_policy_category_settings_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.2.2_L1_Ensure_Audit_Shut_down_system_immediately_if_unable_to_log_security_audits_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.4.1_L1_Ensure_Devices_Allowed_to_format_and_eject_removable_media_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.4.2_L1_Ensure_Devices_Prevent_users_from_installing_printer_drivers_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.5.1_L1_Ensure_Domain_controller_Allow_server_operators_to_schedule_tasks_is_set_to_Disabled_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.5.2_L1_Ensure_Domain_controller_LDAP_server_signing_requirements_is_set_to_Require_signing_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.5.3_L1_Ensure_Domain_controller_Refuse_machine_account_password_changes_is_set_to_Disabled_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.6.1_L1_Ensure_Domain_member_Digitally_encrypt_or_sign_secure_channel_data_always_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.6.2_L1_Ensure_Domain_member_Digitally_encrypt_secure_channel_data_when_possible_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.6.3_L1_Ensure_Domain_member_Digitally_sign_secure_channel_data_when_possible_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.6.4_L1_Ensure_Domain_member_Disable_machine_account_password_changes_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.6.5_L1_Ensure_Domain_member_Maximum_machine_account_password_age_is_set_to_30_or_fewer_days_but_not_0" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.6.6_L1_Ensure_Domain_member_Require_strong_Windows_2000_or_later_session_key_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.7.1_L1_Ensure_Interactive_logon_Do_not_require_CTRLALTDEL_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.7.2_L1_Ensure_Interactive_logon_Dont_display_last_signed-in_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.7.3_L1_Ensure_Interactive_logon_Machine_inactivity_limit_is_set_to_900_or_fewer_seconds_but_not_0" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.7.4_L1_Configure_Interactive_logon_Message_text_for_users_attempting_to_log_on" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.7.5_L1_Configure_Interactive_logon_Message_title_for_users_attempting_to_log_on" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.7.7_L1_Ensure_Interactive_logon_Prompt_user_to_change_password_before_expiration_is_set_to_between_5_and_14_days" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.7.9_L1_Ensure_Interactive_logon_Smart_card_removal_behavior_is_set_to_Lock_Workstation_or_higher" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.8.1_L1_Ensure_Microsoft_network_client_Digitally_sign_communications_always_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.8.2_L1_Ensure_Microsoft_network_client_Digitally_sign_communications_if_server_agrees_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.8.3_L1_Ensure_Microsoft_network_client_Send_unencrypted_password_to_third-party_SMB_servers_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.9.1_L1_Ensure_Microsoft_network_server_Amount_of_idle_time_required_before_suspending_session_is_set_to_15_or_fewer_minutes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.9.2_L1_Ensure_Microsoft_network_server_Digitally_sign_communications_always_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.9.3_L1_Ensure_Microsoft_network_server_Digitally_sign_communications_if_client_agrees_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.9.4_L1_Ensure_Microsoft_network_server_Disconnect_clients_when_logon_hours_expire_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.1_L1_Ensure_Network_access_Allow_anonymous_SIDName_translation_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.4_L2_Ensure_Network_access_Do_not_allow_storage_of_passwords_and_credentials_for_network_authentication_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.5_L1_Ensure_Network_access_Let_Everyone_permissions_apply_to_anonymous_users_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.6_L1_Configure_Network_access_Named_Pipes_that_can_be_accessed_anonymously_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.8_L1_Configure_Network_access_Remotely_accessible_registry_paths" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.9_L1_Configure_Network_access_Remotely_accessible_registry_paths_and_sub-paths" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.10_L1_Ensure_Network_access_Restrict_anonymous_access_to_Named_Pipes_and_Shares_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.12_L1_Ensure_Network_access_Shares_that_can_be_accessed_anonymously_is_set_to_None" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.13_L1_Ensure_Network_access_Sharing_and_security_model_for_local_accounts_is_set_to_Classic_-_local_users_authenticate_as_themselves" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.1_L1_Ensure_Network_security_Allow_Local_System_to_use_computer_identity_for_NTLM_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.2_L1_Ensure_Network_security_Allow_LocalSystem_NULL_session_fallback_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.3_L1_Ensure_Network_Security_Allow_PKU2U_authentication_requests_to_this_computer_to_use_online_identities_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.4_L1_Ensure_Network_security_Configure_encryption_types_allowed_for_Kerberos_is_set_to_AES128_HMAC_SHA1_AES256_HMAC_SHA1_Future_encryption_types" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.5_L1_Ensure_Network_security_Do_not_store_LAN_Manager_hash_value_on_next_password_change_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.6_L1_Ensure_Network_security_Force_logoff_when_logon_hours_expire_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.7_L1_Ensure_Network_security_LAN_Manager_authentication_level_is_set_to_Send_NTLMv2_response_only._Refuse_LM__NTLM" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.8_L1_Ensure_Network_security_LDAP_client_signing_requirements_is_set_to_Negotiate_signing_or_higher" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.9_L1_Ensure_Network_security_Minimum_session_security_for_NTLM_SSP_based_including_secure_RPC_clients_is_set_to_Require_NTLMv2_session_security_Require_128-bit_encryption" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.10_L1_Ensure_Network_security_Minimum_session_security_for_NTLM_SSP_based_including_secure_RPC_servers_is_set_to_Require_NTLMv2_session_security_Require_128-bit_encryption" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.13.1_L1_Ensure_Shutdown_Allow_system_to_be_shut_down_without_having_to_log_on_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.15.1_L1_Ensure_System_objects_Require_case_insensitivity_for_non-Windows_subsystems_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.15.2_L1_Ensure_System_objects_Strengthen_default_permissions_of_internal_system_objects_e.g._Symbolic_Links_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.17.1_L1_Ensure_User_Account_Control_Admin_Approval_Mode_for_the_Built-in_Administrator_account_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.17.2_L1_Ensure_User_Account_Control_Behavior_of_the_elevation_prompt_for_administrators_in_Admin_Approval_Mode_is_set_to_Prompt_for_consent_on_the_secure_desktop" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.17.3_L1_Ensure_User_Account_Control_Behavior_of_the_elevation_prompt_for_standard_users_is_set_to_Automatically_deny_elevation_requests" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.17.4_L1_Ensure_User_Account_Control_Detect_application_installations_and_prompt_for_elevation_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.17.5_L1_Ensure_User_Account_Control_Only_elevate_UIAccess_applications_that_are_installed_in_secure_locations_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.17.6_L1_Ensure_User_Account_Control_Run_all_administrators_in_Admin_Approval_Mode_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.17.7_L1_Ensure_User_Account_Control_Switch_to_the_secure_desktop_when_prompting_for_elevation_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.17.8_L1_Ensure_User_Account_Control_Virtualize_file_and_registry_write_failures_to_per-user_locations_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.1.1_L1_Ensure_Windows_Firewall_Domain_Firewall_state_is_set_to_On_recommended" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.1.2_L1_Ensure_Windows_Firewall_Domain_Inbound_connections_is_set_to_Block_default" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.1.3_L1_Ensure_Windows_Firewall_Domain_Outbound_connections_is_set_to_Allow_default" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.1.4_L1_Ensure_Windows_Firewall_Domain_Settings_Display_a_notification_is_set_to_No" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.1.5_L1_Ensure_Windows_Firewall_Domain_Logging_Name_is_set_to_SystemRootSystem32logfilesfirewalldomainfw.log" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.1.6_L1_Ensure_Windows_Firewall_Domain_Logging_Size_limit_KB_is_set_to_16384_KB_or_greater" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.1.7_L1_Ensure_Windows_Firewall_Domain_Logging_Log_dropped_packets_is_set_to_Yes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.1.8_L1_Ensure_Windows_Firewall_Domain_Logging_Log_successful_connections_is_set_to_Yes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.2.1_L1_Ensure_Windows_Firewall_Private_Firewall_state_is_set_to_On_recommended" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.2.2_L1_Ensure_Windows_Firewall_Private_Inbound_connections_is_set_to_Block_default" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.2.3_L1_Ensure_Windows_Firewall_Private_Outbound_connections_is_set_to_Allow_default" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.2.4_L1_Ensure_Windows_Firewall_Private_Settings_Display_a_notification_is_set_to_No" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.2.5_L1_Ensure_Windows_Firewall_Private_Logging_Name_is_set_to_SystemRootSystem32logfilesfirewallprivatefw.log" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.2.6_L1_Ensure_Windows_Firewall_Private_Logging_Size_limit_KB_is_set_to_16384_KB_or_greater" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.2.7_L1_Ensure_Windows_Firewall_Private_Logging_Log_dropped_packets_is_set_to_Yes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.2.8_L1_Ensure_Windows_Firewall_Private_Logging_Log_successful_connections_is_set_to_Yes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.1_L1_Ensure_Windows_Firewall_Public_Firewall_state_is_set_to_On_recommended" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.2_L1_Ensure_Windows_Firewall_Public_Inbound_connections_is_set_to_Block_default" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.3_L1_Ensure_Windows_Firewall_Public_Outbound_connections_is_set_to_Allow_default" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.4_L1_Ensure_Windows_Firewall_Public_Settings_Display_a_notification_is_set_to_No" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.5_L1_Ensure_Windows_Firewall_Public_Settings_Apply_local_firewall_rules_is_set_to_No" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.6_L1_Ensure_Windows_Firewall_Public_Settings_Apply_local_connection_security_rules_is_set_to_No" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.7_L1_Ensure_Windows_Firewall_Public_Logging_Name_is_set_to_SystemRootSystem32logfilesfirewallpublicfw.log" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.8_L1_Ensure_Windows_Firewall_Public_Logging_Size_limit_KB_is_set_to_16384_KB_or_greater" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.9_L1_Ensure_Windows_Firewall_Public_Logging_Log_dropped_packets_is_set_to_Yes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.10_L1_Ensure_Windows_Firewall_Public_Logging_Log_successful_connections_is_set_to_Yes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.1.1_L1_Ensure_Audit_Credential_Validation_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.1.2_L1_Ensure_Audit_Kerberos_Authentication_Service_is_set_to_Success_and_Failure_DC_Only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.1.3_L1_Ensure_Audit_Kerberos_Service_Ticket_Operations_is_set_to_Success_and_Failure_DC_Only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.2.1_L1_Ensure_Audit_Application_Group_Management_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.2.2_L1_Ensure_Audit_Computer_Account_Management_is_set_to_include_Success_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.2.3_L1_Ensure_Audit_Distribution_Group_Management_is_set_to_include_Success_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.2.4_L1_Ensure_Audit_Other_Account_Management_Events_is_set_to_include_Success_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.2.5_L1_Ensure_Audit_Security_Group_Management_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.2.6_L1_Ensure_Audit_User_Account_Management_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.3.1_L1_Ensure_Audit_PNP_Activity_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.3.2_L1_Ensure_Audit_Process_Creation_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.4.1_L1_Ensure_Audit_Directory_Service_Access_is_set_to_include_Failure_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.4.2_L1_Ensure_Audit_Directory_Service_Changes_is_set_to_include_Success_DC_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.5.1_L1_Ensure_Audit_Account_Lockout_is_set_to_include_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.5.2_L1_Ensure_Audit_Group_Membership_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.5.3_L1_Ensure_Audit_Logoff_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.5.4_L1_Ensure_Audit_Logon_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.5.5_L1_Ensure_Audit_Other_LogonLogoff_Events_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.5.6_L1_Ensure_Audit_Special_Logon_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.6.1_L1_Ensure_Audit_Detailed_File_Share_is_set_to_include_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.6.2_L1_Ensure_Audit_File_Share_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.6.3_L1_Ensure_Audit_Other_Object_Access_Events_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.6.4_L1_Ensure_Audit_Removable_Storage_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.7.1_L1_Ensure_Audit_Audit_Policy_Change_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.7.2_L1_Ensure_Audit_Authentication_Policy_Change_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.7.3_L1_Ensure_Audit_Authorization_Policy_Change_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.7.4_L1_Ensure_Audit_MPSSVC_Rule-Level_Policy_Change_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.7.5_L1_Ensure_Audit_Other_Policy_Change_Events_is_set_to_include_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.8.1_L1_Ensure_Audit_Sensitive_Privilege_Use_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.9.1_L1_Ensure_Audit_IPsec_Driver_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.9.2_L1_Ensure_Audit_Other_System_Events_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.9.3_L1_Ensure_Audit_Security_State_Change_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.9.4_L1_Ensure_Audit_Security_System_Extension_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.9.5_L1_Ensure_Audit_System_Integrity_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.1.1.1_L1_Ensure_Prevent_enabling_lock_screen_camera_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.1.1.2_L1_Ensure_Prevent_enabling_lock_screen_slide_show_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.1.2.2_L1_Ensure_Allow_users_to_enable_online_speech_recognition_services_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.1.3_L2_Ensure_Allow_Online_Tips_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.3.2_L1_Ensure_Configure_SMB_v1_client_driver_is_set_to_Enabled_Disable_driver_recommended" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.3.3_L1_Ensure_Configure_SMB_v1_server_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.3.4_L1_Ensure_Enable_Structured_Exception_Handling_Overwrite_Protection_SEHOP_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.3.5_L1_Ensure_Extended_Protection_for_LDAP_Authentication_Domain_Controllers_only_is_set_to_Enabled_Enabled_always_recommended_DC_Only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.3.6_L1_Ensure_NetBT_NodeType_configuration_is_set_to_Enabled_P-node_recommended" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.3.7_L1_Ensure_WDigest_Authentication_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.1_L1_Ensure_MSS_AutoAdminLogon_Enable_Automatic_Logon_not_recommended_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.2_L1_Ensure_MSS_DisableIPSourceRouting_IPv6_IP_source_routing_protection_level_protects_against_packet_spoofing_is_set_to_Enabled_Highest_protection_source_routing_is_completely_disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.3_L1_Ensure_MSS_DisableIPSourceRouting_IP_source_routing_protection_level_protects_against_packet_spoofing_is_set_to_Enabled_Highest_protection_source_routing_is_completely_disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.4_L1_Ensure_MSS_EnableICMPRedirect_Allow_ICMP_redirects_to_override_OSPF_generated_routes_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.5_L2_Ensure_MSS_KeepAliveTime_How_often_keep-alive_packets_are_sent_in_milliseconds_is_set_to_Enabled_300000_or_5_minutes_recommended" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.6_L1_Ensure_MSS_NoNameReleaseOnDemand_Allow_the_computer_to_ignore_NetBIOS_name_release_requests_except_from_WINS_servers_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.7_L2_Ensure_MSS_PerformRouterDiscovery_Allow_IRDP_to_detect_and_configure_Default_Gateway_addresses_could_lead_to_DoS_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.8_L1_Ensure_MSS_SafeDllSearchMode_Enable_Safe_DLL_search_mode_recommended_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.9_L1_Ensure_MSS_ScreenSaverGracePeriod_The_time_in_seconds_before_the_screen_saver_grace_period_expires_0_recommended_is_set_to_Enabled_5_or_fewer_seconds" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.10_L2_Ensure_MSS_TcpMaxDataRetransmissions_IPv6_How_many_times_unacknowledged_data_is_retransmitted_is_set_to_Enabled_3" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.11_L2_Ensure_MSS_TcpMaxDataRetransmissions_How_many_times_unacknowledged_data_is_retransmitted_is_set_to_Enabled_3" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.12_L1_Ensure_MSS_WarningLevel_Percentage_threshold_for_the_security_event_log_at_which_the_system_will_generate_a_warning_is_set_to_Enabled_90_or_less" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.4.1_L1_Ensure_Turn_off_multicast_name_resolution_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.5.1_L2_Ensure_Enable_Font_Providers_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.8.1_L1_Ensure_Enable_insecure_guest_logons_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.9.1_L2_Ensure_Turn_on_Mapper_IO_LLTDIO_driver_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.9.2_L2_Ensure_Turn_on_Responder_RSPNDR_driver_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.10.2_L2_Ensure_Turn_off_Microsoft_Peer-to-Peer_Networking_Services_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.11.2_L1_Ensure_Prohibit_installation_and_configuration_of_Network_Bridge_on_your_DNS_domain_network_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.11.3_L1_Ensure_Prohibit_use_of_Internet_Connection_Sharing_on_your_DNS_domain_network_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.11.4_L1_Ensure_Require_domain_users_to_elevate_when_setting_a_networks_location_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.14.1_L1_Ensure_Hardened_UNC_Paths_is_set_to_Enabled_with_Require_Mutual_Authentication_and_Require_Integrity_set_for_all_NETLOGON_and_SYSVOL_shares" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.19.2.1_L2_Disable_IPv6_Ensure_TCPIP6_Parameter_DisabledComponents_is_set_to_0xff_255" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.20.1_L2_Ensure_Configuration_of_wireless_settings_using_Windows_Connect_Now_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.20.2_L2_Ensure_Prohibit_access_of_the_Windows_Connect_Now_wizards_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.21.1_L1_Ensure_Minimize_the_number_of_simultaneous_connections_to_the_Internet_or_a_Windows_Domain_is_set_to_Enabled_3__Prevent_Wi-Fi_when_on_Ethernet" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.7.1.1_L2_Ensure_Turn_off_notifications_network_usage_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.3.1_L1_Ensure_Include_command_line_in_process_creation_events_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.4.1_L1_Ensure_Encryption_Oracle_Remediation_is_set_to_Enabled_Force_Updated_Clients" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.4.2_L1_Ensure_Remote_host_allows_delegation_of_non-exportable_credentials_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.14.1_L1_Ensure_Boot-Start_Driver_Initialization_Policy_is_set_to_Enabled_Good_unknown_and_bad_but_critical" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.21.2_L1_Ensure_Configure_registry_policy_processing_Do_not_apply_during_periodic_background_processing_is_set_to_Enabled_FALSE" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.21.3_L1_Ensure_Configure_registry_policy_processing_Process_even_if_the_Group_Policy_objects_have_not_changed_is_set_to_Enabled_TRUE" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.21.4_L1_Ensure_Continue_experiences_on_this_device_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.21.5_L1_Ensure_Turn_off_background_refresh_of_Group_Policy_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.22.1.1_L1_Ensure_Turn_off_downloading_of_print_drivers_over_HTTP_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.22.1.2_L2_Ensure_Turn_off_handwriting_personalization_data_sharing_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.22.1.3_L2_Ensure_Turn_off_handwriting_recognition_error_reporting_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.22.1.4_L2_Ensure_Turn_off_Internet_Connection_Wizard_if_URL_connection_is_referring_to_Microsoft.com_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.22.1.5_L1_Ensure_Turn_off_Internet_download_for_Web_publishing_and_online_ordering_wizards_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.22.1.6_L2_Ensure_Turn_off_printing_over_HTTP_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.22.1.7_L2_Ensure_Turn_off_Registration_if_URL_connection_is_referring_to_Microsoft.com_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.22.1.8_L2_Ensure_Turn_off_Search_Companion_content_file_updates_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.22.1.9_L2_Ensure_Turn_off_the_Order_Prints_picture_task_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.22.1.10_L2_Ensure_Turn_off_the_Publish_to_Web_task_for_files_and_folders_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.22.1.11_L2_Ensure_Turn_off_the_Windows_Messenger_Customer_Experience_Improvement_Program_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.22.1.12_L2_Ensure_Turn_off_Windows_Customer_Experience_Improvement_Program_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.22.1.13_L2_Ensure_Turn_off_Windows_Error_Reporting_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.25.1_L2_Ensure_Support_device_authentication_using_certificate_is_set_to_Enabled_Automatic" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.26.1_L1_Ensure_Enumeration_policy_for_external_devices_incompatible_with_Kernel_DMA_Protection_is_set_to_Enabled_Block_All" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.27.1_L2_Ensure_Disallow_copying_of_user_input_methods_to_the_system_account_for_sign-in_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.28.1_L1_Ensure_Block_user_from_showing_account_details_on_sign-in_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.28.2_L1_Ensure_Do_not_display_network_selection_UI_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.28.3_L1_Ensure_Do_not_enumerate_connected_users_on_domain-joined_computers_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.28.5_L1_Ensure_Turn_off_app_notifications_on_the_lock_screen_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.28.6_L1_Ensure_Turn_off_picture_password_sign-in_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.28.7_L1_Ensure_Turn_on_convenience_PIN_sign-in_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.31.1_L2_Ensure_Allow_Clipboard_synchronization_across_devices_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.31.2_L2_Ensure_Allow_upload_of_User_Activities_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.34.6.1_L2_Ensure_Allow_network_connectivity_during_connected-standby_on_battery_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.34.6.2_L2_Ensure_Allow_network_connectivity_during_connected-standby_plugged_in_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.34.6.3_L1_Ensure_Require_a_password_when_a_computer_wakes_on_battery_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.34.6.4_L1_Ensure_Require_a_password_when_a_computer_wakes_plugged_in_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.36.1_L1_Ensure_Configure_Offer_Remote_Assistance_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.36.2_L1_Ensure_Configure_Solicited_Remote_Assistance_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.47.5.1_L2_Ensure_Microsoft_Support_Diagnostic_Tool_Turn_on_MSDT_interactive_communication_with_support_provider_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.47.11.1_L2_Ensure_EnableDisable_PerfTrack_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.49.1_L2_Ensure_Turn_off_the_advertising_ID_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.52.1.1_L2_Ensure_Enable_Windows_NTP_Client_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.4.1_L2_Ensure_Allow_a_Windows_app_to_share_application_data_between_users_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.6.1_L1_Ensure_Allow_Microsoft_accounts_to_be_optional_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.8.1_L1_Ensure_Disallow_Autoplay_for_non-volume_devices_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.8.2_L1_Ensure_Set_the_default_behavior_for_AutoRun_is_set_to_Enabled_Do_not_execute_any_autorun_commands" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.8.3_L1_Ensure_Turn_off_Autoplay_is_set_to_Enabled_All_drives" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.10.1.1_L1_Ensure_Configure_enhanced_anti-spoofing_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.12.1_L2_Ensure_Allow_Use_of_Camera_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.13.1_L1_Ensure_Turn_off_Microsoft_consumer_experiences_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.14.1_L1_Ensure_Require_pin_for_pairing_is_set_to_Enabled_First_Time_OR_Enabled_Always" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.15.1_L1_Ensure_Do_not_display_the_password_reveal_button_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.15.2_L1_Ensure_Enumerate_administrator_accounts_on_elevation_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.16.1_L1_Ensure_Allow_Telemetry_is_set_to_Enabled_0_-_Security_Enterprise_Only_or_Enabled_1_-_Basic" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.16.2_L2_Ensure_Configure_Authenticated_Proxy_usage_for_the_Connected_User_Experience_and_Telemetry_service_is_set_to_Enabled_Disable_Authenticated_Proxy_usage" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.16.3_L1_Ensure_Do_not_show_feedback_notifications_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.16.4_L1_Ensure_Toggle_user_control_over_Insider_builds_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.26.1.1_L1_Ensure_Application_Control_Event_Log_behavior_when_the_log_file_reaches_its_maximum_size_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.26.1.2_L1_Ensure_Application_Specify_the_maximum_log_file_size_KB_is_set_to_Enabled_32768_or_greater" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.26.2.1_L1_Ensure_Security_Control_Event_Log_behavior_when_the_log_file_reaches_its_maximum_size_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.26.2.2_L1_Ensure_Security_Specify_the_maximum_log_file_size_KB_is_set_to_Enabled_196608_or_greater" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.26.3.1_L1_Ensure_Setup_Control_Event_Log_behavior_when_the_log_file_reaches_its_maximum_size_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.26.3.2_L1_Ensure_Setup_Specify_the_maximum_log_file_size_KB_is_set_to_Enabled_32768_or_greater" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.26.4.1_L1_Ensure_System_Control_Event_Log_behavior_when_the_log_file_reaches_its_maximum_size_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.26.4.2_L1_Ensure_System_Specify_the_maximum_log_file_size_KB_is_set_to_Enabled_32768_or_greater" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.30.2_L1_Ensure_Turn_off_Data_Execution_Prevention_for_Explorer_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.30.3_L1_Ensure_Turn_off_heap_termination_on_corruption_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.30.4_L1_Ensure_Turn_off_shell_protocol_protected_mode_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.39.2_L2_Ensure_Turn_off_location_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.43.1_L2_Ensure_Allow_Message_Service_Cloud_Sync_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.44.1_L1_Ensure_Block_all_consumer_Microsoft_account_user_authentication_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.52.1_L1_Ensure_Prevent_the_usage_of_OneDrive_for_file_storage_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.2.2_L1_Ensure_Do_not_allow_passwords_to_be_saved_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.2.1_L2_Ensure_Restrict_Remote_Desktop_Services_users_to_a_single_Remote_Desktop_Services_session_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.3.1_L2_Ensure_Do_not_allow_COM_port_redirection_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.3.2_L1_Ensure_Do_not_allow_drive_redirection_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.3.3_L2_Ensure_Do_not_allow_LPT_port_redirection_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.3.4_L2_Ensure_Do_not_allow_supported_Plug_and_Play_device_redirection_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.9.1_L1_Ensure_Always_prompt_for_password_upon_connection_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.9.2_L1_Ensure_Require_secure_RPC_communication_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.9.3_L1_Ensure_Require_use_of_specific_security_layer_for_remote_RDP_connections_is_set_to_Enabled_SSL" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.9.4_L1_Ensure_Require_user_authentication_for_remote_connections_by_using_Network_Level_Authentication_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.9.5_L1_Ensure_Set_client_connection_encryption_level_is_set_to_Enabled_High_Level" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.10.1_L2_Ensure_Set_time_limit_for_active_but_idle_Remote_Desktop_Services_sessions_is_set_to_Enabled_15_minutes_or_less" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.10.2_L2_Ensure_Set_time_limit_for_disconnected_sessions_is_set_to_Enabled_1_minute" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.11.1_L1_Ensure_Do_not_delete_temp_folders_upon_exit_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.11.2_L1_Ensure_Do_not_use_temporary_folders_per_session_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.60.1_L1_Ensure_Prevent_downloading_of_enclosures_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.61.2_L2_Ensure_Allow_Cloud_Search_is_set_to_Enabled_Disable_Cloud_Search" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.61.3_L1_Ensure_Allow_indexing_of_encrypted_files_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.66.1_L2_Ensure_Turn_off_KMS_Client_Online_AVS_Validation_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.3.1_L1_Ensure_Configure_local_setting_override_for_reporting_to_Microsoft_MAPS_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.3.2_L2_Ensure_Join_Microsoft_MAPS_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.7.1_L1_Ensure_Turn_on_behavior_monitoring_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.9.1_L2_Ensure_Configure_Watson_events_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.10.1_L1_Ensure_Scan_removable_drives_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.10.2_L1_Ensure_Turn_on_e-mail_scanning_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.13.1.1_L1_Ensure_Configure_Attack_Surface_Reduction_rules_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.13.1.2_L1_Ensure_Configure_Attack_Surface_Reduction_rules_Set_the_state_for_each_ASR_rule_is_configured" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.13.3.1_L1_Ensure_Prevent_users_and_apps_from_accessing_dangerous_websites_is_set_to_Enabled_Block" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.14_L1_Ensure_Configure_detection_for_potentially_unwanted_applications_is_set_to_Enabled_Block" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.15_L1_Ensure_Turn_off_Windows_Defender_AntiVirus_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.80.1.1_L1_Ensure_Configure_Windows_Defender_SmartScreen_is_set_to_Enabled_Warn_and_prevent_bypass" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.84.1_L2_Ensure_Allow_suggested_apps_in_Windows_Ink_Workspace_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.84.2_L1_Ensure_Allow_Windows_Ink_Workspace_is_set_to_Enabled_On_but_disallow_access_above_lock_OR_Disabled_but_not_Enabled_On" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.85.1_L1_Ensure_Allow_user_control_over_installs_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.85.2_L1_Ensure_Always_install_with_elevated_privileges_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.85.3_L2_Ensure_Prevent_Internet_Explorer_security_prompt_for_Windows_Installer_scripts_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.86.1_L1_Ensure_Sign-in_and_lock_last_interactive_user_automatically_after_a_restart_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.95.1_L1_Ensure_Turn_on_PowerShell_Script_Block_Logging_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.95.2_L1_Ensure_Turn_on_PowerShell_Transcription_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.97.1.1_L1_Ensure_Allow_Basic_authentication_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.97.1.2_L1_Ensure_Allow_unencrypted_traffic_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.97.1.3_L1_Ensure_Disallow_Digest_authentication_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.97.2.1_L1_Ensure_Allow_Basic_authentication_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.97.2.2_L2_Ensure_Allow_remote_server_management_through_WinRM_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.97.2.3_L1_Ensure_Allow_unencrypted_traffic_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.97.2.4_L1_Ensure_Disallow_WinRM_from_storing_RunAs_credentials_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.98.1_L2_Ensure_Allow_Remote_Shell_Access_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.99.2.1_L1_Ensure_Prevent_users_from_modifying_settings_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.102.1.1_L1_Ensure_Manage_preview_builds_is_set_to_Enabled_Disable_preview_builds" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.102.1.2_L1_Ensure_Select_when_Preview_Builds_and_Feature_Updates_are_received_is_set_to_Enabled_Semi-Annual_Channel_180_or_more_days" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.102.1.3_L1_Ensure_Select_when_Quality_Updates_are_received_is_set_to_Enabled_0_days" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.102.2_L1_Ensure_Configure_Automatic_Updates_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.102.3_L1_Ensure_Configure_Automatic_Updates_Scheduled_install_day_is_set_to_0_-_Every_day" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.102.4_L1_Ensure_No_auto-restart_with_logged_on_users_for_scheduled_automatic_updates_installations_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.1.3.1_L1_Ensure_Enable_screen_saver_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.1.3.2_L1_Ensure_Force_specific_screen_saver_Screen_saver_executable_name_is_set_to_Enabled_scrnsave.scr" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.1.3.3_L1_Ensure_Password_protect_the_screen_saver_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.1.3.4_L1_Ensure_Screen_saver_timeout_is_set_to_Enabled_900_seconds_or_fewer_but_not_0" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.5.1.1_L1_Ensure_Turn_off_toast_notifications_on_the_lock_screen_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.6.6.1.1_L2_Ensure_Turn_off_Help_Experience_Improvement_Program_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.7.4.1_L1_Ensure_Do_not_preserve_zone_information_in_file_attachments_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.7.4.2_L1_Ensure_Notify_antivirus_programs_when_opening_attachments_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.7.7.1_L1_Ensure_Configure_Windows_spotlight_on_lock_screen_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.7.7.2_L1_Ensure_Do_not_suggest_third-party_content_in_Windows_spotlight_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.7.7.3_L2_Ensure_Do_not_use_diagnostic_data_for_tailored_experiences_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.7.7.4_L2_Ensure_Turn_off_all_Windows_spotlight_features_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.7.26.1_L1_Ensure_Prevent_users_from_sharing_files_within_their_profile._is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.7.41.1_L1_Ensure_Always_install_with_elevated_privileges_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.7.45.2.1_L2_Ensure_Prevent_Codec_Download_is_set_to_Enabled" selected="true"/> </xccdf:Profile> |
Level 2 - Member Server |
This profile extends the "Level 1 - Member Server" profile. Items in this profile exhibit one or more of the following characteristics:
Show
Profile XML
<xccdf:Profile xmlns="http://checklists.nist.gov/xccdf/1.2" xmlns:ae="http://benchmarks.cisecurity.org/ae/0.5" xmlns:cc6="http://cisecurity.org/20-cc/v6.1" xmlns:cc7="http://cisecurity.org/20-cc/v7.0" xmlns:ciscf="https://benchmarks.cisecurity.org/ciscf/1.0" xmlns:notes="http://benchmarks.cisecurity.org/notes" xmlns:xccdf="http://checklists.nist.gov/xccdf/1.2" xmlns:xhtml="http://www.w3.org/1999/xhtml" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" id="xccdf_org.cisecurity.benchmarks_profile_Level_2_-_Member_Server"> <xccdf:title xml:lang="en">Level 2 - Member Server</xccdf:title> <xccdf:description xml:lang="en"> <xhtml:p>This profile extends the "Level 1 - Member Server" profile. Items in this profile exhibit one or more of the following characteristics:</xhtml:p> <xhtml:ul> <xhtml:li>are intended for environments or use cases where security is paramount</xhtml:li> <xhtml:li>acts as defense in depth measure</xhtml:li> <xhtml:li>may negatively inhibit the utility or performance of the technology</xhtml:li> </xhtml:ul> </xccdf:description> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.1.1_L1_Ensure_Enforce_password_history_is_set_to_24_or_more_passwords" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.1.2_L1_Ensure_Maximum_password_age_is_set_to_60_or_fewer_days_but_not_0" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.1.3_L1_Ensure_Minimum_password_age_is_set_to_1_or_more_days" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.1.4_L1_Ensure_Minimum_password_length_is_set_to_14_or_more_characters" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.1.5_L1_Ensure_Password_must_meet_complexity_requirements_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.1.6_L1_Ensure_Store_passwords_using_reversible_encryption_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.2.1_L1_Ensure_Account_lockout_duration_is_set_to_15_or_more_minutes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.2.2_L1_Ensure_Account_lockout_threshold_is_set_to_10_or_fewer_invalid_logon_attempts_but_not_0" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_1.2.3_L1_Ensure_Reset_account_lockout_counter_after_is_set_to_15_or_more_minutes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.1_L1_Ensure_Access_Credential_Manager_as_a_trusted_caller_is_set_to_No_One" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.3_L1_Ensure_Access_this_computer_from_the_network__is_set_to_Administrators_Authenticated_Users_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.4_L1_Ensure_Act_as_part_of_the_operating_system_is_set_to_No_One" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.6_L1_Ensure_Adjust_memory_quotas_for_a_process_is_set_to_Administrators_LOCAL_SERVICE_NETWORK_SERVICE" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.7_L1_Ensure_Allow_log_on_locally_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.9_L1_Ensure_Allow_log_on_through_Remote_Desktop_Services_is_set_to_Administrators_Remote_Desktop_Users_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.10_L1_Ensure_Back_up_files_and_directories_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.11_L1_Ensure_Change_the_system_time_is_set_to_Administrators_LOCAL_SERVICE" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.12_L1_Ensure_Change_the_time_zone_is_set_to_Administrators_LOCAL_SERVICE" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.13_L1_Ensure_Create_a_pagefile_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.14_L1_Ensure_Create_a_token_object_is_set_to_No_One" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.15_L1_Ensure_Create_global_objects_is_set_to_Administrators_LOCAL_SERVICE_NETWORK_SERVICE_SERVICE" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.16_L1_Ensure_Create_permanent_shared_objects_is_set_to_No_One" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.18_L1_Ensure_Create_symbolic_links_is_set_to_Administrators_NT_VIRTUAL_MACHINEVirtual_Machines_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.19_L1_Ensure_Debug_programs_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.21_L1_Ensure_Deny_access_to_this_computer_from_the_network_to_include_Guests_Local_account_and_member_of_Administrators_group_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.22_L1_Ensure_Deny_log_on_as_a_batch_job_to_include_Guests" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.23_L1_Ensure_Deny_log_on_as_a_service_to_include_Guests" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.24_L1_Ensure_Deny_log_on_locally_to_include_Guests" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.26_L1_Ensure_Deny_log_on_through_Remote_Desktop_Services_is_set_to_Guests_Local_account_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.28_L1_Ensure_Enable_computer_and_user_accounts_to_be_trusted_for_delegation_is_set_to_No_One_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.29_L1_Ensure_Force_shutdown_from_a_remote_system_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.30_L1_Ensure_Generate_security_audits_is_set_to_LOCAL_SERVICE_NETWORK_SERVICE" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.32_L1_Ensure_Impersonate_a_client_after_authentication_is_set_to_Administrators_LOCAL_SERVICE_NETWORK_SERVICE_SERVICE_and_when_the_Web_Server_IIS_Role_with_Web_Services_Role_Service_is_installed_IIS_IUSRS_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.33_L1_Ensure_Increase_scheduling_priority_is_set_to_Administrators_Window_ManagerWindow_Manager_Group" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.34_L1_Ensure_Load_and_unload_device_drivers_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.35_L1_Ensure_Lock_pages_in_memory_is_set_to_No_One" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.38_L1_Ensure_Manage_auditing_and_security_log_is_set_to_Administrators_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.39_L1_Ensure_Modify_an_object_label_is_set_to_No_One" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.40_L1_Ensure_Modify_firmware_environment_values_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.41_L1_Ensure_Perform_volume_maintenance_tasks_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.42_L1_Ensure_Profile_single_process_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.43_L1_Ensure_Profile_system_performance_is_set_to_Administrators_NT_SERVICEWdiServiceHost" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.44_L1_Ensure_Replace_a_process_level_token_is_set_to_LOCAL_SERVICE_NETWORK_SERVICE" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.45_L1_Ensure_Restore_files_and_directories_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.46_L1_Ensure_Shut_down_the_system_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.2.48_L1_Ensure_Take_ownership_of_files_or_other_objects_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.1.1_L1_Ensure_Accounts_Administrator_account_status_is_set_to_Disabled_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.1.2_L1_Ensure_Accounts_Block_Microsoft_accounts_is_set_to_Users_cant_add_or_log_on_with_Microsoft_accounts" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.1.3_L1_Ensure_Accounts_Guest_account_status_is_set_to_Disabled_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.1.4_L1_Ensure_Accounts_Limit_local_account_use_of_blank_passwords_to_console_logon_only_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.1.5_L1_Configure_Accounts_Rename_administrator_account" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.1.6_L1_Configure_Accounts_Rename_guest_account" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.2.1_L1_Ensure_Audit_Force_audit_policy_subcategory_settings_Windows_Vista_or_later_to_override_audit_policy_category_settings_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.2.2_L1_Ensure_Audit_Shut_down_system_immediately_if_unable_to_log_security_audits_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.4.1_L1_Ensure_Devices_Allowed_to_format_and_eject_removable_media_is_set_to_Administrators" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.4.2_L1_Ensure_Devices_Prevent_users_from_installing_printer_drivers_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.6.1_L1_Ensure_Domain_member_Digitally_encrypt_or_sign_secure_channel_data_always_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.6.2_L1_Ensure_Domain_member_Digitally_encrypt_secure_channel_data_when_possible_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.6.3_L1_Ensure_Domain_member_Digitally_sign_secure_channel_data_when_possible_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.6.4_L1_Ensure_Domain_member_Disable_machine_account_password_changes_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.6.5_L1_Ensure_Domain_member_Maximum_machine_account_password_age_is_set_to_30_or_fewer_days_but_not_0" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.6.6_L1_Ensure_Domain_member_Require_strong_Windows_2000_or_later_session_key_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.7.1_L1_Ensure_Interactive_logon_Do_not_require_CTRLALTDEL_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.7.2_L1_Ensure_Interactive_logon_Dont_display_last_signed-in_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.7.3_L1_Ensure_Interactive_logon_Machine_inactivity_limit_is_set_to_900_or_fewer_seconds_but_not_0" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.7.4_L1_Configure_Interactive_logon_Message_text_for_users_attempting_to_log_on" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.7.5_L1_Configure_Interactive_logon_Message_title_for_users_attempting_to_log_on" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.7.6_L2_Ensure_Interactive_logon_Number_of_previous_logons_to_cache_in_case_domain_controller_is_not_available_is_set_to_4_or_fewer_logons_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.7.7_L1_Ensure_Interactive_logon_Prompt_user_to_change_password_before_expiration_is_set_to_between_5_and_14_days" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.7.8_L1_Ensure_Interactive_logon_Require_Domain_Controller_Authentication_to_unlock_workstation_is_set_to_Enabled_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.7.9_L1_Ensure_Interactive_logon_Smart_card_removal_behavior_is_set_to_Lock_Workstation_or_higher" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.8.1_L1_Ensure_Microsoft_network_client_Digitally_sign_communications_always_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.8.2_L1_Ensure_Microsoft_network_client_Digitally_sign_communications_if_server_agrees_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.8.3_L1_Ensure_Microsoft_network_client_Send_unencrypted_password_to_third-party_SMB_servers_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.9.1_L1_Ensure_Microsoft_network_server_Amount_of_idle_time_required_before_suspending_session_is_set_to_15_or_fewer_minutes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.9.2_L1_Ensure_Microsoft_network_server_Digitally_sign_communications_always_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.9.3_L1_Ensure_Microsoft_network_server_Digitally_sign_communications_if_client_agrees_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.9.4_L1_Ensure_Microsoft_network_server_Disconnect_clients_when_logon_hours_expire_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.9.5_L1_Ensure_Microsoft_network_server_Server_SPN_target_name_validation_level_is_set_to_Accept_if_provided_by_client_or_higher_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.1_L1_Ensure_Network_access_Allow_anonymous_SIDName_translation_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.2_L1_Ensure_Network_access_Do_not_allow_anonymous_enumeration_of_SAM_accounts_is_set_to_Enabled_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.3_L1_Ensure_Network_access_Do_not_allow_anonymous_enumeration_of_SAM_accounts_and_shares_is_set_to_Enabled_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.4_L2_Ensure_Network_access_Do_not_allow_storage_of_passwords_and_credentials_for_network_authentication_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.5_L1_Ensure_Network_access_Let_Everyone_permissions_apply_to_anonymous_users_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.7_L1_Configure_Network_access_Named_Pipes_that_can_be_accessed_anonymously_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.8_L1_Configure_Network_access_Remotely_accessible_registry_paths" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.9_L1_Configure_Network_access_Remotely_accessible_registry_paths_and_sub-paths" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.10_L1_Ensure_Network_access_Restrict_anonymous_access_to_Named_Pipes_and_Shares_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.11_L1_Ensure_Network_access_Restrict_clients_allowed_to_make_remote_calls_to_SAM_is_set_to_Administrators_Remote_Access_Allow_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.12_L1_Ensure_Network_access_Shares_that_can_be_accessed_anonymously_is_set_to_None" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.10.13_L1_Ensure_Network_access_Sharing_and_security_model_for_local_accounts_is_set_to_Classic_-_local_users_authenticate_as_themselves" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.1_L1_Ensure_Network_security_Allow_Local_System_to_use_computer_identity_for_NTLM_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.2_L1_Ensure_Network_security_Allow_LocalSystem_NULL_session_fallback_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.3_L1_Ensure_Network_Security_Allow_PKU2U_authentication_requests_to_this_computer_to_use_online_identities_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.4_L1_Ensure_Network_security_Configure_encryption_types_allowed_for_Kerberos_is_set_to_AES128_HMAC_SHA1_AES256_HMAC_SHA1_Future_encryption_types" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.5_L1_Ensure_Network_security_Do_not_store_LAN_Manager_hash_value_on_next_password_change_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.6_L1_Ensure_Network_security_Force_logoff_when_logon_hours_expire_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.7_L1_Ensure_Network_security_LAN_Manager_authentication_level_is_set_to_Send_NTLMv2_response_only._Refuse_LM__NTLM" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.8_L1_Ensure_Network_security_LDAP_client_signing_requirements_is_set_to_Negotiate_signing_or_higher" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.9_L1_Ensure_Network_security_Minimum_session_security_for_NTLM_SSP_based_including_secure_RPC_clients_is_set_to_Require_NTLMv2_session_security_Require_128-bit_encryption" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.11.10_L1_Ensure_Network_security_Minimum_session_security_for_NTLM_SSP_based_including_secure_RPC_servers_is_set_to_Require_NTLMv2_session_security_Require_128-bit_encryption" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.13.1_L1_Ensure_Shutdown_Allow_system_to_be_shut_down_without_having_to_log_on_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.15.1_L1_Ensure_System_objects_Require_case_insensitivity_for_non-Windows_subsystems_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.15.2_L1_Ensure_System_objects_Strengthen_default_permissions_of_internal_system_objects_e.g._Symbolic_Links_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.17.1_L1_Ensure_User_Account_Control_Admin_Approval_Mode_for_the_Built-in_Administrator_account_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.17.2_L1_Ensure_User_Account_Control_Behavior_of_the_elevation_prompt_for_administrators_in_Admin_Approval_Mode_is_set_to_Prompt_for_consent_on_the_secure_desktop" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.17.3_L1_Ensure_User_Account_Control_Behavior_of_the_elevation_prompt_for_standard_users_is_set_to_Automatically_deny_elevation_requests" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.17.4_L1_Ensure_User_Account_Control_Detect_application_installations_and_prompt_for_elevation_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.17.5_L1_Ensure_User_Account_Control_Only_elevate_UIAccess_applications_that_are_installed_in_secure_locations_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.17.6_L1_Ensure_User_Account_Control_Run_all_administrators_in_Admin_Approval_Mode_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.17.7_L1_Ensure_User_Account_Control_Switch_to_the_secure_desktop_when_prompting_for_elevation_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_2.3.17.8_L1_Ensure_User_Account_Control_Virtualize_file_and_registry_write_failures_to_per-user_locations_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.1.1_L1_Ensure_Windows_Firewall_Domain_Firewall_state_is_set_to_On_recommended" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.1.2_L1_Ensure_Windows_Firewall_Domain_Inbound_connections_is_set_to_Block_default" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.1.3_L1_Ensure_Windows_Firewall_Domain_Outbound_connections_is_set_to_Allow_default" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.1.4_L1_Ensure_Windows_Firewall_Domain_Settings_Display_a_notification_is_set_to_No" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.1.5_L1_Ensure_Windows_Firewall_Domain_Logging_Name_is_set_to_SystemRootSystem32logfilesfirewalldomainfw.log" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.1.6_L1_Ensure_Windows_Firewall_Domain_Logging_Size_limit_KB_is_set_to_16384_KB_or_greater" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.1.7_L1_Ensure_Windows_Firewall_Domain_Logging_Log_dropped_packets_is_set_to_Yes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.1.8_L1_Ensure_Windows_Firewall_Domain_Logging_Log_successful_connections_is_set_to_Yes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.2.1_L1_Ensure_Windows_Firewall_Private_Firewall_state_is_set_to_On_recommended" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.2.2_L1_Ensure_Windows_Firewall_Private_Inbound_connections_is_set_to_Block_default" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.2.3_L1_Ensure_Windows_Firewall_Private_Outbound_connections_is_set_to_Allow_default" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.2.4_L1_Ensure_Windows_Firewall_Private_Settings_Display_a_notification_is_set_to_No" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.2.5_L1_Ensure_Windows_Firewall_Private_Logging_Name_is_set_to_SystemRootSystem32logfilesfirewallprivatefw.log" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.2.6_L1_Ensure_Windows_Firewall_Private_Logging_Size_limit_KB_is_set_to_16384_KB_or_greater" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.2.7_L1_Ensure_Windows_Firewall_Private_Logging_Log_dropped_packets_is_set_to_Yes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.2.8_L1_Ensure_Windows_Firewall_Private_Logging_Log_successful_connections_is_set_to_Yes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.1_L1_Ensure_Windows_Firewall_Public_Firewall_state_is_set_to_On_recommended" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.2_L1_Ensure_Windows_Firewall_Public_Inbound_connections_is_set_to_Block_default" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.3_L1_Ensure_Windows_Firewall_Public_Outbound_connections_is_set_to_Allow_default" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.4_L1_Ensure_Windows_Firewall_Public_Settings_Display_a_notification_is_set_to_No" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.5_L1_Ensure_Windows_Firewall_Public_Settings_Apply_local_firewall_rules_is_set_to_No" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.6_L1_Ensure_Windows_Firewall_Public_Settings_Apply_local_connection_security_rules_is_set_to_No" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.7_L1_Ensure_Windows_Firewall_Public_Logging_Name_is_set_to_SystemRootSystem32logfilesfirewallpublicfw.log" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.8_L1_Ensure_Windows_Firewall_Public_Logging_Size_limit_KB_is_set_to_16384_KB_or_greater" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.9_L1_Ensure_Windows_Firewall_Public_Logging_Log_dropped_packets_is_set_to_Yes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_9.3.10_L1_Ensure_Windows_Firewall_Public_Logging_Log_successful_connections_is_set_to_Yes" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.1.1_L1_Ensure_Audit_Credential_Validation_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.2.1_L1_Ensure_Audit_Application_Group_Management_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.2.5_L1_Ensure_Audit_Security_Group_Management_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.2.6_L1_Ensure_Audit_User_Account_Management_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.3.1_L1_Ensure_Audit_PNP_Activity_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.3.2_L1_Ensure_Audit_Process_Creation_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.5.1_L1_Ensure_Audit_Account_Lockout_is_set_to_include_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.5.2_L1_Ensure_Audit_Group_Membership_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.5.3_L1_Ensure_Audit_Logoff_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.5.4_L1_Ensure_Audit_Logon_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.5.5_L1_Ensure_Audit_Other_LogonLogoff_Events_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.5.6_L1_Ensure_Audit_Special_Logon_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.6.1_L1_Ensure_Audit_Detailed_File_Share_is_set_to_include_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.6.2_L1_Ensure_Audit_File_Share_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.6.3_L1_Ensure_Audit_Other_Object_Access_Events_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.6.4_L1_Ensure_Audit_Removable_Storage_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.7.1_L1_Ensure_Audit_Audit_Policy_Change_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.7.2_L1_Ensure_Audit_Authentication_Policy_Change_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.7.3_L1_Ensure_Audit_Authorization_Policy_Change_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.7.4_L1_Ensure_Audit_MPSSVC_Rule-Level_Policy_Change_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.7.5_L1_Ensure_Audit_Other_Policy_Change_Events_is_set_to_include_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.8.1_L1_Ensure_Audit_Sensitive_Privilege_Use_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.9.1_L1_Ensure_Audit_IPsec_Driver_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.9.2_L1_Ensure_Audit_Other_System_Events_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.9.3_L1_Ensure_Audit_Security_State_Change_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.9.4_L1_Ensure_Audit_Security_System_Extension_is_set_to_include_Success" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_17.9.5_L1_Ensure_Audit_System_Integrity_is_set_to_Success_and_Failure" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.1.1.1_L1_Ensure_Prevent_enabling_lock_screen_camera_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.1.1.2_L1_Ensure_Prevent_enabling_lock_screen_slide_show_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.1.2.2_L1_Ensure_Allow_users_to_enable_online_speech_recognition_services_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.1.3_L2_Ensure_Allow_Online_Tips_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.2.1_L1_Ensure_LAPS_AdmPwd_GPO_Extension__CSE_is_installed_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.2.2_L1_Ensure_Do_not_allow_password_expiration_time_longer_than_required_by_policy_is_set_to_Enabled_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.2.3_L1_Ensure_Enable_Local_Admin_Password_Management_is_set_to_Enabled_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.2.4_L1_Ensure_Password_Settings_Password_Complexity_is_set_to_Enabled_Large_letters__small_letters__numbers__special_characters_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.2.5_L1_Ensure_Password_Settings_Password_Length_is_set_to_Enabled_15_or_more_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.2.6_L1_Ensure_Password_Settings_Password_Age_Days_is_set_to_Enabled_30_or_fewer_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.3.1_L1_Ensure_Apply_UAC_restrictions_to_local_accounts_on_network_logons_is_set_to_Enabled_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.3.2_L1_Ensure_Configure_SMB_v1_client_driver_is_set_to_Enabled_Disable_driver_recommended" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.3.3_L1_Ensure_Configure_SMB_v1_server_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.3.4_L1_Ensure_Enable_Structured_Exception_Handling_Overwrite_Protection_SEHOP_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.3.6_L1_Ensure_NetBT_NodeType_configuration_is_set_to_Enabled_P-node_recommended" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.3.7_L1_Ensure_WDigest_Authentication_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.1_L1_Ensure_MSS_AutoAdminLogon_Enable_Automatic_Logon_not_recommended_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.2_L1_Ensure_MSS_DisableIPSourceRouting_IPv6_IP_source_routing_protection_level_protects_against_packet_spoofing_is_set_to_Enabled_Highest_protection_source_routing_is_completely_disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.3_L1_Ensure_MSS_DisableIPSourceRouting_IP_source_routing_protection_level_protects_against_packet_spoofing_is_set_to_Enabled_Highest_protection_source_routing_is_completely_disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.4_L1_Ensure_MSS_EnableICMPRedirect_Allow_ICMP_redirects_to_override_OSPF_generated_routes_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.5_L2_Ensure_MSS_KeepAliveTime_How_often_keep-alive_packets_are_sent_in_milliseconds_is_set_to_Enabled_300000_or_5_minutes_recommended" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.6_L1_Ensure_MSS_NoNameReleaseOnDemand_Allow_the_computer_to_ignore_NetBIOS_name_release_requests_except_from_WINS_servers_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.7_L2_Ensure_MSS_PerformRouterDiscovery_Allow_IRDP_to_detect_and_configure_Default_Gateway_addresses_could_lead_to_DoS_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.8_L1_Ensure_MSS_SafeDllSearchMode_Enable_Safe_DLL_search_mode_recommended_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.9_L1_Ensure_MSS_ScreenSaverGracePeriod_The_time_in_seconds_before_the_screen_saver_grace_period_expires_0_recommended_is_set_to_Enabled_5_or_fewer_seconds" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.10_L2_Ensure_MSS_TcpMaxDataRetransmissions_IPv6_How_many_times_unacknowledged_data_is_retransmitted_is_set_to_Enabled_3" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.11_L2_Ensure_MSS_TcpMaxDataRetransmissions_How_many_times_unacknowledged_data_is_retransmitted_is_set_to_Enabled_3" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.4.12_L1_Ensure_MSS_WarningLevel_Percentage_threshold_for_the_security_event_log_at_which_the_system_will_generate_a_warning_is_set_to_Enabled_90_or_less" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.4.1_L1_Ensure_Turn_off_multicast_name_resolution_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.5.1_L2_Ensure_Enable_Font_Providers_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.8.1_L1_Ensure_Enable_insecure_guest_logons_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.9.1_L2_Ensure_Turn_on_Mapper_IO_LLTDIO_driver_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.9.2_L2_Ensure_Turn_on_Responder_RSPNDR_driver_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.10.2_L2_Ensure_Turn_off_Microsoft_Peer-to-Peer_Networking_Services_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.11.2_L1_Ensure_Prohibit_installation_and_configuration_of_Network_Bridge_on_your_DNS_domain_network_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.11.3_L1_Ensure_Prohibit_use_of_Internet_Connection_Sharing_on_your_DNS_domain_network_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.11.4_L1_Ensure_Require_domain_users_to_elevate_when_setting_a_networks_location_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.14.1_L1_Ensure_Hardened_UNC_Paths_is_set_to_Enabled_with_Require_Mutual_Authentication_and_Require_Integrity_set_for_all_NETLOGON_and_SYSVOL_shares" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.19.2.1_L2_Disable_IPv6_Ensure_TCPIP6_Parameter_DisabledComponents_is_set_to_0xff_255" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.20.1_L2_Ensure_Configuration_of_wireless_settings_using_Windows_Connect_Now_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.20.2_L2_Ensure_Prohibit_access_of_the_Windows_Connect_Now_wizards_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.21.1_L1_Ensure_Minimize_the_number_of_simultaneous_connections_to_the_Internet_or_a_Windows_Domain_is_set_to_Enabled_3__Prevent_Wi-Fi_when_on_Ethernet" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.5.21.2_L2_Ensure_Prohibit_connection_to_non-domain_networks_when_connected_to_domain_authenticated_network_is_set_to_Enabled_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.7.1.1_L2_Ensure_Turn_off_notifications_network_usage_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.3.1_L1_Ensure_Include_command_line_in_process_creation_events_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.4.1_L1_Ensure_Encryption_Oracle_Remediation_is_set_to_Enabled_Force_Updated_Clients" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.4.2_L1_Ensure_Remote_host_allows_delegation_of_non-exportable_credentials_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.14.1_L1_Ensure_Boot-Start_Driver_Initialization_Policy_is_set_to_Enabled_Good_unknown_and_bad_but_critical" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.21.2_L1_Ensure_Configure_registry_policy_processing_Do_not_apply_during_periodic_background_processing_is_set_to_Enabled_FALSE" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.21.3_L1_Ensure_Configure_registry_policy_processing_Process_even_if_the_Group_Policy_objects_have_not_changed_is_set_to_Enabled_TRUE" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.21.4_L1_Ensure_Continue_experiences_on_this_device_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.21.5_L1_Ensure_Turn_off_background_refresh_of_Group_Policy_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.22.1.1_L1_Ensure_Turn_off_downloading_of_print_drivers_over_HTTP_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.22.1.2_L2_Ensure_Turn_off_handwriting_personalization_data_sharing_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.22.1.3_L2_Ensure_Turn_off_handwriting_recognition_error_reporting_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.22.1.4_L2_Ensure_Turn_off_Internet_Connection_Wizard_if_URL_connection_is_referring_to_Microsoft.com_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.22.1.5_L1_Ensure_Turn_off_Internet_download_for_Web_publishing_and_online_ordering_wizards_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.22.1.6_L2_Ensure_Turn_off_printing_over_HTTP_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.22.1.7_L2_Ensure_Turn_off_Registration_if_URL_connection_is_referring_to_Microsoft.com_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.22.1.8_L2_Ensure_Turn_off_Search_Companion_content_file_updates_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.22.1.9_L2_Ensure_Turn_off_the_Order_Prints_picture_task_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.22.1.10_L2_Ensure_Turn_off_the_Publish_to_Web_task_for_files_and_folders_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.22.1.11_L2_Ensure_Turn_off_the_Windows_Messenger_Customer_Experience_Improvement_Program_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.22.1.12_L2_Ensure_Turn_off_Windows_Customer_Experience_Improvement_Program_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.22.1.13_L2_Ensure_Turn_off_Windows_Error_Reporting_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.25.1_L2_Ensure_Support_device_authentication_using_certificate_is_set_to_Enabled_Automatic" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.26.1_L1_Ensure_Enumeration_policy_for_external_devices_incompatible_with_Kernel_DMA_Protection_is_set_to_Enabled_Block_All" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.27.1_L2_Ensure_Disallow_copying_of_user_input_methods_to_the_system_account_for_sign-in_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.28.1_L1_Ensure_Block_user_from_showing_account_details_on_sign-in_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.28.2_L1_Ensure_Do_not_display_network_selection_UI_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.28.3_L1_Ensure_Do_not_enumerate_connected_users_on_domain-joined_computers_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.28.4_L1_Ensure_Enumerate_local_users_on_domain-joined_computers_is_set_to_Disabled_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.28.5_L1_Ensure_Turn_off_app_notifications_on_the_lock_screen_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.28.6_L1_Ensure_Turn_off_picture_password_sign-in_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.28.7_L1_Ensure_Turn_on_convenience_PIN_sign-in_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.31.1_L2_Ensure_Allow_Clipboard_synchronization_across_devices_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.31.2_L2_Ensure_Allow_upload_of_User_Activities_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.34.6.1_L2_Ensure_Allow_network_connectivity_during_connected-standby_on_battery_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.34.6.2_L2_Ensure_Allow_network_connectivity_during_connected-standby_plugged_in_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.34.6.3_L1_Ensure_Require_a_password_when_a_computer_wakes_on_battery_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.34.6.4_L1_Ensure_Require_a_password_when_a_computer_wakes_plugged_in_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.36.1_L1_Ensure_Configure_Offer_Remote_Assistance_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.36.2_L1_Ensure_Configure_Solicited_Remote_Assistance_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.37.1_L1_Ensure_Enable_RPC_Endpoint_Mapper_Client_Authentication_is_set_to_Enabled_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.37.2_L2_Ensure_Restrict_Unauthenticated_RPC_clients_is_set_to_Enabled_Authenticated_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.47.5.1_L2_Ensure_Microsoft_Support_Diagnostic_Tool_Turn_on_MSDT_interactive_communication_with_support_provider_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.47.11.1_L2_Ensure_EnableDisable_PerfTrack_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.49.1_L2_Ensure_Turn_off_the_advertising_ID_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.52.1.1_L2_Ensure_Enable_Windows_NTP_Client_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.52.1.2_L2_Ensure_Enable_Windows_NTP_Server_is_set_to_Disabled_MS_only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.4.1_L2_Ensure_Allow_a_Windows_app_to_share_application_data_between_users_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.6.1_L1_Ensure_Allow_Microsoft_accounts_to_be_optional_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.8.1_L1_Ensure_Disallow_Autoplay_for_non-volume_devices_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.8.2_L1_Ensure_Set_the_default_behavior_for_AutoRun_is_set_to_Enabled_Do_not_execute_any_autorun_commands" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.8.3_L1_Ensure_Turn_off_Autoplay_is_set_to_Enabled_All_drives" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.10.1.1_L1_Ensure_Configure_enhanced_anti-spoofing_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.12.1_L2_Ensure_Allow_Use_of_Camera_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.13.1_L1_Ensure_Turn_off_Microsoft_consumer_experiences_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.14.1_L1_Ensure_Require_pin_for_pairing_is_set_to_Enabled_First_Time_OR_Enabled_Always" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.15.1_L1_Ensure_Do_not_display_the_password_reveal_button_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.15.2_L1_Ensure_Enumerate_administrator_accounts_on_elevation_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.16.1_L1_Ensure_Allow_Telemetry_is_set_to_Enabled_0_-_Security_Enterprise_Only_or_Enabled_1_-_Basic" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.16.2_L2_Ensure_Configure_Authenticated_Proxy_usage_for_the_Connected_User_Experience_and_Telemetry_service_is_set_to_Enabled_Disable_Authenticated_Proxy_usage" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.16.3_L1_Ensure_Do_not_show_feedback_notifications_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.16.4_L1_Ensure_Toggle_user_control_over_Insider_builds_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.26.1.1_L1_Ensure_Application_Control_Event_Log_behavior_when_the_log_file_reaches_its_maximum_size_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.26.1.2_L1_Ensure_Application_Specify_the_maximum_log_file_size_KB_is_set_to_Enabled_32768_or_greater" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.26.2.1_L1_Ensure_Security_Control_Event_Log_behavior_when_the_log_file_reaches_its_maximum_size_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.26.2.2_L1_Ensure_Security_Specify_the_maximum_log_file_size_KB_is_set_to_Enabled_196608_or_greater" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.26.3.1_L1_Ensure_Setup_Control_Event_Log_behavior_when_the_log_file_reaches_its_maximum_size_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.26.3.2_L1_Ensure_Setup_Specify_the_maximum_log_file_size_KB_is_set_to_Enabled_32768_or_greater" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.26.4.1_L1_Ensure_System_Control_Event_Log_behavior_when_the_log_file_reaches_its_maximum_size_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.26.4.2_L1_Ensure_System_Specify_the_maximum_log_file_size_KB_is_set_to_Enabled_32768_or_greater" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.30.2_L1_Ensure_Turn_off_Data_Execution_Prevention_for_Explorer_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.30.3_L1_Ensure_Turn_off_heap_termination_on_corruption_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.30.4_L1_Ensure_Turn_off_shell_protocol_protected_mode_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.39.2_L2_Ensure_Turn_off_location_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.43.1_L2_Ensure_Allow_Message_Service_Cloud_Sync_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.44.1_L1_Ensure_Block_all_consumer_Microsoft_account_user_authentication_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.52.1_L1_Ensure_Prevent_the_usage_of_OneDrive_for_file_storage_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.2.2_L1_Ensure_Do_not_allow_passwords_to_be_saved_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.2.1_L2_Ensure_Restrict_Remote_Desktop_Services_users_to_a_single_Remote_Desktop_Services_session_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.3.1_L2_Ensure_Do_not_allow_COM_port_redirection_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.3.2_L1_Ensure_Do_not_allow_drive_redirection_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.3.3_L2_Ensure_Do_not_allow_LPT_port_redirection_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.3.4_L2_Ensure_Do_not_allow_supported_Plug_and_Play_device_redirection_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.9.1_L1_Ensure_Always_prompt_for_password_upon_connection_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.9.2_L1_Ensure_Require_secure_RPC_communication_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.9.3_L1_Ensure_Require_use_of_specific_security_layer_for_remote_RDP_connections_is_set_to_Enabled_SSL" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.9.4_L1_Ensure_Require_user_authentication_for_remote_connections_by_using_Network_Level_Authentication_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.9.5_L1_Ensure_Set_client_connection_encryption_level_is_set_to_Enabled_High_Level" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.10.1_L2_Ensure_Set_time_limit_for_active_but_idle_Remote_Desktop_Services_sessions_is_set_to_Enabled_15_minutes_or_less" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.10.2_L2_Ensure_Set_time_limit_for_disconnected_sessions_is_set_to_Enabled_1_minute" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.11.1_L1_Ensure_Do_not_delete_temp_folders_upon_exit_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.59.3.11.2_L1_Ensure_Do_not_use_temporary_folders_per_session_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.60.1_L1_Ensure_Prevent_downloading_of_enclosures_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.61.2_L2_Ensure_Allow_Cloud_Search_is_set_to_Enabled_Disable_Cloud_Search" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.61.3_L1_Ensure_Allow_indexing_of_encrypted_files_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.66.1_L2_Ensure_Turn_off_KMS_Client_Online_AVS_Validation_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.3.1_L1_Ensure_Configure_local_setting_override_for_reporting_to_Microsoft_MAPS_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.3.2_L2_Ensure_Join_Microsoft_MAPS_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.7.1_L1_Ensure_Turn_on_behavior_monitoring_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.9.1_L2_Ensure_Configure_Watson_events_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.10.1_L1_Ensure_Scan_removable_drives_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.10.2_L1_Ensure_Turn_on_e-mail_scanning_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.13.1.1_L1_Ensure_Configure_Attack_Surface_Reduction_rules_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.13.1.2_L1_Ensure_Configure_Attack_Surface_Reduction_rules_Set_the_state_for_each_ASR_rule_is_configured" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.13.3.1_L1_Ensure_Prevent_users_and_apps_from_accessing_dangerous_websites_is_set_to_Enabled_Block" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.14_L1_Ensure_Configure_detection_for_potentially_unwanted_applications_is_set_to_Enabled_Block" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.77.15_L1_Ensure_Turn_off_Windows_Defender_AntiVirus_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.80.1.1_L1_Ensure_Configure_Windows_Defender_SmartScreen_is_set_to_Enabled_Warn_and_prevent_bypass" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.84.1_L2_Ensure_Allow_suggested_apps_in_Windows_Ink_Workspace_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.84.2_L1_Ensure_Allow_Windows_Ink_Workspace_is_set_to_Enabled_On_but_disallow_access_above_lock_OR_Disabled_but_not_Enabled_On" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.85.1_L1_Ensure_Allow_user_control_over_installs_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.85.2_L1_Ensure_Always_install_with_elevated_privileges_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.85.3_L2_Ensure_Prevent_Internet_Explorer_security_prompt_for_Windows_Installer_scripts_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.86.1_L1_Ensure_Sign-in_and_lock_last_interactive_user_automatically_after_a_restart_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.95.1_L1_Ensure_Turn_on_PowerShell_Script_Block_Logging_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.95.2_L1_Ensure_Turn_on_PowerShell_Transcription_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.97.1.1_L1_Ensure_Allow_Basic_authentication_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.97.1.2_L1_Ensure_Allow_unencrypted_traffic_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.97.1.3_L1_Ensure_Disallow_Digest_authentication_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.97.2.1_L1_Ensure_Allow_Basic_authentication_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.97.2.2_L2_Ensure_Allow_remote_server_management_through_WinRM_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.97.2.3_L1_Ensure_Allow_unencrypted_traffic_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.97.2.4_L1_Ensure_Disallow_WinRM_from_storing_RunAs_credentials_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.98.1_L2_Ensure_Allow_Remote_Shell_Access_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.99.2.1_L1_Ensure_Prevent_users_from_modifying_settings_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.102.1.1_L1_Ensure_Manage_preview_builds_is_set_to_Enabled_Disable_preview_builds" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.102.1.2_L1_Ensure_Select_when_Preview_Builds_and_Feature_Updates_are_received_is_set_to_Enabled_Semi-Annual_Channel_180_or_more_days" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.102.1.3_L1_Ensure_Select_when_Quality_Updates_are_received_is_set_to_Enabled_0_days" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.102.2_L1_Ensure_Configure_Automatic_Updates_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.102.3_L1_Ensure_Configure_Automatic_Updates_Scheduled_install_day_is_set_to_0_-_Every_day" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.9.102.4_L1_Ensure_No_auto-restart_with_logged_on_users_for_scheduled_automatic_updates_installations_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.1.3.1_L1_Ensure_Enable_screen_saver_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.1.3.2_L1_Ensure_Force_specific_screen_saver_Screen_saver_executable_name_is_set_to_Enabled_scrnsave.scr" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.1.3.3_L1_Ensure_Password_protect_the_screen_saver_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.1.3.4_L1_Ensure_Screen_saver_timeout_is_set_to_Enabled_900_seconds_or_fewer_but_not_0" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.5.1.1_L1_Ensure_Turn_off_toast_notifications_on_the_lock_screen_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.6.6.1.1_L2_Ensure_Turn_off_Help_Experience_Improvement_Program_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.7.4.1_L1_Ensure_Do_not_preserve_zone_information_in_file_attachments_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.7.4.2_L1_Ensure_Notify_antivirus_programs_when_opening_attachments_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.7.7.1_L1_Ensure_Configure_Windows_spotlight_on_lock_screen_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.7.7.2_L1_Ensure_Do_not_suggest_third-party_content_in_Windows_spotlight_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.7.7.3_L2_Ensure_Do_not_use_diagnostic_data_for_tailored_experiences_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.7.7.4_L2_Ensure_Turn_off_all_Windows_spotlight_features_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.7.26.1_L1_Ensure_Prevent_users_from_sharing_files_within_their_profile._is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.7.41.1_L1_Ensure_Always_install_with_elevated_privileges_is_set_to_Disabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_19.7.45.2.1_L2_Ensure_Prevent_Codec_Download_is_set_to_Enabled" selected="true"/> </xccdf:Profile> |
Next Generation Windows Security - Domain Controller |
This profile contains advanced Windows security features that have specific configuration dependencies, and may not be compatible with all systems. It therefore requires special attention to detail and testing before implementation. If your environment supports these features, they are highly recommended as they have tangible security benefits. This profile is intended to be an optional "add-on" to the Level 1 or Level 2 profiles.
Show
Profile XML
<xccdf:Profile xmlns="http://checklists.nist.gov/xccdf/1.2" xmlns:ae="http://benchmarks.cisecurity.org/ae/0.5" xmlns:cc6="http://cisecurity.org/20-cc/v6.1" xmlns:cc7="http://cisecurity.org/20-cc/v7.0" xmlns:ciscf="https://benchmarks.cisecurity.org/ciscf/1.0" xmlns:notes="http://benchmarks.cisecurity.org/notes" xmlns:xccdf="http://checklists.nist.gov/xccdf/1.2" xmlns:xhtml="http://www.w3.org/1999/xhtml" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" id="xccdf_org.cisecurity.benchmarks_profile_Next_Generation_Windows_Security_-_Domain_Controller"> <xccdf:title xml:lang="en">Next Generation Windows Security - Domain Controller</xccdf:title> <xccdf:description xml:lang="en"> <xhtml:p>This profile contains advanced Windows security features that have specific configuration dependencies, and may not be compatible with all systems. It therefore requires special attention to detail and testing before implementation. If your environment supports these features, they are highly recommended as they have tangible security benefits. This profile is intended to be an optional "add-on" to the Level 1 or Level 2 profiles.</xhtml:p> </xccdf:description> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.5.1_NG_Ensure_Turn_On_Virtualization_Based_Security_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.5.2_NG_Ensure_Turn_On_Virtualization_Based_Security_Select_Platform_Security_Level_is_set_to_Secure_Boot_and_DMA_Protection" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.5.3_NG_Ensure_Turn_On_Virtualization_Based_Security_Virtualization_Based_Protection_of_Code_Integrity_is_set_to_Enabled_with_UEFI_lock" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.5.4_NG_Ensure_Turn_On_Virtualization_Based_Security_Require_UEFI_Memory_Attributes_Table_is_set_to_True_checked" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.5.6_NG_Ensure_Turn_On_Virtualization_Based_Security_Credential_Guard_Configuration_is_set_to_Disabled_DC_Only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.5.7_NG_Ensure_Turn_On_Virtualization_Based_Security_Secure_Launch_Configuration_is_set_to_Enabled" selected="true"/> </xccdf:Profile> |
Next Generation Windows Security - Member Server |
This profile contains advanced Windows security features that have specific configuration dependencies, and may not be compatible with all systems. It therefore requires special attention to detail and testing before implementation. If your environment supports these features, they are highly recommended as they have tangible security benefits. This profile is intended to be an optional "add-on" to the Level 1 or Level 2 profiles.
Show
Profile XML
<xccdf:Profile xmlns="http://checklists.nist.gov/xccdf/1.2" xmlns:ae="http://benchmarks.cisecurity.org/ae/0.5" xmlns:cc6="http://cisecurity.org/20-cc/v6.1" xmlns:cc7="http://cisecurity.org/20-cc/v7.0" xmlns:ciscf="https://benchmarks.cisecurity.org/ciscf/1.0" xmlns:notes="http://benchmarks.cisecurity.org/notes" xmlns:xccdf="http://checklists.nist.gov/xccdf/1.2" xmlns:xhtml="http://www.w3.org/1999/xhtml" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" id="xccdf_org.cisecurity.benchmarks_profile_Next_Generation_Windows_Security_-_Member_Server"> <xccdf:title xml:lang="en">Next Generation Windows Security - Member Server</xccdf:title> <xccdf:description xml:lang="en"> <xhtml:p>This profile contains advanced Windows security features that have specific configuration dependencies, and may not be compatible with all systems. It therefore requires special attention to detail and testing before implementation. If your environment supports these features, they are highly recommended as they have tangible security benefits. This profile is intended to be an optional "add-on" to the Level 1 or Level 2 profiles.</xhtml:p> </xccdf:description> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.5.1_NG_Ensure_Turn_On_Virtualization_Based_Security_is_set_to_Enabled" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.5.2_NG_Ensure_Turn_On_Virtualization_Based_Security_Select_Platform_Security_Level_is_set_to_Secure_Boot_and_DMA_Protection" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.5.3_NG_Ensure_Turn_On_Virtualization_Based_Security_Virtualization_Based_Protection_of_Code_Integrity_is_set_to_Enabled_with_UEFI_lock" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.5.4_NG_Ensure_Turn_On_Virtualization_Based_Security_Require_UEFI_Memory_Attributes_Table_is_set_to_True_checked" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.5.5_NG_Ensure_Turn_On_Virtualization_Based_Security_Credential_Guard_Configuration_is_set_to_Enabled_with_UEFI_lock_MS_Only" selected="true"/> <xccdf:select idref="xccdf_org.cisecurity.benchmarks_rule_18.8.5.7_NG_Ensure_Turn_On_Virtualization_Based_Security_Secure_Launch_Configuration_is_set_to_Enabled" selected="true"/> </xccdf:Profile> |